Jump to content

Malware on my pc - please help


Recommended Posts

Hi - I think I'm infected with malware, maybe a rootkit virus. When doing a Google search I'm sometimes redirected to an unexpected site, also I can't go to Malwarebytes.org on that computer (it says IE can't display the webpage but other webpages work).

I started following the instructions in "I'm infected - What do I do now?, Please follow these instructions to clean your system" but GMER Rootkit Scanner won't run at all (nothing happens after double-clicking) and I'm not sure the defogger worked, either.

I'd appreciate any help!

Here are my results:

MalwareBytes:

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

6/18/2010 2:12:02 AM

mbam-log-2010-06-18 (02-12-02).txt

Scan type: Quick scan

Objects scanned: 139412

Time elapsed: 11 minute(s), 47 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 3

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Page_URL (Hijack.StartPage) -> Bad: (http://www.googlesayfa.com/en) Good: (http://www.google.com) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.168,93.188.166.199 -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{52ac28ac-2f54-4836-a343-78f8222838bc}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.168,93.188.166.199 -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

defogger_disable.log:

defogger_disable by jpshortstuff (23.02.10.1)

Log created at 13:20 on 18/06/2010 (xxxxx)

Checking for autostart values...

HKCU\~\Run values retrieved.

HKLM\~\Run values retrieved.

Checking for services/drivers...

-=E.O.F=-

DDS.txt:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Sylvie at 13:27:04.01 on Fri 06/18/2010

Internet Explorer: 7.0.5730.13

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.565 [GMT -5:00]

AV: PC Tools AntiVirus Free *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

C:\WINDOWS\Explorer.EXE

svchost.exe

C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe

C:\WINDOWS\system32\CSHelper.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Logitech\QuickCam\Quickcam.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\PC Tools Security\pctsTray.exe

C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe

C:\Program Files\PC Tools Security\pctsAuxs.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\PC Tools Security\pctsSvc.exe

C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Sylvie\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uSearch Page = hxxp://search.live.com

uSearch Bar = hxxp://search.live.com/sphome.aspx

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uDefault_Page_URL = hxxp://www.google.com

uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/

mSearchAssistant = hxxp://search.live.com/sphome.aspx

uURLSearchHooks: FCToolbarURLSearchHook Class: {da879c19-9088-418b-a63a-2e6fb294eaf0} - c:\program files\aadvantage eshoppingsm toolbar\Helper.dll

uURLSearchHooks: H - No File

mWinlogon: Userinit=c:\windows\system32\userinit.exe

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Freecause Toolbar BHO: {5712a6bb-b6c8-4e52-a152-1ba741c9a6a2} - c:\program files\aadvantage eshoppingsm toolbar\Toolbar.dll

BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll

BHO: Club Bing Toolbar Helper: {b771fea3-2a05-4c21-b1e2-55551a97d520} - c:\program files\club bing toolbar helper\Bmbho.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: Club Bing Toolbar: {719d74ab-1af9-43a1-8c62-d8750628d93e} - c:\program files\club bing toolbar\Toolbar.dll

TB: Club Bing Toolbar Helper: {b771fea3-2a05-4c21-b1e2-55551a97d520} - c:\program files\club bing toolbar helper\Bmbho.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: AAdvantage eShoppingSM Toolbar: {85741f1d-ed47-4dcf-9109-07d10213c4d0} - c:\program files\aadvantage eshoppingsm toolbar\Toolbar.dll

TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File

uRun: [PMCRemote] c:\program files\pinnacle\shared files\programs\remote\Remoterm.exe

uRun: [Google Update] "c:\documents and settings\sylvie\local settings\application data\google\update\GoogleUpdate.exe" /c

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"

mRun: [soundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe

mRun: [PMX Daemon] ICO.EXE

mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"

mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide

mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [iSTray] "c:\program files\pc tools security\pctsTray.exe"

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office xp\office10\OSA.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{d25122bc-a60e-4663-b602-b01718f12044}\Icon3E5562ED7.ico

mPolicies-system: EnableLUA = 0 (0x0)

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\mi699f~1\office11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi699f~1\office11\REFIEBAR.DLL

LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll

DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} - hxxps://ra.qwest.com/sdccommon/download/tgctlins.cab

DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://ra.qwest.com/sdccommon/download/tgctlcm.cab

DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - hxxp://www.worldwinner.com/games/v47/scrabblecubes/scrabblecubes.cab

DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab

DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - hxxp://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264407051781

DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab

DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} - hxxps://mail203.mmm.com/dwa85W.cab

DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} - hxxp://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - hxxp://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab

DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} - hxxp://rms2.invokesolutions.com/events/bin/6.2.0.1452/MILive.cab

DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab

DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} - hxxp://www.worldwinner.com/games/v46/monopoly/monopoly.cab

DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47}

DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxps://us-mail-18.mmm.com/dwa7W.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - hxxp://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab

TCP: NameServer = 93.188.162.168,93.188.166.199

TCP: {52AC28AC-2F54-4836-A343-78F8222838BC} = 93.188.162.168,93.188.166.199

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\sylvie\applic~1\mozilla\firefox\profiles\15ny5g5a.default\

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff2.dll

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.6.dll

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.dll

FF - component: c:\program files\pc tools security\bdt\firefox\platform\winnt_x86-msvc\components\libheuristic.dll

FF - plugin: c:\documents and settings\sylvie\application data\move networks\plugins\npqmp071503000010.dll

FF - plugin: c:\documents and settings\sylvie\application data\move networks\plugins\npqmp071701000002.dll

FF - plugin: c:\documents and settings\sylvie\application data\mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\documents and settings\sylvie\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll

FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: XULRunner: {FABA4F21-0E5A-4DC6-936B-8A7205CA6ED2} - c:\documents and settings\sylvie\local settings\application data\{FABA4F21-0E5A-4DC6-936B-8A7205CA6ED2}

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr

ef", true);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-6-1 218592]

R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2006-3-17 65536]

R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2010-3-4 266240]

R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]

R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2010-6-1 366840]

R2 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2010-6-1 1142224]

S2 Browser Defender Update Service;Browser Defender Update Service;"c:\program files\pc tools security\bdt\bdtupdateservice.exe" --> c:\program files\pc tools security\bdt\BDTUpdateService.exe [?]

S3 cpuz132;cpuz132;\??\c:\docume~1\sylvie\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\sylvie\locals~1\temp\cpuz132\cpuz132_x32.sys [?]

S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2006-12-30 18432]

S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2006-12-30 14336]

S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]

S4 gupdate1c9d359281aab1a;Google Update Service (gupdate1c9d359281aab1a);c:\program files\google\update\GoogleUpdate.exe [2009-5-12 133104]

=============== Created Last 30 ================

2010-06-18 18:17:58 0 ----a-w- c:\documents and settings\sylvie\defogger_reenable

2010-06-17 20:17:17 44544 ----a-w- c:\windows\system32\ernel32.dll

2010-06-17 20:17:16 44544 ----a-w- c:\docume~1\sylvie\applic~1\0b1d0ef5.exe

2010-06-01 22:31:49 0 d-----w- c:\docume~1\sylvie\applic~1\BitDefender

2010-06-01 22:20:11 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat

2010-06-01 22:20:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2010-06-01 22:20:07 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2010-06-01 22:20:07 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat

2010-06-01 22:20:07 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat

2010-06-01 22:20:07 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2010-06-01 22:20:03 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat

2010-06-01 22:20:03 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2010-06-01 22:19:58 0 d-----w- c:\program files\PC Tools Security

2010-06-01 22:19:58 0 d-----w- c:\program files\common files\PC Tools

2010-06-01 22:19:58 0 d-----w- c:\docume~1\sylvie\applic~1\PC Tools

2010-06-01 22:19:58 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools

2010-05-26 17:44:31 0 d-----w- c:\docume~1\sylvie\applic~1\FCTB000062125

2010-05-26 17:43:59 0 d-----w- c:\program files\AAdvantage eShoppingSM Toolbar

2010-05-23 07:06:49 19469 ------w- c:\windows\hpoins01.dat

2010-05-23 07:06:49 16606 ------w- c:\windows\hpomdl01.dat

2010-05-23 06:56:05 0 d-----w- c:\temp\HP All-in-One Series Web Release

2010-05-23 06:44:01 0 d-----w- c:\program files\Windows Installer Clean Up

2010-05-23 06:43:45 0 d-----w- c:\program files\MSECACHE

2010-05-23 04:40:03 0 d-----w- c:\docume~1\alluse~1\applic~1\UAB

2010-05-23 04:39:25 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters

2010-05-23 04:38:42 0 d-----w- c:\program files\PC Drivers HeadQuarters

2010-05-22 18:45:14 0 d-----w- c:\windows\system32\NtmsData

2010-05-22 04:43:08 17218 ------w- c:\windows\hpomdl04.dat.temp

2010-05-22 04:43:08 102007 ------w- c:\windows\hpoins04.dat.temp

==================== Find3M ====================

2010-05-20 05:08:51 3686418 ----a-w- C:\FossSwimSchool.zip

2010-05-15 02:41:27 40960 ---ha-w- c:\windows\system32\cisvdl32.dll

2010-05-15 02:39:57 20 ----a-w- c:\docume~1\sylvie\applic~1\wqhtpi.dat

2010-04-29 20:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-04-29 20:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-04 15:38:01 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012010020420100205\index.dat

============= FINISH: 13:30:29.56 ===============

Link to post
Share on other sites

Hi and welcome to the Malwarebytes forums. ;)

I'm melboy and I am going to try to help you with your problem. Please take note of the following:

  1. I will be working on your Malware issues this may or may not solve other issues you have with your machine.
  2. The fixes are specific to your problem and should only be used for this issue on this machine.
  3. If you don't know or understand something, please don't hesitate to ask.
  4. Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc...)
  5. Please DO NOT run any other tools or scans whilst I am helping you.
  6. It is important that you reply to this thread. Do not start a new topic.
  7. DO NOT attach logs unless requested to. Please copy/paste all requested logs into your replies.
  8. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  9. Absence of symptoms does not mean that everything is clear.

NOTE: Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

No Reply Within 3 Days Will Result In Your Topic Being Closed!! If you need more time, please inform me.

===================================================

GooredFix

  • Please download GooredFix and save it to your Desktop.
  • Ensure all Firefox windows are closed.
  • Double-click Goored.exe to run it.
  • When prompted to run the scan, click Yes. GooredFix will check for infections
  • When completed, a log will open. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).

TFC

  • Please download TFC by Old Timer to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • Click the Start button in the bottom left of TFC
  • If prompted, click "Yes" to reboot.

Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It should not take longer than a couple of minutes , and may only take a few seconds. Only if needed will you be prompted to reboot.

Malwarebytes' Anti-Malware (MBAM)

As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform Quick scan, then click on Scan
  • When done, you will be prompted. Click OK. If Items are found, then click on Show Results
  • Check all items then click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply.
    The log can also be found here:
    1. C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
    2. Or via the Logs tab when the application is started.

Note: MBAM may ask to reboot your computer so it can continue with the removal process, please do so immediately.

Failure to reboot will prevent MBAM from removing all the malware.

Re-run DDS

Please disable any anti-malware program that will block scripts from running before running DDS.

  • Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, save both reports to your desktop.
  • Please copy & paste the contents of :
    • DDS.txt
    • attach.txt

    And post them in your next reply.

    In your next reply:

    1. DDS.txt
    2. attach.txt
    3. MBAM log
    4. GooredLog.txt

Link to post
Share on other sites

Thank you very much for your offer to help. Before I got your reply I decided to try the "I'm infected - What do I do now?" steps again, and this time I got different results and was able to run GMER Rootkit Scanner. I am posting the results here WITHOUT following any of your next steps (have not run GooredFix, TFC) so I don't complicate things further, and in case these results point you in a different direction. Now that we're talking, I won't do anything else until I hear back. Thanks again.

MalwareBytes:

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

6/18/2010 9:17:40 PM

mbam-log-2010-06-18 (21-17-40).txt

Scan type: Quick scan

Objects scanned: 143379

Time elapsed: 16 minute(s), 44 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 2

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.168,93.188.166.199 -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{52ac28ac-2f54-4836-a343-78f8222838bc}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.168,93.188.166.199 -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

defogger_disable.log (ran but did not prompt for reboot):

defogger_disable by jpshortstuff (23.02.10.1)

Log created at 21:23 on 18/06/2010 (xxxxx)

Checking for autostart values...

HKCU\~\Run values retrieved.

HKLM\~\Run values retrieved.

Checking for services/drivers...

-=E.O.F=-

DDS.txt

DDS (Ver_10-03-17.01) - NTFSx86

Run by xxxxx at 22:38:33.26 on Fri 06/18/2010

Internet Explorer: 7.0.5730.13

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.571 [GMT -5:00]

AV: PC Tools AntiVirus Free *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe

C:\WINDOWS\system32\CSHelper.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe

C:\Program Files\PC Tools Security\pctsAuxs.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

C:\Program Files\PC Tools Security\pctsSvc.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program Files\PC Tools Security\pctsTray.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Sylvie\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uSearch Page = hxxp://search.live.com

uSearch Bar = hxxp://search.live.com/sphome.aspx

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uDefault_Page_URL = hxxp://www.google.com

uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/

mSearchAssistant = hxxp://search.live.com/sphome.aspx

uURLSearchHooks: FCToolbarURLSearchHook Class: {da879c19-9088-418b-a63a-2e6fb294eaf0} - c:\program files\aadvantage eshoppingsm toolbar\Helper.dll

uURLSearchHooks: H - No File

mWinlogon: Userinit=c:\windows\system32\userinit.exe

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Freecause Toolbar BHO: {5712a6bb-b6c8-4e52-a152-1ba741c9a6a2} - c:\program files\aadvantage eshoppingsm toolbar\Toolbar.dll

BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll

BHO: Club Bing Toolbar Helper: {b771fea3-2a05-4c21-b1e2-55551a97d520} - c:\program files\club bing toolbar helper\Bmbho.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: Club Bing Toolbar: {719d74ab-1af9-43a1-8c62-d8750628d93e} - c:\program files\club bing toolbar\Toolbar.dll

TB: Club Bing Toolbar Helper: {b771fea3-2a05-4c21-b1e2-55551a97d520} - c:\program files\club bing toolbar helper\Bmbho.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: AAdvantage eShoppingSM Toolbar: {85741f1d-ed47-4dcf-9109-07d10213c4d0} - c:\program files\aadvantage eshoppingsm toolbar\Toolbar.dll

TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File

uRun: [PMCRemote] c:\program files\pinnacle\shared files\programs\remote\Remoterm.exe

uRun: [Google Update] "c:\documents and settings\sylvie\local settings\application data\google\update\GoogleUpdate.exe" /c

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"

mRun: [soundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe

mRun: [PMX Daemon] ICO.EXE

mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"

mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide

mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [iSTray] "c:\program files\pc tools security\pctsTray.exe"

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office xp\office10\OSA.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{d25122bc-a60e-4663-b602-b01718f12044}\Icon3E5562ED7.ico

mPolicies-system: EnableLUA = 0 (0x0)

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\mi699f~1\office11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi699f~1\office11\REFIEBAR.DLL

LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll

DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} - hxxps://ra.qwest.com/sdccommon/download/tgctlins.cab

DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://ra.qwest.com/sdccommon/download/tgctlcm.cab

DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - hxxp://www.worldwinner.com/games/v47/scrabblecubes/scrabblecubes.cab

DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab

DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - hxxp://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264407051781

DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab

DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} - hxxps://mail203.mmm.com/dwa85W.cab

DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://pawbhaji.spaces.live.com/PhotoUpload/MsnPUpld.cab

DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} - hxxp://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - hxxp://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab

DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} - hxxp://rms2.invokesolutions.com/events/bin/6.2.0.1452/MILive.cab

DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab

DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} - hxxp://www.worldwinner.com/games/v46/monopoly/monopoly.cab

DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47}

DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxps://us-mail-18.mmm.com/dwa7W.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - hxxp://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\sylvie\applic~1\mozilla\firefox\profiles\15ny5g5a.default\

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff2.dll

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.6.dll

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.dll

FF - component: c:\program files\pc tools security\bdt\firefox\platform\winnt_x86-msvc\components\libheuristic.dll

FF - plugin: c:\documents and settings\sylvie\application data\move networks\plugins\npqmp071503000010.dll

FF - plugin: c:\documents and settings\sylvie\application data\move networks\plugins\npqmp071701000002.dll

FF - plugin: c:\documents and settings\sylvie\application data\mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\documents and settings\sylvie\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll

FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: XULRunner: {FABA4F21-0E5A-4DC6-936B-8A7205CA6ED2} - c:\documents and settings\sylvie\local settings\application data\{FABA4F21-0E5A-4DC6-936B-8A7205CA6ED2}

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr

ef", true);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-6-1 218592]

R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2006-3-17 65536]

R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2010-3-4 266240]

R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]

R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2010-6-1 366840]

R2 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2010-6-1 1142224]

S2 Browser Defender Update Service;Browser Defender Update Service;"c:\program files\pc tools security\bdt\bdtupdateservice.exe" --> c:\program files\pc tools security\bdt\BDTUpdateService.exe [?]

S3 cpuz132;cpuz132;\??\c:\docume~1\sylvie\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\sylvie\locals~1\temp\cpuz132\cpuz132_x32.sys [?]

S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2006-12-30 18432]

S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2006-12-30 14336]

S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]

S4 gupdate1c9d359281aab1a;Google Update Service (gupdate1c9d359281aab1a);c:\program files\google\update\GoogleUpdate.exe [2009-5-12 133104]

=============== Created Last 30 ================

2010-06-18 18:17:58 0 ----a-w- c:\documents and settings\sylvie\defogger_reenable

2010-06-17 20:17:17 44544 ----a-w- c:\windows\system32\ernel32.dll

2010-06-17 20:17:16 44544 ----a-w- c:\docume~1\sylvie\applic~1\0b1d0ef5.exe

2010-06-01 22:31:49 0 d-----w- c:\docume~1\sylvie\applic~1\BitDefender

2010-06-01 22:20:11 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat

2010-06-01 22:20:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2010-06-01 22:20:07 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2010-06-01 22:20:07 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat

2010-06-01 22:20:07 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat

2010-06-01 22:20:07 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2010-06-01 22:20:03 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat

2010-06-01 22:20:03 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2010-06-01 22:19:58 0 d-----w- c:\program files\PC Tools Security

2010-06-01 22:19:58 0 d-----w- c:\program files\common files\PC Tools

2010-06-01 22:19:58 0 d-----w- c:\docume~1\sylvie\applic~1\PC Tools

2010-06-01 22:19:58 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools

2010-05-26 17:44:31 0 d-----w- c:\docume~1\sylvie\applic~1\FCTB000062125

2010-05-26 17:43:59 0 d-----w- c:\program files\AAdvantage eShoppingSM Toolbar

2010-05-23 07:06:49 19469 ------w- c:\windows\hpoins01.dat

2010-05-23 07:06:49 16606 ------w- c:\windows\hpomdl01.dat

2010-05-23 06:56:05 0 d-----w- c:\temp\HP All-in-One Series Web Release

2010-05-23 06:44:01 0 d-----w- c:\program files\Windows Installer Clean Up

2010-05-23 06:43:45 0 d-----w- c:\program files\MSECACHE

2010-05-23 04:40:03 0 d-----w- c:\docume~1\alluse~1\applic~1\UAB

2010-05-23 04:39:25 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters

2010-05-23 04:38:42 0 d-----w- c:\program files\PC Drivers HeadQuarters

2010-05-22 18:45:14 0 d-----w- c:\windows\system32\NtmsData

2010-05-22 04:43:08 17218 ------w- c:\windows\hpomdl04.dat.temp

2010-05-22 04:43:08 102007 ------w- c:\windows\hpoins04.dat.temp

==================== Find3M ====================

2010-05-20 05:08:51 3686418 ----a-w- C:\FossSwimSchool.zip

2010-05-15 02:41:27 40960 ---ha-w- c:\windows\system32\cisvdl32.dll

2010-05-15 02:39:57 20 ----a-w- c:\docume~1\sylvie\applic~1\wqhtpi.dat

2010-04-29 20:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-04-29 20:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-04 15:38:01 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012010020420100205\index.dat

============= FINISH: 22:42:21.87 ===============

Attach.zip

ark.zip

Link to post
Share on other sites

Hi

Your MBAM scans are showing that it is quite a few database versions behind. The current as I type is 4217. Yours shows 4052. You need to update it. Instructions for doing this are included below. Let me know how things are running when you've completed them, along with posting the rquired logs.

GooredFix

  • Please download GooredFix and save it to your Desktop.
  • Ensure all Firefox windows are closed.
  • Double-click Goored.exe to run it.
  • When prompted to run the scan, click Yes. GooredFix will check for infections
  • When completed, a log will open. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).

TFC

  • Please download TFC by Old Timer to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • Click the Start button in the bottom left of TFC
  • If prompted, click "Yes" to reboot.

Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It should not take longer than a couple of minutes , and may only take a few seconds. Only if needed will you be prompted to reboot.

Malwarebytes' Anti-Malware (MBAM)

As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform Quick scan, then click on Scan
  • When done, you will be prompted. Click OK. If Items are found, then click on Show Results
  • Check all items then click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply.
    The log can also be found here:
    1. C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
    2. Or via the Logs tab when the application is started.

Note: MBAM may ask to reboot your computer so it can continue with the removal process, please do so immediately.

Failure to reboot will prevent MBAM from removing all the malware.

Re-run DDS

Please disable any anti-malware program that will block scripts from running before running DDS.

  • Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, Please copy & paste the contents of :
    • DDS.txt

And post it in your next reply.

In your next reply:

  1. GooredLog.txt
  2. MBAM log
  3. DDS.txt

Link to post
Share on other sites

Thanks, I've run everything as advised. I can now open MalwareBytes.org on that computer (previously I got a message that IE can't display the webpage).

I still have these symptoms:

- I continue to sometimes get redirected to the wrong website when I click a link from Google search.

- I'm now getting this message when I reboot the pc: "To help protect your computer, Windows Firewall has blocked some features of this program. Do you want to keep blocking this program? Name: Windows Explorer, Publisher: Microsoft Corporation." I selected the option "Ask Me Later" because I'm not sure what to do.

- Also, I'm now sometimes getting a message at startup like "kbmdpk.dll can't start up because this file cannot be found." I ran msconfig and kbmdpk.dll is in the startup list, but is disabled. Also, there is a startup item called "ozcii" at "c:\documents and settings\username\application data\Ihuzqa\ozcii.exe" that I hadn't noticed before, not sure what it is but it's enabled.

Here are my results:

GooredFix.txt

GooredFix by jpshortstuff (08.01.10.1)

Log created at 17:11 on 20/06/2010 (Sylvie)

Firefox version 3.6.3 (en-US)

========== GooredScan ==========

Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{FABA4F21-0E5A-4DC6-936B-8A7205CA6ED2} -> Success!

Deleting C:\Documents and Settings\Sylvie\Local Settings\Application Data\{FABA4F21-0E5A-4DC6-936B-8A7205CA6ED2} -> Success!

========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\

{972ce4c6-7e08-4474-a285-3208198ce6fd} [02:55 29/05/2010]

C:\Documents and Settings\Sylvie\Application Data\Mozilla\Firefox\Profiles\15ny5g5a.default\extensions\

{20a82645-c095-46ed-80e3-08825760534b} [02:56 29/05/2010]

{e0204bd5-9d31-402b-a99d-a6aa8ffebdca} [03:30 29/05/2010]

C:\Documents and Settings\Sylvie\Application Data\Mozilla\Firefox\Profiles\profile.knconnector\extensions\

staged-xpis [05:12 07/06/2010]

{20a82645-c095-46ed-80e3-08825760534b} [05:12 07/06/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]

"{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [08:05 15/08/2009]

"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [12:17 16/08/2009]

"FFToolbar@bitdefender.com"="C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\" [16:29 15/03/2010]

-=E.O.F=-

MalwareBytes:

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4219

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

6/20/2010 5:27:50 PM

mbam-log-2010-06-20 (17-27-50).txt

Scan type: Quick scan

Objects scanned: 143828

Time elapsed: 5 minute(s), 36 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 2

Registry Keys Infected: 0

Registry Values Infected: 2

Registry Data Items Infected: 2

Folders Infected: 0

Files Infected: 3

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

C:\WINDOWS\uwehizajifoha.dll (Trojan.Hiloti) -> Delete on reboot.

C:\WINDOWS\kbmdpk.dll (Trojan.Hiloti.Gen) -> Delete on reboot.

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yxiravakuleja (Trojan.Hiloti) -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mlafani (Trojan.Hiloti.Gen) -> Delete on reboot.

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.168,93.188.166.199 -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{52ac28ac-2f54-4836-a343-78f8222838bc}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.168,93.188.166.199 -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\uwehizajifoha.dll (Trojan.Hiloti) -> Delete on reboot.

C:\WINDOWS\kbmdpk.dll (Trojan.Hiloti.Gen) -> Delete on reboot.

C:\WINDOWS\xdel_kbmdpk.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.

DDS.txt:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Sylvie at 17:31:26.26 on Sun 06/20/2010

Internet Explorer: 7.0.5730.13

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.426 [GMT -5:00]

AV: PC Tools AntiVirus Free *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe

C:\WINDOWS\system32\CSHelper.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe

C:\Program Files\PC Tools Security\pctsAuxs.exe

C:\Program Files\PC Tools Security\pctsSvc.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

C:\WINDOWS\Explorer.EXE

C:\Documents and Settings\Sylvie\Application Data\0b1d0ef5.exe

C:\Program Files\PC Tools Security\pctsTray.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe

C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Sylvie\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uSearch Page = hxxp://search.live.com

uSearch Bar = hxxp://search.live.com/sphome.aspx

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uDefault_Page_URL = hxxp://www.google.com

uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/

mSearchAssistant = hxxp://search.live.com/sphome.aspx

uURLSearchHooks: FCToolbarURLSearchHook Class: {da879c19-9088-418b-a63a-2e6fb294eaf0} - c:\program files\aadvantage eshoppingsm toolbar\Helper.dll

uURLSearchHooks: H - No File

mWinlogon: Userinit=c:\windows\system32\userinit.exe

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Freecause Toolbar BHO: {5712a6bb-b6c8-4e52-a152-1ba741c9a6a2} - c:\program files\aadvantage eshoppingsm toolbar\Toolbar.dll

BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll

BHO: Club Bing Toolbar Helper: {b771fea3-2a05-4c21-b1e2-55551a97d520} - c:\program files\club bing toolbar helper\Bmbho.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: Club Bing Toolbar: {719d74ab-1af9-43a1-8c62-d8750628d93e} - c:\program files\club bing toolbar\Toolbar.dll

TB: Club Bing Toolbar Helper: {b771fea3-2a05-4c21-b1e2-55551a97d520} - c:\program files\club bing toolbar helper\Bmbho.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: AAdvantage eShoppingSM Toolbar: {85741f1d-ed47-4dcf-9109-07d10213c4d0} - c:\program files\aadvantage eshoppingsm toolbar\Toolbar.dll

TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File

uRun: [PMCRemote] c:\program files\pinnacle\shared files\programs\remote\Remoterm.exe

uRun: [Google Update] "c:\documents and settings\sylvie\local settings\application data\google\update\GoogleUpdate.exe" /c

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [{B6E61364-ECC0-B049-8BA4-D309C9162509}] "c:\documents and settings\sylvie\application data\ihuzqa\ozcii.exe"

uRun: [Mlafani] rundll32.exe "c:\windows\kbmdpk.dll",Startup

mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"

mRun: [soundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe

mRun: [PMX Daemon] ICO.EXE

mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"

mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide

mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [iSTray] "c:\program files\pc tools security\pctsTray.exe"

mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office xp\office10\OSA.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{d25122bc-a60e-4663-b602-b01718f12044}\Icon3E5562ED7.ico

mPolicies-system: EnableLUA = 0 (0x0)

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\mi699f~1\office11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi699f~1\office11\REFIEBAR.DLL

LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll

DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} - hxxps://ra.qwest.com/sdccommon/download/tgctlins.cab

DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://ra.qwest.com/sdccommon/download/tgctlcm.cab

DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - hxxp://www.worldwinner.com/games/v47/scrabblecubes/scrabblecubes.cab

DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab

DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - hxxp://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1264407051781

DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab

DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} - hxxps://mail203.mmm.com/dwa85W.cab

DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://pawbhaji.spaces.live.com/PhotoUpload/MsnPUpld.cab

DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} - hxxp://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - hxxp://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab

DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} - hxxp://rms2.invokesolutions.com/events/bin/6.2.0.1452/MILive.cab

DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab

DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} - hxxp://www.worldwinner.com/games/v46/monopoly/monopoly.cab

DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47}

DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxps://us-mail-18.mmm.com/dwa7W.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - hxxp://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab

TCP: NameServer = 93.188.162.168,93.188.166.199

TCP: {52AC28AC-2F54-4836-A343-78F8222838BC} = 93.188.162.168,93.188.166.199

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\sylvie\applic~1\mozilla\firefox\profiles\15ny5g5a.default\

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff2.dll

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.6.dll

FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.dll

FF - plugin: c:\documents and settings\sylvie\application data\move networks\plugins\npqmp071503000010.dll

FF - plugin: c:\documents and settings\sylvie\application data\move networks\plugins\npqmp071701000002.dll

FF - plugin: c:\documents and settings\sylvie\application data\mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\documents and settings\sylvie\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll

FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: XULRunner: {EDFAA8BC-7D40-4DCD-8B31-705E9D7852B0} - c:\documents and settings\sylvie\local settings\application data\{edfaa8bc-7d40-4dcd-8b31-705e9d7852b0}\

---- FIREFOX POLICIES ----

FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr

ef", true);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-6-1 218592]

R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2006-3-17 65536]

R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2010-3-4 266240]

R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]

R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2010-6-1 366840]

R2 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2010-6-1 1142224]

S2 Browser Defender Update Service;Browser Defender Update Service;"c:\program files\pc tools security\bdt\bdtupdateservice.exe" --> c:\program files\pc tools security\bdt\BDTUpdateService.exe [?]

S3 cpuz132;cpuz132;\??\c:\docume~1\sylvie\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\sylvie\locals~1\temp\cpuz132\cpuz132_x32.sys [?]

S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2006-12-30 18432]

S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2006-12-30 14336]

S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]

S4 gupdate1c9d359281aab1a;Google Update Service (gupdate1c9d359281aab1a);c:\program files\google\update\GoogleUpdate.exe [2009-5-12 133104]

=============== Created Last 30 ================

2010-06-18 18:17:58 0 ----a-w- c:\documents and settings\sylvie\defogger_reenable

2010-06-17 20:17:17 44544 ----a-w- c:\windows\system32\ernel32.dll

2010-06-17 20:17:16 44544 ----a-w- c:\docume~1\sylvie\applic~1\0b1d0ef5.exe

2010-06-01 22:31:49 0 d-----w- c:\docume~1\sylvie\applic~1\BitDefender

2010-06-01 22:20:11 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat

2010-06-01 22:20:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2010-06-01 22:20:07 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2010-06-01 22:20:07 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat

2010-06-01 22:20:07 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat

2010-06-01 22:20:07 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2010-06-01 22:20:03 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat

2010-06-01 22:20:03 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2010-06-01 22:19:58 0 d-----w- c:\program files\PC Tools Security

2010-06-01 22:19:58 0 d-----w- c:\program files\common files\PC Tools

2010-06-01 22:19:58 0 d-----w- c:\docume~1\sylvie\applic~1\PC Tools

2010-06-01 22:19:58 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools

2010-05-26 17:44:31 0 d-----w- c:\docume~1\sylvie\applic~1\FCTB000062125

2010-05-26 17:43:59 0 d-----w- c:\program files\AAdvantage eShoppingSM Toolbar

2010-05-23 07:06:49 19469 ------w- c:\windows\hpoins01.dat

2010-05-23 07:06:49 16606 ------w- c:\windows\hpomdl01.dat

2010-05-23 06:56:05 0 d-----w- c:\temp\HP All-in-One Series Web Release

2010-05-23 06:44:01 0 d-----w- c:\program files\Windows Installer Clean Up

2010-05-23 06:43:45 0 d-----w- c:\program files\MSECACHE

2010-05-23 04:40:03 0 d-----w- c:\docume~1\alluse~1\applic~1\UAB

2010-05-23 04:39:25 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters

2010-05-23 04:38:42 0 d-----w- c:\program files\PC Drivers HeadQuarters

2010-05-22 18:45:14 0 d-----w- c:\windows\system32\NtmsData

2010-05-22 04:43:08 17218 ------w- c:\windows\hpomdl04.dat.temp

2010-05-22 04:43:08 102007 ------w- c:\windows\hpoins04.dat.temp

==================== Find3M ====================

2010-05-20 05:08:51 3686418 ----a-w- C:\FossSwimSchool.zip

2010-05-15 02:41:27 40960 ---ha-w- c:\windows\system32\cisvdl32.dll

2010-05-15 02:39:57 20 ----a-w- c:\docume~1\sylvie\applic~1\wqhtpi.dat

2010-04-29 20:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-04-29 20:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-04 15:38:01 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012010020420100205\index.dat

============= FINISH: 17:35:18.71 ===============

Link to post
Share on other sites

Hi

ComboFix (by sUBs)

Please visit this webpage for instructions for downloading and running ComboFix: Bleeping Computer ComboFix Tutorial

  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
    For instructions on how to disable your security programs, please see this topic:
    How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply
  • Re-enable all the programs that were disabled during the running of ComboFix..

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.

This tool is not a toy and not for everyday use.

ComboFix SHOULD NOT be used unless requested by a forum helper

Link to post
Share on other sites

Thanks for your help - here are the ComboFix results:

ComboFix 10-06-23.02 - Sylvie 06/23/2010 21:25:25.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.652 [GMT -5:00]

Running from: c:\documents and settings\Sylvie\Desktop\ComboFix.exe

AV: PC Tools AntiVirus Free *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

.

The following files were disabled during the run:

c:\windows\system32\cisvdl32.dll

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Sylvie\Application Data\0b1d0ef5.exe

c:\documents and settings\Sylvie\Application Data\Ihuzqa

c:\documents and settings\Sylvie\Application Data\Ihuzqa\ozcii.exe

c:\documents and settings\Sylvie\g2mdlhlpx.exe

c:\documents and settings\Sylvie\Local Settings\Application Data\{EDFAA8BC-7D40-4DCD-8B31-705E9D7852B0}

c:\documents and settings\Sylvie\Local Settings\Application Data\{EDFAA8BC-7D40-4DCD-8B31-705E9D7852B0}\chrome.manifest

c:\documents and settings\Sylvie\Local Settings\Application Data\{EDFAA8BC-7D40-4DCD-8B31-705E9D7852B0}\chrome\content\_cfg.js

c:\documents and settings\Sylvie\Local Settings\Application Data\{EDFAA8BC-7D40-4DCD-8B31-705E9D7852B0}\chrome\content\overlay.xul

c:\documents and settings\Sylvie\Local Settings\Application Data\{EDFAA8BC-7D40-4DCD-8B31-705E9D7852B0}\install.rdf

c:\program files\WinPCap

c:\program files\WinPCap\rpcapd.exe

C:\s

c:\windows\system32\18467.exe

c:\windows\system32\19169.exe

c:\windows\system32\26500.exe

c:\windows\system32\6334.exe

c:\windows\system32\drivers\npf.sys

c:\windows\system32\ernel32.dll

c:\windows\system32\Packet.dll

c:\windows\system32\pthreadVC.dll

c:\windows\system32\spool\prtprocs\w32x86\A179sK7y.dll

c:\windows\system32\spool\prtprocs\w32x86\C9sK793.dll

c:\windows\system32\spool\prtprocs\w32x86\EIQ31c.dll

c:\windows\system32\spool\prtprocs\w32x86\GM3179o.dll

c:\windows\system32\spool\prtprocs\w32x86\GMY79oCEI.dll

c:\windows\system32\spool\prtprocs\w32x86\I5q5w.dll

c:\windows\system32\spool\prtprocs\w32x86\K31gMY17o.dll

c:\windows\system32\spool\prtprocs\w32x86\KUOC31u9.dll

c:\windows\system32\spool\prtprocs\w32x86\MY79o17m.dll

c:\windows\system32\spool\prtprocs\w32x86\MY7cEI7q.dll

c:\windows\system32\spool\prtprocs\w32x86\O31m93w7u.dll

c:\windows\system32\spool\prtprocs\w32x86\O5o55.dll

c:\windows\system32\spool\prtprocs\w32x86\Q5w55.dll

c:\windows\system32\spool\prtprocs\w32x86\S1eI3q7w.dll

c:\windows\system32\spool\prtprocs\w32x86\U7m31w.dll

c:\windows\system32\spool\prtprocs\w32x86\U93iQ9w.dll

c:\windows\system32\spool\prtprocs\w32x86\Y7c3s7.dll

c:\windows\system32\spool\prtprocs\w32x86\YWS179u.dll

c:\windows\system32\spool\prtprocs\w32x86\YWSK17.dll

c:\windows\system32\WanPacket.dll

c:\windows\system32\wpcap.dll

c:\windows\TEMP\logishrd\LVPrcInj01.dll

c:\windows\xpsp1hfm.log

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_NPF

-------\Legacy_SVLOSTSERVICES

-------\Service_npf

((((((((((((((((((((((((( Files Created from 2010-05-24 to 2010-06-24 )))))))))))))))))))))))))))))))

.

2010-06-13 23:12 . 2010-06-13 23:12 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla

2010-06-02 02:14 . 2010-06-02 02:14 -------- d-----w- c:\documents and settings\Sylvie\Local Settings\Application Data\Threat Expert

2010-06-01 22:31 . 2010-06-01 22:31 -------- d-----w- c:\documents and settings\Sylvie\Application Data\BitDefender

2010-06-01 22:20 . 2010-02-05 14:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2010-06-01 22:20 . 2010-03-29 15:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2010-06-01 22:20 . 2009-11-23 18:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2010-06-01 22:20 . 2010-04-08 19:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2010-06-01 22:19 . 2010-06-24 02:07 -------- d-----w- c:\program files\PC Tools Security

2010-06-01 22:19 . 2010-06-01 22:30 -------- d-----w- c:\program files\Common Files\PC Tools

2010-06-01 22:19 . 2010-06-01 22:19 -------- d-----w- c:\documents and settings\Sylvie\Application Data\PC Tools

2010-06-01 22:19 . 2010-06-01 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools

2010-05-29 02:55 . 2010-05-29 02:55 -------- d-----w- c:\documents and settings\Sylvie\Local Settings\Application Data\Mozilla

2010-05-26 17:44 . 2010-05-26 17:44 -------- d-----w- c:\documents and settings\Sylvie\Application Data\FCTB000062125

2010-05-26 17:43 . 2010-05-26 17:44 -------- d-----w- c:\program files\AAdvantage eShoppingSM Toolbar

2010-05-25 17:34 . 2010-05-25 17:40 -------- d-----w- c:\program files\Common Files\Adobe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-06-24 02:08 . 2008-07-27 16:20 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2010-06-24 01:46 . 2008-09-30 19:57 -------- d-----w- c:\documents and settings\Sylvie\Application Data\MSN6

2010-06-24 01:00 . 2009-06-26 19:50 -------- d-----w- c:\documents and settings\Sylvie\Application Data\Ivso

2010-06-24 00:17 . 2010-06-24 00:17 503808 ----a-w- c:\documents and settings\Sylvie\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-2e0b370d-n\msvcp71.dll

2010-06-24 00:17 . 2010-06-24 00:17 499712 ----a-w- c:\documents and settings\Sylvie\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-2e0b370d-n\jmc.dll

2010-06-24 00:17 . 2010-06-24 00:17 348160 ----a-w- c:\documents and settings\Sylvie\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-2e0b370d-n\msvcr71.dll

2010-06-23 23:33 . 2008-08-29 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater

2010-06-22 15:23 . 2010-05-17 15:00 -------- d-----w- c:\documents and settings\Sylvie\Application Data\U3

2010-06-21 04:52 . 2010-05-28 05:23 356352 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\solitairerush\solitairerush.dll

2010-06-20 21:43 . 2010-05-15 02:46 120 ----a-w- c:\windows\Ckozuzeqijiwa.dat

2010-06-20 13:40 . 2010-05-15 02:46 0 ----a-w- c:\windows\Dbucimonusi.bin

2010-06-18 06:56 . 2010-01-25 06:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-06-18 05:15 . 2010-02-18 05:10 339968 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\dealornodeal\dealornodeal.dll

2010-06-15 16:41 . 2010-04-24 14:54 439816 ----a-w- c:\documents and settings\Sylvie\Application Data\Real\Update\setup3.10\setup.exe

2010-06-11 04:06 . 2009-09-14 21:51 1235968 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\chuzzle\Chuzzle.dll

2010-06-11 04:06 . 2009-12-04 03:58 -------- d-----w- c:\documents and settings\All Users\Application Data\WorldWinner

2010-06-01 22:10 . 2010-03-15 16:28 -------- d-----w- c:\program files\BitDefender

2010-06-01 22:10 . 2010-03-15 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender

2010-06-01 22:10 . 2010-03-15 16:25 -------- d-----w- c:\program files\Common Files\BitDefender

2010-05-29 02:55 . 2009-04-14 03:37 -------- d-----w- c:\documents and settings\Sylvie\Application Data\Move Networks

2010-05-26 17:44 . 2010-05-26 17:44 113939 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\Uninst.exe

2010-05-26 17:44 . 2010-05-26 17:44 1558528 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\Toolbar.dll

2010-05-26 17:44 . 2010-05-26 17:44 243200 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\Helper.dll

2010-05-25 05:13 . 2010-05-25 05:13 430141 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\luxor\luxor.dll

2010-05-23 06:44 . 2010-05-23 06:44 3584 ----a-r- c:\documents and settings\Sylvie\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe

2010-05-23 06:44 . 2010-05-23 06:44 -------- d-----w- c:\program files\Windows Installer Clean Up

2010-05-23 06:43 . 2010-05-23 06:43 -------- d-----w- c:\program files\MSECACHE

2010-05-23 04:40 . 2010-05-23 04:40 -------- d-----w- c:\documents and settings\All Users\Application Data\UAB

2010-05-23 04:39 . 2010-05-23 04:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters

2010-05-23 04:38 . 2010-05-23 04:38 -------- d-----w- c:\program files\PC Drivers HeadQuarters

2010-05-23 04:16 . 2010-03-28 11:50 -------- d-----w- c:\program files\Hp

2010-05-20 16:54 . 2010-05-26 17:44 1477 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\patch.bat

2010-05-20 05:08 . 2009-07-15 07:17 3686418 ----a-w- C:\FossSwimSchool.zip

2010-05-16 00:05 . 2010-05-16 00:05 401408 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\swapit\swapit.dll

2010-05-15 02:41 . 2010-05-15 02:41 40960 ----a-w- c:\windows\system32\cisvdl32.dll

2010-05-15 02:39 . 2010-05-15 02:39 20 ----a-w- c:\documents and settings\Sylvie\Application Data\wqhtpi.dat

2010-05-08 20:37 . 2008-08-29 23:59 -------- d-----w- c:\program files\Google

2010-05-08 04:37 . 2010-05-08 04:37 540672 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\scrabblecubes\scrabblecubes.dll

2010-05-08 03:32 . 2010-05-26 17:44 371200 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\RSSReader_plugin.dll

2010-05-07 17:55 . 2010-05-07 17:55 255472 ----a-w- c:\documents and settings\Sylvie\Application Data\Mozilla\plugins\npgoogletalk.dll

2010-05-07 17:09 . 2010-05-26 17:44 395776 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\emailchecker_plugin.dll

2010-05-05 22:30 . 2010-04-04 04:15 532480 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\bejeweled\bejeweled.dll

2010-05-05 17:36 . 2010-05-26 17:44 143496 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\ToolbarUpdate.exe

2010-05-01 04:04 . 2010-05-26 17:44 209408 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\SearchComponent.dll

2010-04-30 03:44 . 2010-05-26 17:44 274432 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\bookmarksplugin.dll

2010-04-29 20:39 . 2010-01-25 06:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-04-29 20:39 . 2010-01-25 06:29 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-04-23 20:56 . 2010-03-11 06:28 937984 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\plantsvzombies\plantsvzombies.dll

2010-04-06 23:51 . 2010-05-26 17:44 264704 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\statplugin.dll

2010-04-06 23:51 . 2010-05-26 17:44 276992 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\weatherplugin.dll

2010-04-06 23:51 . 2010-05-26 17:44 399360 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\RadioPlugin.dll

2010-04-06 23:51 . 2010-05-26 17:44 290304 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\msgboxplugin.dll

2010-04-06 04:28 . 2009-10-06 19:33 1055744 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\bigmoney\BigMoney.dll

2010-04-01 04:26 . 2009-10-06 19:32 972288 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\dynomite\Dynomite.dll

2010-03-31 22:58 . 2010-03-31 22:58 1956656 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{da879c19-9088-418b-a63a-2e6fb294eaf0}"= "c:\program files\AAdvantage eShoppingSM Toolbar\Helper.dll" [2010-05-26 243200]

[HKEY_CLASSES_ROOT\clsid\{da879c19-9088-418b-a63a-2e6fb294eaf0}]

[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]

[HKEY_CLASSES_ROOT\TypeLib\{26582F40-76E8-4A2A-B30C-26832801B787}]

[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5712A6BB-B6C8-4E52-A152-1BA741C9A6A2}]

2010-05-26 17:44 1558528 ----a-w- c:\program files\AAdvantage eShoppingSM Toolbar\Toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{85741F1D-ED47-4DCF-9109-07D10213C4D0}"= "c:\program files\AAdvantage eShoppingSM Toolbar\Toolbar.dll" [2010-05-26 1558528]

[HKEY_CLASSES_ROOT\clsid\{85741f1d-ed47-4dcf-9109-07d10213c4d0}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar.3]

[HKEY_CLASSES_ROOT\TypeLib\{5E8947F8-3769-4215-877F-BEA00225DC12}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{85741F1D-ED47-4DCF-9109-07D10213C4D0}"= "c:\program files\AAdvantage eShoppingSM Toolbar\Toolbar.dll" [2010-05-26 1558528]

[HKEY_CLASSES_ROOT\clsid\{85741f1d-ed47-4dcf-9109-07d10213c4d0}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar.3]

[HKEY_CLASSES_ROOT\TypeLib\{5E8947F8-3769-4215-877F-BEA00225DC12}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2008-07-30 226576]

"Google Update"="c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-09 133104]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-09-04 6856704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-16 148888]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]

"PMX Daemon"="ICO.EXE" [2006-11-08 49152]

"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-06-23 53248]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-08 98304]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]

"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-22 198160]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Microsoft Office.lnk - c:\program files\Microsoft Office XP\Office10\OSA.EXE [2001-2-13 83360]

Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2006-12-30 69632]

VPN Client.lnk - c:\windows\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [2009-12-17 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

2006-01-02 23:41 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

2007-09-04 21:40 6856704 ----a-w- c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"gusvc"=2 (0x2)

"gupdate1c9d359281aab1a"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Documents and Settings\\Sylvie\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=

"c:\\Documents and Settings\\Sylvie\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\AAdvantage eShoppingSM Toolbar\\TroubleShooter.exe"=

"c:\\Program Files\\AAdvantage eShoppingSM Toolbar\\ToolbarUpdate.exe"=

"c:\\WINDOWS\\system32\\spoolsv.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [6/1/2010 5:20 PM 218592]

R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [3/17/2006 6:25 PM 65536]

R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [3/4/2010 5:40 PM 266240]

S2 Browser Defender Update Service;Browser Defender Update Service;"c:\program files\PC Tools Security\BDT\BDTUpdateService.exe" --> c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [?]

S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [12/30/2006 12:26 PM 18432]

S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [12/30/2006 12:26 PM 14336]

S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [6/1/2010 5:19 PM 366840]

S4 gupdate1c9d359281aab1a;Google Update Service (gupdate1c9d359281aab1a);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2009 6:27 PM 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bdx REG_MULTI_SZ sysagent

.

Contents of the 'Scheduled Tasks' folder

2010-06-24 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-29 00:07]

2010-06-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 23:27]

2010-06-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 23:27]

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-886524922-2343721888-3062340848-1005Core.job

- c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-09 17:37]

2010-06-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-886524922-2343721888-3062340848-1005UA.job

- c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-09 17:37]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MI699F~1\OFFICE11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} - hxxps://ra.qwest.com/sdccommon/download/tgctlins.cab

DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} - hxxps://mail203.mmm.com/dwa85W.cab

DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} - hxxp://rms2.invokesolutions.com/events/bin/6.2.0.1452/MILive.cab

DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47}

FF - ProfilePath - c:\documents and settings\Sylvie\Application Data\Mozilla\Firefox\Profiles\15ny5g5a.default\

FF - component: c:\program files\BitDefender\BitDefender 2010\bdaphffext\components\bdaphff2.dll

FF - component: c:\program files\BitDefender\BitDefender 2010\bdaphffext\components\bdaphff3.6.dll

FF - component: c:\program files\BitDefender\BitDefender 2010\bdaphffext\components\bdaphff3.dll

FF - plugin: c:\documents and settings\Sylvie\Application Data\Move Networks\plugins\npqmp071503000010.dll

FF - plugin: c:\documents and settings\Sylvie\Application Data\Move Networks\plugins\npqmp071701000002.dll

FF - plugin: c:\documents and settings\Sylvie\Application Data\Mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll

FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr

ef", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-{B6E61364-ECC0-B049-8BA4-D309C9162509} - c:\documents and settings\Sylvie\Application Data\Ihuzqa\ozcii.exe

MSConfigStartUp-Mlafani - c:\windows\kbmdpk.dll

MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe

MSConfigStartUp-Yxiravakuleja - c:\windows\uvecekir.dll

AddRemove-{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA} - c:\program files\InstallShield Installation Information\{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}\Setup.exeUNINSTALL

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-06-23 21:34

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(984)

c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

- - - - - - - > 'explorer.exe'(6360)

c:\windows\system32\WININET.dll

c:\windows\TEMP\logishrd\LVPrcInj01.dll

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\Ati2evxx.exe

c:\program files\Cisco Systems\VPN Client\cvpnd.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

c:\progra~1\MICROS~4\MSSQL\binn\sqlservr.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\wscntfy.exe

c:\windows\system32\ICO.EXE

c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe

.

**************************************************************************

.

Completion time: 2010-06-23 21:39:38 - machine was rebooted

ComboFix-quarantined-files.txt 2010-06-24 02:39

Pre-Run: 119,530,033,152 bytes free

Post-Run: 119,401,144,320 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - F497C75FFDC22114D3520A91FFCA2E89

Link to post
Share on other sites

Hi

Check a file

  • Go to VirusTotal or Jotti's
    c:\windows\system32\cisvdl32.dll

  • Copy/Paste the file above into the white Upload a file box.
  • Click Send/Submit, and the file will upload to VirusTotal/Jotti, where it will be scanned by several anti-virus programmes.
    NOTE: if you receive a message stating:
    • File has already been analyzed,(VirusTotal) click Reanalyze file Now.
    • File has been scanned before(Jotti), click Scan again.

    [*]After a while, a window will open, with details of what the scans found.

    [*] Copy and paste the results into your next reply.

TFC

You should still have this on your desktop

  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • Click the Start button in the bottom left of TFC
  • If prompted, click "Yes" to reboot.

Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It should not take longer than a couple of minutes , and may only take a few seconds. Only if needed will you be prompted to reboot.

Malwarebytes' Anti-Malware (MBAM)

As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform Quick scan, then click on Scan
  • When done, you will be prompted. Click OK. If Items are found, then click on Show Results
  • Check all items then click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply.
    The log can also be found here:
    1. C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
    2. Or via the Logs tab when the application is started.

Note: MBAM may ask to reboot your computer so it can continue with the removal process, please do so immediately.

Failure to reboot will prevent MBAM from removing all the malware.

Link to post
Share on other sites

Thanks! Here are my results:

VirusTotal:

File cisvdl32.dll received on 2010.06.25 14:53:27 (UTC)

Current status: finished

Result: 22/40 (55%)

Antivirus Version Last Update Result

a-squared 5.0.0.30 2010.06.25 Trojan.Win32.FakeAV!IK

AhnLab-V3 2010.06.25.04 2010.06.25 Win-Trojan/Fraudpack.40960.S

AntiVir 8.2.4.2 2010.06.25 TR/FraudPack.awnf

Antiy-AVL 2.0.3.7 2010.06.25 Trojan/Win32.FraudPack.gen

Authentium 5.2.0.5 2010.06.25 W32/Trojan2.MVEN

Avast 4.8.1351.0 2010.06.25 Win32:Spyware-gen

Avast5 5.0.332.0 2010.06.25 Win32:Spyware-gen

AVG 9.0.0.836 2010.06.25 PSW.Generic7.CCBF

BitDefender 7.2 2010.06.25 -

CAT-QuickHeal 10.00 2010.06.25 -

ClamAV 0.96.0.3-git 2010.06.25 -

Comodo 5215 2010.06.25 TrojWare.Win32.FraudPack.awnf

DrWeb 5.0.2.03300 2010.06.25 -

eSafe 7.0.17.0 2010.06.24 -

eTrust-Vet 36.1.7666 2010.06.25 -

F-Prot 4.6.1.107 2010.06.24 W32/Trojan2.MVEN

F-Secure 9.0.15370.0 2010.06.25 -

Fortinet 4.1.133.0 2010.06.25 -

GData 21 2010.06.25 Win32:Spyware-gen

Ikarus T3.1.1.84.0 2010.06.25 Trojan.Win32.FakeAV

Jiangmin 13.0.900 2010.06.15 Trojan/FraudPack.vam

Kaspersky 7.0.0.125 2010.06.25 Trojan.Win32.FraudPack.awnf

McAfee 5.400.0.1158 2010.06.25 -

McAfee-GW-Edition 2010.1 2010.06.25 Artemis!80D58268EB21

Microsoft 1.5902 2010.06.25 TrojanSpy:Win32/Ursnif.gen!I

NOD32 5229 2010.06.25 -

Norman 6.05.10 2010.06.25 -

nProtect 2010-06-25.01 2010.06.25 Trojan/W32.FraudPack.40960.AF

Panda 10.0.2.7 2010.06.25 Generic Trojan

PCTools 7.0.3.5 2010.06.25 -

Rising 22.53.04.05 2010.06.25 -

Sophos 4.54.0 2010.06.25 Troj/Spyurs-Gen

Sunbelt 6504 2010.06.25 Trojan.Win32.Generic!BT

Symantec 20101.1.0.89 2010.06.25 -

TheHacker 6.5.2.0.303 2010.06.25 -

TrendMicro 9.120.0.1004 2010.06.25 -

TrendMicro-HouseCall 9.120.0.1004 2010.06.25 -

VBA32 3.12.12.5 2010.06.25 Trojan.Win32.FraudPack.awnf

ViRobot 2010.6.21.3896 2010.06.25 -

VirusBuster 5.0.27.0 2010.06.25 Trojan.FraudPack.ADYB

Additional information

File size: 40960 bytes

MD5...: 80d58268eb213e769949dbd37ddcabdf

SHA1..: 2db9aa1d5acb666ac80589efbb81ca2dc1142c66

SHA256: 720f9f28045550ba74d0013236955f12090c3dadc9e1e02868065c76a355c2f5

ssdeep: 768:a8ozMBbNHTAF8TQXYJcIa60X8ZC9C/vY80kEJJIWbX3Qqnx4Kfm6:kabyqQo

aIWX8ZCM48075bnue

PEiD..: -

PEInfo: PE Structure information

( base data )

entrypointaddress.: 0x12d8

timedatestamp.....: 0x3ab59464 (Mon Mar 19 05:08:52 2001)

machinetype.......: 0x14c (I386)

( 4 sections )

name viradd virsiz rawdsiz ntrpy md5

.text 0x1000 0x7000 0x6400 7.40 53487a496b77fb835cac350cfd623b56

.data 0x8000 0x1000 0x200 2.57 d560cc751a8c3091a30fa80c45672dd6

.cdata 0x9000 0x4000 0x3400 7.38 2ca998257b7bd797131a2f87d8087b95

.reloc 0xd000 0x1000 0x200 0.50 da3a480a74ac78c5d2d5c14435636e61

( 1 imports )

> KERNEL32.dll: ReleaseSemaphore, GetModuleHandleA, OpenSemaphoreA, CreateSemaphoreA, GetLastError

( 2 exports )

CreateProcessNotify, DllEntryPoint

RDS...: NSRL Reference Data Set

-

pdfid.: -

trid..: Win32 Executable Generic (68.0%)

Generic Win/DOS Executable (15.9%)

DOS Executable Generic (15.9%)

Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)

Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security_response/...-021223-0550-99

sigcheck:

publisher....: n/a

copyright....: n/a

product......: n/a

description..: n/a

original name: n/a

internal name: n/a

file version.: n/a

comments.....: n/a

signers......: -

signing date.: -

verified.....: Unsigned

MalwareBytes

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4238

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

6/25/2010 10:17:56 AM

mbam-log-2010-06-25 (10-17-56).txt

Scan type: Quick scan

Objects scanned: 143752

Time elapsed: 5 minute(s), 39 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Hi

Good - Thanks for that. Give me an update on how things are running after executing the CFScript below, particularly tell me if the redirects have stopped.

COMBOFIX-Script

A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use.

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    http://forums.malwarebytes.org/index.php?s=&showtopic=54528&view=findpost&p=274650

    Collect::
    c:\documents and settings\Sylvie\Application Data\wqhtpi.dat
    c:\windows\system32\cisvdl32.dll

    File::
    c:\windows\Ckozuzeqijiwa.dat
    c:\windows\Dbucimonusi.bin


  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
    CFScriptB-4.gif
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Note: When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.

  • Ensure you are connected to the internet and click OK on the message box.

===========

Link to post
Share on other sites

I'm no longer getting redirected and Google seems to be opening and searching normally. :-)

I ran ComboFix again as requested, and it prompted me that a newer version was available so I let it install the update. Here are the log results:

ComboFix 10-06-27.06 - Sylvie 06/28/2010 23:48:13.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.679 [GMT -5:00]

Running from: c:\documents and settings\Sylvie\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\Sylvie\Desktop\CFScript.txt

AV: PC Tools AntiVirus Free *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

FILE ::

"c:\windows\Ckozuzeqijiwa.dat"

"c:\windows\Dbucimonusi.bin"

file zipped: c:\documents and settings\Sylvie\Application Data\wqhtpi.dat

file zipped: c:\windows\system32\cisvdl32.dll

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Sylvie\Application Data\wqhtpi.dat

c:\windows\Ckozuzeqijiwa.dat

c:\windows\Dbucimonusi.bin

c:\windows\system32\cisvdl32.dll

c:\windows\TEMP\logishrd\LVPrcInj01.dll

.

((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))

.

2010-06-13 23:12 . 2010-06-13 23:12 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla

2010-06-02 02:14 . 2010-06-02 02:14 -------- d-----w- c:\documents and settings\Sylvie\Local Settings\Application Data\Threat Expert

2010-06-01 22:31 . 2010-06-01 22:31 -------- d-----w- c:\documents and settings\Sylvie\Application Data\BitDefender

2010-06-01 22:20 . 2010-02-05 14:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2010-06-01 22:20 . 2010-03-29 15:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2010-06-01 22:20 . 2009-11-23 18:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2010-06-01 22:20 . 2010-04-08 19:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2010-06-01 22:19 . 2010-06-29 04:34 -------- d-----w- c:\program files\PC Tools Security

2010-06-01 22:19 . 2010-06-01 22:30 -------- d-----w- c:\program files\Common Files\PC Tools

2010-06-01 22:19 . 2010-06-01 22:19 -------- d-----w- c:\documents and settings\Sylvie\Application Data\PC Tools

2010-06-01 22:19 . 2010-06-01 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-06-29 04:40 . 2008-08-29 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater

2010-06-29 04:37 . 2008-09-30 19:57 -------- d-----w- c:\documents and settings\Sylvie\Application Data\MSN6

2010-06-29 04:35 . 2008-07-27 16:20 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2010-06-26 18:06 . 2010-06-26 18:06 72346 ----a-w- c:\documents and settings\All Users\Application Data\tmp1FE.tmp

2010-06-25 17:05 . 2010-04-24 14:54 439816 ----a-w- c:\documents and settings\Sylvie\Application Data\Real\Update\setup3.10\setup.exe

2010-06-24 01:00 . 2009-06-26 19:50 -------- d-----w- c:\documents and settings\Sylvie\Application Data\Ivso

2010-06-22 15:23 . 2010-05-17 15:00 -------- d-----w- c:\documents and settings\Sylvie\Application Data\U3

2010-06-21 04:52 . 2010-05-28 05:23 356352 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\solitairerush\solitairerush.dll

2010-06-18 06:56 . 2010-01-25 06:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-06-18 05:15 . 2010-02-18 05:10 339968 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\dealornodeal\dealornodeal.dll

2010-06-11 04:06 . 2009-09-14 21:51 1235968 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\chuzzle\Chuzzle.dll

2010-06-11 04:06 . 2009-12-04 03:58 -------- d-----w- c:\documents and settings\All Users\Application Data\WorldWinner

2010-06-01 22:10 . 2010-03-15 16:28 -------- d-----w- c:\program files\BitDefender

2010-06-01 22:10 . 2010-03-15 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender

2010-06-01 22:10 . 2010-03-15 16:25 -------- d-----w- c:\program files\Common Files\BitDefender

2010-05-29 02:55 . 2009-04-14 03:37 -------- d-----w- c:\documents and settings\Sylvie\Application Data\Move Networks

2010-05-26 17:44 . 2010-05-26 17:44 -------- d-----w- c:\documents and settings\Sylvie\Application Data\FCTB000062125

2010-05-26 17:44 . 2010-05-26 17:44 113939 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\Uninst.exe

2010-05-20 05:08 . 2009-07-15 07:17 3686418 ----a-w- C:\FossSwimSchool.zip

2010-05-16 00:05 . 2010-05-16 00:05 401408 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\swapit\swapit.dll

2010-05-08 20:37 . 2008-08-29 23:59 -------- d-----w- c:\program files\Google

2010-05-08 04:37 . 2010-05-08 04:37 540672 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\scrabblecubes\scrabblecubes.dll

2010-05-08 03:32 . 2010-05-26 17:44 371200 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\RSSReader_plugin.dll

2010-05-07 17:55 . 2010-05-07 17:55 255472 ----a-w- c:\documents and settings\Sylvie\Application Data\Mozilla\plugins\npgoogletalk.dll

2010-05-07 17:09 . 2010-05-26 17:44 395776 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\emailchecker_plugin.dll

2010-05-05 22:30 . 2010-04-04 04:15 532480 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\bejeweled\bejeweled.dll

2010-05-05 17:36 . 2010-05-26 17:44 143496 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\ToolbarUpdate.exe

2010-05-01 04:04 . 2010-05-26 17:44 209408 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\SearchComponent.dll

2010-04-30 03:44 . 2010-05-26 17:44 274432 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\bookmarksplugin.dll

2010-04-29 20:39 . 2010-01-25 06:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-04-29 20:39 . 2010-01-25 06:29 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-04-23 20:56 . 2010-03-11 06:28 937984 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\plantsvzombies\plantsvzombies.dll

2010-04-06 23:51 . 2010-05-26 17:44 264704 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\statplugin.dll

2010-04-06 23:51 . 2010-05-26 17:44 276992 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\weatherplugin.dll

2010-04-06 23:51 . 2010-05-26 17:44 399360 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\RadioPlugin.dll

2010-04-06 23:51 . 2010-05-26 17:44 290304 ----a-w- c:\documents and settings\Sylvie\Application Data\FCTB000062125\Toolbar\msgboxplugin.dll

2010-04-06 04:28 . 2009-10-06 19:33 1055744 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\bigmoney\BigMoney.dll

2010-04-01 04:26 . 2009-10-06 19:32 972288 ----a-w- c:\documents and settings\All Users\Application Data\WorldWinner\dynomite\Dynomite.dll

2010-03-31 22:58 . 2010-03-31 22:58 1956656 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe

.

((((((((((((((((((((((((((((( SnapShot@2010-06-24_02.35.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-06-29 04:55 . 2010-06-29 04:55 16384 c:\windows\Temp\Perflib_Perfdata_d8.dat

+ 2010-06-29 04:55 . 2010-06-29 04:55 16384 c:\windows\Temp\Perflib_Perfdata_1b8.dat

- 2010-06-24 02:34 . 2010-06-24 02:34 16384 c:\windows\Temp\Perflib_Perfdata_1b8.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{da879c19-9088-418b-a63a-2e6fb294eaf0}"= "c:\program files\AAdvantage eShoppingSM Toolbar\Helper.dll" [2010-05-26 243200]

[HKEY_CLASSES_ROOT\clsid\{da879c19-9088-418b-a63a-2e6fb294eaf0}]

[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]

[HKEY_CLASSES_ROOT\TypeLib\{26582F40-76E8-4A2A-B30C-26832801B787}]

[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5712A6BB-B6C8-4E52-A152-1BA741C9A6A2}]

2010-05-26 17:44 1558528 ----a-w- c:\program files\AAdvantage eShoppingSM Toolbar\Toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{85741F1D-ED47-4DCF-9109-07D10213C4D0}"= "c:\program files\AAdvantage eShoppingSM Toolbar\Toolbar.dll" [2010-05-26 1558528]

[HKEY_CLASSES_ROOT\clsid\{85741f1d-ed47-4dcf-9109-07d10213c4d0}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar.3]

[HKEY_CLASSES_ROOT\TypeLib\{5E8947F8-3769-4215-877F-BEA00225DC12}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{85741F1D-ED47-4DCF-9109-07D10213C4D0}"= "c:\program files\AAdvantage eShoppingSM Toolbar\Toolbar.dll" [2010-05-26 1558528]

[HKEY_CLASSES_ROOT\clsid\{85741f1d-ed47-4dcf-9109-07d10213c4d0}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar.3]

[HKEY_CLASSES_ROOT\TypeLib\{5E8947F8-3769-4215-877F-BEA00225DC12}]

[HKEY_CLASSES_ROOT\FCTB000062125.IEToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2008-07-30 226576]

"Google Update"="c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-09 133104]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-09-04 6856704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-16 148888]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]

"PMX Daemon"="ICO.EXE" [2006-11-08 49152]

"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-06-23 53248]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-08 98304]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]

"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-22 198160]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Microsoft Office.lnk - c:\program files\Microsoft Office XP\Office10\OSA.EXE [2001-2-13 83360]

Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2006-12-30 69632]

VPN Client.lnk - c:\windows\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [2009-12-17 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

2006-01-02 23:41 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

2007-09-04 21:40 6856704 ----a-w- c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"gusvc"=2 (0x2)

"gupdate1c9d359281aab1a"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Documents and Settings\\Sylvie\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=

"c:\\Documents and Settings\\Sylvie\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\AAdvantage eShoppingSM Toolbar\\TroubleShooter.exe"=

"c:\\Program Files\\AAdvantage eShoppingSM Toolbar\\ToolbarUpdate.exe"=

"c:\\WINDOWS\\system32\\spoolsv.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [6/1/2010 5:20 PM 218592]

R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [3/17/2006 6:25 PM 65536]

R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [3/4/2010 5:40 PM 266240]

S2 Browser Defender Update Service;Browser Defender Update Service;"c:\program files\PC Tools Security\BDT\BDTUpdateService.exe" --> c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [?]

S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [12/30/2006 12:26 PM 18432]

S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [12/30/2006 12:26 PM 14336]

S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [6/1/2010 5:19 PM 366840]

S4 gupdate1c9d359281aab1a;Google Update Service (gupdate1c9d359281aab1a);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2009 6:27 PM 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bdx REG_MULTI_SZ sysagent

.

Contents of the 'Scheduled Tasks' folder

2010-06-29 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-29 00:07]

2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 23:27]

2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 23:27]

2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-886524922-2343721888-3062340848-1005Core.job

- c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-09 17:37]

2010-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-886524922-2343721888-3062340848-1005UA.job

- c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-09 17:37]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MI699F~1\OFFICE11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} - hxxps://ra.qwest.com/sdccommon/download/tgctlins.cab

DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} - hxxps://mail203.mmm.com/dwa85W.cab

DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} - hxxp://rms2.invokesolutions.com/events/bin/6.2.0.1452/MILive.cab

DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47}

FF - ProfilePath - c:\documents and settings\Sylvie\Application Data\Mozilla\Firefox\Profiles\15ny5g5a.default\

FF - component: c:\program files\BitDefender\BitDefender 2010\bdaphffext\components\bdaphff2.dll

FF - component: c:\program files\BitDefender\BitDefender 2010\bdaphffext\components\bdaphff3.6.dll

FF - component: c:\program files\BitDefender\BitDefender 2010\bdaphffext\components\bdaphff3.dll

FF - plugin: c:\documents and settings\Sylvie\Application Data\Move Networks\plugins\npqmp071503000010.dll

FF - plugin: c:\documents and settings\Sylvie\Application Data\Move Networks\plugins\npqmp071701000002.dll

FF - plugin: c:\documents and settings\Sylvie\Application Data\Mozilla\plugins\npgoogletalk.dll

FF - plugin: c:\documents and settings\Sylvie\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll

FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr

ef", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-06-28 23:55

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(984)

c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

- - - - - - - > 'explorer.exe'(8032)

c:\windows\system32\WININET.dll

c:\windows\TEMP\logishrd\LVPrcInj01.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\msi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\Ati2evxx.exe

c:\program files\Cisco Systems\VPN Client\cvpnd.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

c:\progra~1\MICROS~4\MSSQL\binn\sqlservr.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\wscntfy.exe

c:\windows\system32\ICO.EXE

c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe

.

**************************************************************************

.

Completion time: 2010-06-29 00:01:05 - machine was rebooted

ComboFix-quarantined-files.txt 2010-06-29 05:01

ComboFix2.txt 2010-06-24 02:39

Pre-Run: 119,185,309,696 bytes free

Post-Run: 119,184,711,680 bytes free

- - End Of File - - 5FDE9B6DDFC0F092A9422258DA03C289

Link to post
Share on other sites

I'm no longer getting redirected and Google seems to be opening and searching normally

Good! - We're nearly done.

The CFScript I asked you to run should have uploaded malware files on your system for analysis. Unfortunately the upload looks to have failed so I would like you to upload these files manually

  • Please click on the following LINK. A new window will open.
  • Please copy/paste the text inside the codebox below into the box marked Link to topic where this file was requested:
    http://forums.malwarebytes.org/index.php?s=&showtopic=54528&view=findpost&p=274689


  • Click the Browse button and navigate to C:\Qoobox\Quarantine
  • There should be a zip file there named [4]-Submit_Date_Time.zip
    (Where "[4]-Submit_Date_Time.zip" denotes the Date and Time stamp - EG: "[4]-Submit_2010-03-23_13:42.zip")
  • Select the zip file and click Open
  • In the Leave any comments... box, please put:
    Failed Collect::
  • Finally click SendFile
  • let me know in your next post if the upload was successful.

Update Java Runtime

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 20.

  • Go to Sun Java
  • Scroll down to where it says "JDK 6 Update 20 (JDK or JRE)"
  • Click the orange Download JRE button to the right
  • In the Platform box choose Windows.
  • Check the box to Accept License Agreement and click Continue.
  • Click on Windows Offline Installation, click on the link under it which says "jre-6u20-windows-i586.exe" and save the downloaded file to your desktop.
  • Uninstall all old versions of Java via Start > Control Panel > Add/Remove Programs:
    J2SE Runtime Environment 5.0 Update 6
    Java 6 Update 14
    Java 6 Update 7
  • Install the new version by running the newly-downloaded file with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer

TFC

  • You should still have this on your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • Click the Start button in the bottom left of TFC
  • If prompted, click "Yes" to reboot.

Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It should not take longer than a couple of minutes , and may only take a few seconds. Only if needed will you be prompted to reboot.

ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: EOLS1.gif
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: EOLS2.gif
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:

    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology

[*]Now click on: EOLS3.gif

[*]The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.

[*]When completed the Online Scan will begin automatically.

[*]Do not touch either the Mouse or keyboard during the scan otherwise it may stall.

[*]When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt

[*]Copy and paste that log as a reply to this topic.

[*]Now click on: EOLS4.gif (Selecting Uninstall application on close if you so wish)

Link to post
Share on other sites

The upload was successful, I updated Java and ran TFC, and here are my ESET results:

ESET Online Scanner:

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=7.00.6000.16981 (vista_gdr.091215-2244)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=f16a18b4eb4db342a37d6a734e4b70de

# end=finished

# remove_checked=false

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-07-01 04:22:19

# local_time=2010-06-30 11:22:19 (-0600, Central Daylight Time)

# country="United States"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=2560 16777191 100 0 0 0 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=97613

# found=3

# cleaned=0

# scan_time=3063

C:\Qoobox\Quarantine\[4]-Submit_2010-06-28_23.48.07.zip a variant of Win32/Kryptik.EFC trojan 00000000000000000000000000000000 I

C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP674\A0089466.exe a variant of Win32/Kryptik.FAX trojan 00000000000000000000000000000000 I

C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP675\A0089553.dll a variant of Win32/Kryptik.EFC trojan 00000000000000000000000000000000 I

Link to post
Share on other sites

Hi

Your log now appears to be clean.

This is my general post for when your logs show no more signs of malware - Please let me know if you still are having problems with your computer and what these problems are. If everything is good, please continue with the instructions below.

Uninstall Combofix

We Need to Remove ComboFix

  1. Please go to Start -> Run
  2. Enter "ComboFix /uninstall" (without quotes). Note the space between "ComboFix" and "/uninstall", it needs to be there.
    combofix.png
  3. Press OK (Or hit enter).
  4. Allow ComboFix to remove itself.

DeFogger Re-enable

To re-enable your Emulation drivers, double click DeFogger to run the tool.

  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK

IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

OTC by OldTimer

Download OTC by Old Timer and save it to your Desktop.

  • Double-click OTC.exe
  • Click the CleanUp! button
  • Select Yes when the Begin cleanup Process? Prompt appears
  • If you are prompted to Reboot during the cleanup, select Yes
  • The tool will delete itself once it finishes, if not delete it by yourself

===============================================================

General Security and Computer Health

Below are some steps to follow in order to dramatically lower the chances of reinfection. You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented.

  • Make sure that you keep your antivirus updated
    New viruses come out every minute, so it is essential that you have the latest signatures for your antivirus program to provide you with the best possible protection from malicious software.
    Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.
    Uninstall Tools for Major Antivirus Products
  • Security Updates for Windows, Internet Explorer & Microsoft Office
    Whenever a security problem in its software is found, Microsoft will usually create a patch so that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC. Keeping up with these patches will help to prevent malicious software being installed on your PC. Ensure you are registered for Windows updates via Start > right-click on My Computer > Properties > Automatic Updates tab or visit the Microsoft Update site on a regular basis.
    Note: The update process uses ActiveX, so you will need to use internet explorer for it and allow the ActiveX control to install.
  • Update Non-Microsoft Programs
    Microsoft isn't the only company whose products can contain security vulnerabilities. To check whether other programs running on your PC are in need of an update, you can use the Secunia Software Inspector - I suggest that you run it at least once a month.
  • Make Internet Explorer More Secure
    Internet Explorer 8 <<< Recommended Version
    For older versions please read and follow the recommendations at this site
    Internet Explorer7

Recommended Programs

I would recommend the download and installation of some or all of the following programs (if not already present), and the updating of them on a regular basis.

  • WinPatrol
    As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge. For more information, please visit HERE.
  • Malwarebytes' Anti-Malware
    As you already have Malwarebytes' Anti-Malware on board I would keep it regularly updated and run regular quick scans with it. (TIP: Cleaning out temp files can reduce scanning times.)
    Malwarebytes' Anti-Malware is an anti-malware application that can thoroughly remove even the most advanced malware. The Full version includes a number of features, including a built in protection monitor that blocks malicious processes before they even start.
  • Hosts File
    For added protection you may also like to add a host file. A simple explanation of what a Hosts file does is HERE and for more information regarding host files read HERE.
  • Install and use a firewall with outbound protection
    The Windows firewall only monitors incoming traffic, NOT outgoing. Using a software firewall in its default configuration to replace the Windows firewall greatly reduces the risk of your computer being hacked. Make sure your firewall is always enabled while your computer is connected to the internet.
    Note: You should only have one firewall installed at a time. Having more than one firewall installed at once is likely to cause conflicts and may well decrease your overall protection as well as seriously impairing the performance of your PC.
    Suggestions:

[Please note that trial pay is not needed to get any product for free.]

Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date.

Also please read this great article by Tony Klein So How Did I Get Infected In First Place

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.

Happy surfing and stay clean!

Link to post
Share on other sites

Thank you, thank you, thank you - I don't have words to say how much I appreciate your help. This has been a great experience - thanks for being so thorough and stepping me through the process. I'm amazed, impressed, grateful that you share your time and experience this way, please keep doing it, huge thanks.

I've uninstalled Combofix, re-enabled CD emulation drivers (Defogger didn't ask me to reboot, but I didn't get an error and got the 'Finished!' message so I just rebooted myself) and ran OTC. I really appreciate the advice on how to better protect my computer and will be installing all recommended apps. I noticed OTC didn't uninstall TFC - wondering if that's something I should run periodically to clean up?

Extraordinary - thanks again!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.