Jump to content

Recommended Posts

Hello all,

I'm experiencing the a Google Redirect, Background Music "virus". I also noticed that iexplore.exe is running in the Processes even when my IE8 is closed. I've ran Malwarebytes and other Virus Removal Cleaners with no luck in finding the culprit causing this. Any help to remove this is much appreciated.

Thank you,

BTI

Can anyone help?

Thanks,

Link to post
Share on other sites

post-32477-1261866970.gif

Logs will be closed if you haven't replied within 3 days

Please don't attach the scans / logs for these tools, use "copy/paste".

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Please run a new MBAM scan being sure to update before scanning.

Post the scan results

Also please describe how your computer behaves at the moment.

Please don't attach the scans / logs, use "copy/paste".

Link to post
Share on other sites

Here is the MBAM log:

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

Database version: 8187

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

11/18/2011 7:30:38 AM

mbam-log-2011-11-18 (07-30-38).txt

Scan type: Full scan (C:\|)

Objects scanned: 313029

Time elapsed: 35 minute(s), 47 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\documents and settings\jbushman\application data\Sun\Java\deployment\cache\6.0\20\59153d14-27f5de62 (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

c:\documents and settings\jbushman\application data\Sun\Java\deployment\cache\6.0\45\9f0af6d-1436dd1c (Rogue.FakeAlert) -> Quarantined and deleted successfully.

Computer's Behavior:

Computer is up-to-speed and all the programs are opening and working. Google redirects me when I click on a search link. Music randomly plays in the backgroud. When I look at the Processes, I notice that iexplore.exe is still running even when IE8 is closed.

Link to post
Share on other sites

Logs will be closed if you haven't replied within 3 days

Please don't attach the scans / logs from these scans, use "copy/paste".

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Vista and Windows 7 users:

1. These tools MUST be run from the executable. (.exe) every time you run them

2. With Admin Rights (Right click, choose "Run as Administrator")

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.

Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.

Under Main choose: Select All

Click the Empty Selected button.

  • If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser

  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download GooredFix from one of the locations below and save it to your Desktop

Download Mirror #1

Download Mirror #2

  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    TDSSKillermain.png
  • If an infected file is detected, the default action will be Cure, click on Continue.
    TDSSKillerMal-1.png
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
    TDSSKillerSuspicious.png
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    TDSSKillerCompleted.png
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

please post the contents of that log TDSSKiller log.

Also please describe how your computer behaves at the moment.

Link to post
Share on other sites

Here is the TDSSKiller Log:

14:59:32.0497 1724 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50

14:59:32.0840 1724 ============================================================

14:59:32.0840 1724 Current date / time: 2011/11/18 14:59:32.0840

14:59:32.0840 1724 SystemInfo:

14:59:32.0840 1724

14:59:32.0840 1724 OS Version: 5.1.2600 ServicePack: 3.0

14:59:32.0840 1724 Product type: Workstation

14:59:32.0840 1724 ComputerName: GJB-DC5800-19

14:59:32.0840 1724 UserName: jbushman

14:59:32.0840 1724 Windows directory: C:\WINDOWS

14:59:32.0840 1724 System windows directory: C:\WINDOWS

14:59:32.0840 1724 Processor architecture: Intel x86

14:59:32.0840 1724 Number of processors: 2

14:59:32.0840 1724 Page size: 0x1000

14:59:32.0840 1724 Boot type: Normal boot

14:59:32.0840 1724 ============================================================

14:59:34.0262 1724 Initialize success

14:59:36.0184 3132 ============================================================

14:59:36.0184 3132 Scan started

14:59:36.0184 3132 Mode: Manual;

14:59:36.0184 3132 ============================================================

14:59:39.0153 3132 Abiosdsk - ok

14:59:39.0169 3132 abp480n5 - ok

14:59:39.0231 3132 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys

14:59:39.0231 3132 ac97intc - ok

14:59:39.0278 3132 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys

14:59:39.0278 3132 ACPI - ok

14:59:39.0309 3132 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys

14:59:39.0309 3132 ACPIEC - ok

14:59:39.0356 3132 ADIHdAudAddService (53b29a84f5105a6d887b662188c93503) C:\WINDOWS\system32\drivers\ADIHdAud.sys

14:59:39.0356 3132 ADIHdAudAddService - ok

14:59:39.0466 3132 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys

14:59:39.0466 3132 adpu160m - ok

14:59:39.0481 3132 adpu320 (0ea9b1f0c6c90a509c8603775366adb7) C:\WINDOWS\system32\DRIVERS\adpu320.sys

14:59:39.0481 3132 adpu320 - ok

14:59:39.0481 3132 AEAudio (b4afcc2f911939a1c16a26e7eba7f36b) C:\WINDOWS\system32\drivers\AEAudio.sys

14:59:39.0481 3132 AEAudio - ok

14:59:39.0512 3132 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

14:59:39.0512 3132 aec - ok

14:59:39.0575 3132 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys

14:59:39.0575 3132 AFD - ok

14:59:39.0575 3132 Aha154x - ok

14:59:39.0606 3132 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys

14:59:39.0606 3132 aic78u2 - ok

14:59:39.0622 3132 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys

14:59:39.0622 3132 aic78xx - ok

14:59:39.0716 3132 AliIde - ok

14:59:39.0716 3132 amsint - ok

14:59:39.0731 3132 asc - ok

14:59:39.0731 3132 asc3350p - ok

14:59:39.0731 3132 asc3550 - ok

14:59:39.0778 3132 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

14:59:39.0778 3132 AsyncMac - ok

14:59:39.0809 3132 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

14:59:39.0809 3132 atapi - ok

14:59:39.0809 3132 Atdisk - ok

14:59:39.0841 3132 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

14:59:39.0841 3132 Atmarpc - ok

14:59:39.0872 3132 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

14:59:39.0887 3132 audstub - ok

14:59:39.0887 3132 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

14:59:39.0887 3132 Beep - ok

14:59:39.0950 3132 CBDisk (93c568904e116607df2389907a9d8899) C:\WINDOWS\system32\drivers\{1ec00332-9da9-436d-9aaa-048787df45b6}.sys

14:59:39.0950 3132 CBDisk - ok

14:59:40.0012 3132 CbFs (92bb587b4a32102a6871f2c0f1f321c6) C:\WINDOWS\system32\drivers\{E7224BCD-D889-4528-8456-60CE0724367E}.sys

14:59:40.0028 3132 CbFs - ok

14:59:40.0044 3132 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

14:59:40.0044 3132 cbidf2k - ok

14:59:40.0075 3132 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

14:59:40.0075 3132 CCDECODE - ok

14:59:40.0091 3132 cd20xrnt - ok

14:59:40.0122 3132 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

14:59:40.0122 3132 Cdaudio - ok

14:59:40.0153 3132 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

14:59:40.0153 3132 Cdfs - ok

14:59:40.0169 3132 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

14:59:40.0169 3132 Cdrom - ok

14:59:40.0169 3132 Changer - ok

14:59:40.0184 3132 CmdIde - ok

14:59:40.0184 3132 Cpqarray - ok

14:59:40.0216 3132 dac2w2k - ok

14:59:40.0294 3132 dac960nt - ok

14:59:40.0341 3132 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

14:59:40.0341 3132 Disk - ok

14:59:40.0387 3132 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys

14:59:40.0403 3132 dmboot - ok

14:59:40.0434 3132 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys

14:59:40.0434 3132 dmio - ok

14:59:40.0450 3132 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

14:59:40.0466 3132 dmload - ok

14:59:40.0481 3132 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

14:59:40.0481 3132 DMusic - ok

14:59:40.0528 3132 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys

14:59:40.0528 3132 dpti2o - ok

14:59:40.0559 3132 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

14:59:40.0559 3132 drmkaud - ok

14:59:40.0575 3132 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys

14:59:40.0575 3132 E100B - ok

14:59:40.0622 3132 e1express (8942419786970adb32b05bb7950aee72) C:\WINDOWS\system32\DRIVERS\e1e5132.sys

14:59:40.0622 3132 e1express - ok

14:59:40.0669 3132 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

14:59:40.0669 3132 Fastfat - ok

14:59:40.0700 3132 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys

14:59:40.0700 3132 Fdc - ok

14:59:40.0731 3132 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys

14:59:40.0731 3132 Fips - ok

14:59:40.0747 3132 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys

14:59:40.0747 3132 Flpydisk - ok

14:59:40.0762 3132 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys

14:59:40.0762 3132 FltMgr - ok

14:59:40.0794 3132 fqnvi (e6d35f3aa51a65eb35c1f2340154a25e) C:\WINDOWS\system32\drivers\kjnconti.sys

14:59:40.0794 3132 fqnvi - ok

14:59:40.0872 3132 FRIdrv (c223008ef742c15e825c8fac0cdd2af7) C:\WINDOWS\system32\drivers\FRIdrv.sys

14:59:40.0872 3132 FRIdrv - ok

14:59:40.0887 3132 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

14:59:40.0887 3132 Fs_Rec - ok

14:59:40.0919 3132 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

14:59:40.0919 3132 Ftdisk - ok

14:59:40.0950 3132 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys

14:59:40.0966 3132 GEARAspiWDM - ok

14:59:41.0028 3132 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

14:59:41.0028 3132 Gpc - ok

14:59:41.0059 3132 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys

14:59:41.0059 3132 HDAudBus - ok

14:59:41.0122 3132 HECI (c865d1f6d03595df213dc3c67e4e4c58) C:\WINDOWS\system32\DRIVERS\HECI.sys

14:59:41.0137 3132 HECI - ok

14:59:41.0169 3132 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys

14:59:41.0169 3132 HidUsb - ok

14:59:41.0169 3132 hpn - ok

14:59:41.0200 3132 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

14:59:41.0200 3132 HTTP - ok

14:59:41.0216 3132 i2omgmt - ok

14:59:41.0216 3132 i2omp - ok

14:59:41.0262 3132 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

14:59:41.0262 3132 i8042prt - ok

14:59:41.0278 3132 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys

14:59:41.0278 3132 i81x - ok

14:59:41.0341 3132 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys

14:59:41.0341 3132 iAimFP0 - ok

14:59:41.0341 3132 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys

14:59:41.0341 3132 iAimFP1 - ok

14:59:41.0356 3132 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys

14:59:41.0356 3132 iAimFP2 - ok

14:59:41.0356 3132 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys

14:59:41.0356 3132 iAimFP3 - ok

14:59:41.0356 3132 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys

14:59:41.0356 3132 iAimFP4 - ok

14:59:41.0372 3132 iAimFP5 (0308aef61941e4af478fa1a0f83812f5) C:\WINDOWS\system32\DRIVERS\wADV07nt.sys

14:59:41.0372 3132 iAimFP5 - ok

14:59:41.0372 3132 iAimFP6 (714038a8aa5de08e12062202cd7eaeb5) C:\WINDOWS\system32\DRIVERS\wADV08nt.sys

14:59:41.0372 3132 iAimFP6 - ok

14:59:41.0372 3132 iAimFP7 (7bb3aa595e4507a788de1cdc63f4c8c4) C:\WINDOWS\system32\DRIVERS\wADV09nt.sys

14:59:41.0372 3132 iAimFP7 - ok

14:59:41.0387 3132 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys

14:59:41.0387 3132 iAimTV0 - ok

14:59:41.0387 3132 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys

14:59:41.0387 3132 iAimTV1 - ok

14:59:41.0387 3132 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys

14:59:41.0387 3132 iAimTV3 - ok

14:59:41.0403 3132 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys

14:59:41.0403 3132 iAimTV4 - ok

14:59:41.0403 3132 iAimTV5 (791cc45de6e50445be72e8ad6401ff45) C:\WINDOWS\system32\DRIVERS\wATV10nt.sys

14:59:41.0403 3132 iAimTV5 - ok

14:59:41.0403 3132 iAimTV6 (352fa0e98bc461ce1ce5d41f64db558d) C:\WINDOWS\system32\DRIVERS\wATV06nt.sys

14:59:41.0403 3132 iAimTV6 - ok

14:59:41.0559 3132 ialm (bffa387180121df1e4646c4ced3e16ca) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys

14:59:41.0669 3132 ialm - ok

14:59:41.0763 3132 IFXTPM (2cdf483f8fc2bf3f7b93e3bdd734cfbd) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS

14:59:41.0763 3132 IFXTPM - ok

14:59:41.0809 3132 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys

14:59:41.0809 3132 Imapi - ok

14:59:41.0825 3132 ini910u - ok

14:59:41.0841 3132 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys

14:59:41.0841 3132 IntelIde - ok

14:59:41.0856 3132 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys

14:59:41.0856 3132 intelppm - ok

14:59:41.0856 3132 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

14:59:41.0856 3132 Ip6Fw - ok

14:59:41.0872 3132 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

14:59:41.0872 3132 IpFilterDriver - ok

14:59:41.0872 3132 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

14:59:41.0872 3132 IpInIp - ok

14:59:41.0903 3132 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

14:59:41.0903 3132 IpNat - ok

14:59:41.0981 3132 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys

14:59:41.0981 3132 IPSec - ok

14:59:42.0013 3132 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

14:59:42.0013 3132 IRENUM - ok

14:59:42.0044 3132 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys

14:59:42.0044 3132 isapnp - ok

14:59:42.0091 3132 Iviaspi (4ac11b2250106774f694df2db4ffed61) C:\WINDOWS\system32\drivers\iviaspi.sys

14:59:42.0091 3132 Iviaspi - ok

14:59:42.0122 3132 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

14:59:42.0122 3132 Kbdclass - ok

14:59:42.0153 3132 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

14:59:42.0153 3132 kbdhid - ok

14:59:42.0231 3132 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

14:59:42.0231 3132 kmixer - ok

14:59:42.0278 3132 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

14:59:42.0278 3132 KSecDD - ok

14:59:42.0278 3132 lbrtfdc - ok

14:59:42.0325 3132 MBAMSwissArmy (0905dc0814d738cff53577a59ccd81e0) C:\WINDOWS\system32\drivers\mbamswissarmy.sys

14:59:42.0325 3132 MBAMSwissArmy - ok

14:59:42.0356 3132 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

14:59:42.0356 3132 mnmdd - ok

14:59:42.0388 3132 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys

14:59:42.0388 3132 Modem - ok

14:59:42.0419 3132 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys

14:59:42.0419 3132 Mouclass - ok

14:59:42.0513 3132 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys

14:59:42.0513 3132 mouhid - ok

14:59:42.0544 3132 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

14:59:42.0544 3132 MountMgr - ok

14:59:42.0544 3132 mraid35x - ok

14:59:42.0559 3132 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

14:59:42.0559 3132 MRxDAV - ok

14:59:42.0606 3132 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

14:59:42.0606 3132 MRxSmb - ok

14:59:42.0638 3132 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

14:59:42.0638 3132 Msfs - ok

14:59:42.0653 3132 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

14:59:42.0653 3132 MSKSSRV - ok

14:59:42.0653 3132 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

14:59:42.0653 3132 MSPCLOCK - ok

14:59:42.0669 3132 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

14:59:42.0669 3132 MSPQM - ok

14:59:42.0747 3132 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

14:59:42.0747 3132 mssmbios - ok

14:59:42.0778 3132 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys

14:59:42.0778 3132 MSTEE - ok

14:59:42.0794 3132 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys

14:59:42.0794 3132 Mup - ok

14:59:42.0825 3132 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

14:59:42.0825 3132 NABTSFEC - ok

14:59:42.0841 3132 NAL (d02734423b59b3ac14cdfe91e9665ff0) C:\WINDOWS\system32\Drivers\iqvw32.sys

14:59:42.0856 3132 NAL - ok

14:59:42.0888 3132 NDIS (8716356e49a665bdc7b114725b60a456) C:\WINDOWS\system32\drivers\NDIS.sys

14:59:42.0903 3132 NDIS - ok

14:59:42.0981 3132 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

14:59:42.0981 3132 NdisIP - ok

14:59:43.0013 3132 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

14:59:43.0013 3132 NdisTapi - ok

14:59:43.0013 3132 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

14:59:43.0013 3132 Ndisuio - ok

14:59:43.0044 3132 NdisWan (5526cfebb619f7f763bd6a2e1b618078) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

14:59:43.0044 3132 NdisWan - ok

14:59:43.0075 3132 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys

14:59:43.0091 3132 NDProxy - ok

14:59:43.0091 3132 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

14:59:43.0091 3132 NetBIOS - ok

14:59:43.0153 3132 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

14:59:43.0153 3132 NetBT - ok

14:59:43.0216 3132 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

14:59:43.0216 3132 Npfs - ok

14:59:43.0263 3132 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

14:59:43.0263 3132 Ntfs - ok

14:59:43.0278 3132 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

14:59:43.0278 3132 Null - ok

14:59:43.0294 3132 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

14:59:43.0309 3132 NwlnkFlt - ok

14:59:43.0309 3132 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

14:59:43.0309 3132 NwlnkFwd - ok

14:59:43.0341 3132 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys

14:59:43.0341 3132 P3 - ok

14:59:43.0356 3132 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys

14:59:43.0356 3132 Parport - ok

14:59:43.0388 3132 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

14:59:43.0388 3132 PartMgr - ok

14:59:43.0419 3132 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys

14:59:43.0419 3132 ParVdm - ok

14:59:43.0481 3132 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys

14:59:43.0481 3132 PCI - ok

14:59:43.0481 3132 PCIDump - ok

14:59:43.0528 3132 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys

14:59:43.0528 3132 PCIIde - ok

14:59:43.0544 3132 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys

14:59:43.0544 3132 Pcmcia - ok

14:59:43.0559 3132 PDCOMP - ok

14:59:43.0559 3132 PDFRAME - ok

14:59:43.0559 3132 PDRELI - ok

14:59:43.0575 3132 PDRFRAME - ok

14:59:43.0575 3132 perc2 - ok

14:59:43.0575 3132 perc2hib - ok

14:59:43.0622 3132 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

14:59:43.0622 3132 PptpMiniport - ok

14:59:43.0638 3132 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

14:59:43.0638 3132 PSched - ok

14:59:43.0638 3132 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

14:59:43.0638 3132 Ptilink - ok

14:59:43.0638 3132 ql1080 - ok

14:59:43.0653 3132 Ql10wnt - ok

14:59:43.0653 3132 ql12160 - ok

14:59:43.0653 3132 ql1240 - ok

14:59:43.0669 3132 ql1280 - ok

14:59:43.0700 3132 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

14:59:43.0700 3132 RasAcd - ok

14:59:43.0716 3132 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

14:59:43.0731 3132 Rasl2tp - ok

14:59:43.0731 3132 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

14:59:43.0731 3132 RasPppoe - ok

14:59:43.0731 3132 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

14:59:43.0731 3132 Raspti - ok

14:59:43.0778 3132 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

14:59:43.0778 3132 Rdbss - ok

14:59:43.0825 3132 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

14:59:43.0841 3132 RDPCDD - ok

14:59:43.0841 3132 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

14:59:43.0841 3132 rdpdr - ok

14:59:43.0872 3132 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys

14:59:43.0872 3132 RDPWD - ok

14:59:43.0888 3132 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys

14:59:43.0903 3132 redbook - ok

14:59:43.0919 3132 regi (001b4278407f4303efc902a2b16f2453) C:\WINDOWS\system32\drivers\regi.sys

14:59:43.0919 3132 regi - ok

14:59:43.0950 3132 RimUsb (616eac1b0e48b236a5a9b8ae07fdb81c) C:\WINDOWS\system32\Drivers\RimUsb.sys

14:59:43.0966 3132 RimUsb - ok

14:59:43.0981 3132 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys

14:59:43.0981 3132 RimVSerPort - ok

14:59:44.0091 3132 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys

14:59:44.0091 3132 ROOTMODEM - ok

14:59:44.0106 3132 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

14:59:44.0106 3132 Secdrv - ok

14:59:44.0138 3132 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys

14:59:44.0138 3132 serenum - ok

14:59:44.0138 3132 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys

14:59:44.0138 3132 Serial - ok

14:59:44.0153 3132 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys

14:59:44.0153 3132 Sfloppy - ok

14:59:44.0169 3132 Simbad - ok

14:59:44.0200 3132 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys

14:59:44.0200 3132 SLIP - ok

14:59:44.0216 3132 Sparrow - ok

14:59:44.0231 3132 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

14:59:44.0247 3132 splitter - ok

14:59:44.0356 3132 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys

14:59:44.0356 3132 sr - ok

14:59:44.0388 3132 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys

14:59:44.0403 3132 Srv - ok

14:59:44.0419 3132 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

14:59:44.0419 3132 streamip - ok

14:59:44.0450 3132 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

14:59:44.0450 3132 swenum - ok

14:59:44.0466 3132 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

14:59:44.0466 3132 swmidi - ok

14:59:44.0497 3132 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys

14:59:44.0497 3132 symc810 - ok

14:59:44.0513 3132 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys

14:59:44.0513 3132 symc8xx - ok

14:59:44.0513 3132 Symmpi (f2b7e8416f508368ac6730e2ae1c614f) C:\WINDOWS\system32\DRIVERS\symmpi.sys

14:59:44.0528 3132 Symmpi - ok

14:59:44.0591 3132 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys

14:59:44.0591 3132 sym_hi - ok

14:59:44.0591 3132 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys

14:59:44.0591 3132 sym_u3 - ok

14:59:44.0622 3132 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

14:59:44.0622 3132 sysaudio - ok

14:59:44.0700 3132 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

14:59:44.0700 3132 Tcpip - ok

14:59:44.0747 3132 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

14:59:44.0747 3132 TDPIPE - ok

14:59:44.0747 3132 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

14:59:44.0747 3132 TDTCP - ok

14:59:44.0778 3132 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

14:59:44.0778 3132 TermDD - ok

14:59:44.0794 3132 TosIde - ok

14:59:44.0825 3132 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

14:59:44.0825 3132 Udfs - ok

14:59:44.0934 3132 ultra - ok

14:59:44.0997 3132 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys

14:59:44.0997 3132 USBAAPL - ok

14:59:45.0044 3132 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys

14:59:45.0044 3132 usbaudio - ok

14:59:45.0075 3132 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

14:59:45.0075 3132 usbccgp - ok

14:59:45.0091 3132 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

14:59:45.0091 3132 usbehci - ok

14:59:45.0153 3132 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

14:59:45.0153 3132 usbhub - ok

14:59:45.0247 3132 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys

14:59:45.0247 3132 usbscan - ok

14:59:45.0278 3132 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

14:59:45.0278 3132 USBSTOR - ok

14:59:45.0309 3132 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

14:59:45.0309 3132 usbuhci - ok

14:59:45.0356 3132 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys

14:59:45.0356 3132 usbvideo - ok

14:59:45.0388 3132 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

14:59:45.0388 3132 VgaSave - ok

14:59:45.0481 3132 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys

14:59:45.0497 3132 ViaIde - ok

14:59:45.0528 3132 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys

14:59:45.0528 3132 VolSnap - ok

14:59:45.0559 3132 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

14:59:45.0559 3132 Wanarp - ok

14:59:45.0606 3132 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys

14:59:45.0622 3132 Wdf01000 - ok

14:59:45.0638 3132 WDICA - ok

14:59:45.0685 3132 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

14:59:45.0685 3132 wdmaud - ok

14:59:45.0731 3132 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys

14:59:45.0731 3132 WmiAcpi - ok

14:59:45.0794 3132 WpdUsb (c1b3d9d75c3fb735f5fa3a5806aded57) C:\WINDOWS\system32\Drivers\wpdusb.sys

14:59:45.0794 3132 WpdUsb - ok

14:59:45.0966 3132 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

14:59:45.0966 3132 WSTCODEC - ok

14:59:45.0997 3132 MBR (0x1B8) (4975bdbeda8a3afb2aeadefc06ce9e12) \Device\Harddisk0\DR0

14:59:46.0044 3132 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - infected

14:59:46.0044 3132 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.b (0)

14:59:46.0075 3132 Boot (0x1200) (335ad3a2109acaa46c4b2683282da1ed) \Device\Harddisk0\DR0\Partition0

14:59:46.0122 3132 \Device\Harddisk0\DR0\Partition0 - ok

14:59:46.0122 3132 ============================================================

14:59:46.0122 3132 Scan finished

14:59:46.0122 3132 ============================================================

14:59:46.0138 1288 Detected object count: 1

14:59:46.0138 1288 Actual detected object count: 1

15:00:09.0138 1288 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - will be cured on reboot

15:00:09.0138 1288 \Device\Harddisk0\DR0 - ok

15:00:09.0138 1288 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Cure

15:00:54.0452 0332 Deinitialize success

Computer's Behavior:

Slow startup like it mentions above after running this but other than that the computer is running fine. I have not tested Google searching at the moment. Is this something you would like me to do after every run through cleaners?

Link to post
Share on other sites

We need to see if the redirections have stopped so give Google a try.

Its working now with no hiccups whatsoever. Noticed before that it would take 2-4 seconds to go to the page, which of course, was probably the redirection taking effect. I would like to test it out for the rest of today and Monday when I get back in town, to let you know that it has completely been resolve. Thanks for all your help. Please let me know if I have to run anything else.

Thanks,

BTI

Link to post
Share on other sites

How's it running?

Sorry for the late response and thanks for getting back with me. Google is not redirecting me anymore and I havent noticed iexplore.exe running in the background anymore. Also, no more music playing in the back. What I have noticed though is that while i'm watching Flash required videos, every so often the page begins to flicker and I start getting Window Line Errors popups in IE8. Then I hit "ok" and the next page to load gives me the same error. Then theres no way to use IE8 until I close the program and re-enter. Have you seen this before?

Link to post
Share on other sites

Lets see if it's a IE add-on

You can open Internet Explorer without add-ons in 2 ways. One way to open is to navigate to start menu-> All Programs-> Accessories-> System Tools-> Internet Explorer (no Add-ons). This opens up IE without ActiveX controls and browser extensions.

•Type iexplore –extoff in the Run box on the Start menu

•Click “Internet Explorer (No Add-ons)” under All Programs -> Accessories -> System Tools

•Right-clicking the IE icon on the Start Menu (if IE is your default browser) and selecting “Browse Without Add-Ons”

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.