![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: May 2009
Posts: 7
OS: xp
|
Google links redirected
Hi,
I am running Windows XP and use Google as a search engine. Google works fine and when I search for something it shows me the usual page with the results with the correct web addresses (in green). However, when I click on those to see the page, I get redirected to some random pages (advertisements). If I go back to the Google result page and click again on the link, the same happens over and over until it stops and gives me the right link (after maybe 5-6 attempts). Any idea how to fix that ? Please find below the requested DDS and attached the other 2 files. Thanks a lot in advance for your help, Best, Dav. DDS (Ver_09-05-14.01) - NTFSx86 Run by David at 13:48:36.35 on 2009-05-19 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1129 [GMT -4:00] AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} ============== Running Processes =============== C:\windows\system32\svchost -k DcomLaunch C:\windows\system32\svchost -k rpcss C:\Program Files\Windows Defender\MsMpEng.exe C:\windows\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\windows\system32\svchost.exe -k NetworkService C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\spoolsv.exe C:\windows\System32\SCardSvr.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\windows\system32\svchost.exe -k LocalService C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\basfipm.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Juniper Networks\Common Files\dsNcService.exe C:\windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\windows\keyacc32.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\windows\Explorer.EXE C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe C:\Program Files\McAfee\Common Framework\naPrdMgr.exe C:\windows\System32\svchost.exe -k HPZ12 C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\windows\System32\svchost.exe -k HPZ12 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe C:\Program Files\Spyware Terminator\sp_rsser.exe C:\windows\system32\svchost.exe -k imgsvc C:\Program Files\ThreatFire\TFService.exe C:\windows\system32\wbem\wmiprvse.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Dell\QuickSet\Quickset.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\windows\System32\alg.exe C:\windows\system32\taskswitch.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\windows\system32\wuauclt.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\Windows Defender\MSASCui.exe C:\windows\kass.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\ThreatFire\TFTray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\windows\system32\ctfmon.exe C:\Documents and Settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Comcast\Desktop Doctor\agent\bin\bcont.exe C:\Documents and Settings\David\Desktop\dds.scr C:\windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uWindow Title = Windows Internet Explorer provided by Comcast uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mWindow Title = Windows Internet Explorer provided by Comcast uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\david\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless mRun: [Dell QuickSet] c:\program files\dell\quickset\Quickset.exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2 mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [CoolSwitch] c:\windows\system32\taskswitch.exe mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [KeyAccess] kass.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: E&xporter vers Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll Notify: ssqNFWpO - ssqNFWpO.dll Notify: wintfj32 - wintfj32.dll AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll katrack.dll,c:\windows\system32\higidipe.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll STS: {E2BA40A2-74F3-42BD-F434-2604812C8953} - No File SEH: {DF986C2C-446C-49B7-913D-DBB1BAE4DC17} - No File SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL LSA: Authentication Packages = msv1_0 relog_ap c:\windows\system32\nnnoPFvS LSA: Notification Packages = scecli c:\windows\system32\higidipe.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\david\applic~1\mozilla\firefox\profiles\lfaz9fxx.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - plugin: c:\documents and settings\david\application data\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\david\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll FF - plugin: c:\program files\cambridgesoft\chemoffice2008\chem3d\npChem3DPlugin.dll FF - plugin: c:\program files\cambridgesoft\chemoffice2008\chemdraw\NPCDP32.DLL FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll ============= SERVICES / DRIVERS =============== R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-5-18 28544] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-5-19 51472] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-5-19 39184] R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2006-11-30 31944] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-14 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-14 72944] R2 KeyAccess;KeyAccess;c:\windows\keyacc32.exe [2008-10-8 1041088] R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-7-27 104000] R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\mcshield.exe [2007-2-22 144960] R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2007-2-22 54872] R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service --> c:\program files\threatfire\TFService.exe service [?] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [1979-12-31 80384] R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-7-27 72264] R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-7-27 34152] R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-7-27 170408] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-14 7408] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-5-19 33040] S3 Agilent Chemstation Data Service;Agilent Chemstation Data Service;c:\chem32\sys\DataServer.exe [2006-3-1 86098] S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [2005-10-22 223232] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2006-9-19 29744] S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344] =============== Created Last 30 ================ 2009-05-19 10:47 51,472 a------- c:\windows\system32\drivers\TfFsMon.sys 2009-05-19 10:47 39,184 a------- c:\windows\system32\drivers\TfSysMon.sys 2009-05-19 10:47 33,040 a------- c:\windows\system32\drivers\TfNetMon.sys 2009-05-19 10:47 12,560 a------- c:\windows\system32\drivers\TfKbMon.sys 2009-05-19 10:47 <DIR> --d----- c:\program files\ThreatFire 2009-05-19 10:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools 2009-05-19 09:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-05-19 09:57 <DIR> --d----- c:\program files\SUPERAntiSpyware 2009-05-19 09:57 <DIR> --d----- c:\docume~1\david\applic~1\SUPERAntiSpyware.com 2009-05-19 09:57 <DIR> --d----- c:\program files\common files\Wise Installation Wizard 2009-05-18 21:51 <DIR> --d----- c:\docume~1\david\applic~1\IObit 2009-05-18 21:51 <DIR> --d----- c:\program files\IObit 2009-05-18 21:38 142,592 a------- c:\windows\system32\drivers\sp_rsdrv2.sys 2009-05-18 21:38 <DIR> --d----- c:\docume~1\david\applic~1\Spyware Terminator 2009-05-18 21:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spyware Terminator 2009-05-18 21:38 <DIR> --d----- c:\program files\Spyware Terminator 2009-05-18 20:33 28,544 a------- c:\windows\system32\drivers\pavboot.sys 2009-05-18 20:32 <DIR> --d----- c:\program files\Panda Security 2009-05-18 20:14 <DIR> --dsh--- c:\documents and settings\david\PrivacIE 2009-05-18 10:25 21,504 a------- c:\windows\system32\hidserv.dll 2009-05-18 10:25 21,504 a------- c:\windows\system32\dllcache\hidserv.dll 2009-05-18 10:24 14,592 a------- c:\windows\system32\drivers\kbdhid.sys 2009-05-18 10:24 14,592 a------- c:\windows\system32\dllcache\kbdhid.sys 2009-05-15 18:38 <DIR> --d----- c:\windows\MSICacheSigmaPlot 2009-05-15 18:37 <DIR> --d----- c:\program files\SigmaPlot 2009-05-15 18:35 1,025 a------- c:\windows\system32\iy33zkj.tgz 2009-05-13 10:09 <DIR> --dsh--- c:\documents and settings\david\IETldCache 2009-05-12 18:28 <DIR> --d----- c:\windows\ie8updates 2009-05-12 18:26 102,400 -------- c:\windows\system32\dllcache\iecompat.dll 2009-05-12 18:22 <DIR> -cd-h--- c:\windows\ie8 2009-05-11 10:59 <DIR> --d----- c:\program files\common files\xing shared 2009-05-10 16:24 102,664 a------- c:\windows\system32\drivers\tmcomm.sys 2009-05-10 16:24 <DIR> --d----- c:\documents and settings\david\.housecall6.6 2009-05-06 13:13 <DIR> --d----- C:\New Folder 2009-04-21 14:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\CambridgeSoft 2009-04-21 13:48 <DIR> --d----- c:\program files\MestRe-C 2009-04-21 13:46 <DIR> --d----- c:\program files\CambridgeSoft 2009-04-21 13:45 <DIR> --d----- C:\CSTEMP 2009-04-19 18:30 <DIR> --d----- c:\docume~1\david\applic~1\pidle 2009-04-19 18:30 1,486 a------- c:\windows\system32\ovfsthcxnlbopxpqsxerlioepyouwrlgiyapvl.dat 2009-04-19 18:30 0 a------- C:\-1072349134 ==================== Find3M ==================== 2009-05-14 23:59 0 a------- c:\windows\system32\drivers\lvuvc.hs 2009-05-14 23:59 0 a------- c:\windows\system32\drivers\logiflt.iad 2009-05-11 10:58 348,160 a------- c:\windows\system32\msvcr71.dll 2009-05-11 10:58 499,712 a------- c:\windows\system32\msvcp71.dll 2009-03-21 10:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll 2009-03-10 22:18 934,792 -------- c:\windows\system32\dllcache\WgaTray.exe 2009-03-10 22:18 239,496 -------- c:\windows\system32\dllcache\wgaLogon.dll 2009-03-09 05:19 410,984 a------- c:\windows\system32\deploytk.dll 2009-03-08 14:09 638,816 a------- c:\windows\system32\dllcache\iexplore.exe 2009-03-08 14:09 391,536 a------- c:\windows\system32\dllcache\iedkcs32.dll 2009-03-08 04:41 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll 2009-03-08 04:39 11,063,808 a------- c:\windows\system32\dllcache\ieframe.dll 2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll 2009-03-08 04:34 914,944 a------- c:\windows\system32\dllcache\wininet.dll 2009-03-08 04:34 1,206,784 a------- c:\windows\system32\dllcache\urlmon.dll 2009-03-08 04:34 236,544 a------- c:\windows\system32\dllcache\webcheck.dll 2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll 2009-03-08 04:34 43,008 a------- c:\windows\system32\dllcache\licmgr10.dll 2009-03-08 04:34 105,984 a------- c:\windows\system32\dllcache\url.dll 2009-03-08 04:34 193,536 a------- c:\windows\system32\dllcache\msrating.dll 2009-03-08 04:34 109,568 a------- c:\windows\system32\dllcache\occache.dll 2009-03-08 04:33 759,296 a------- c:\windows\system32\dllcache\VGX.dll 2009-03-08 04:33 18,944 a------- c:\windows\system32\dllcache\corpol.dll 2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll 2009-03-08 04:33 25,600 a------- c:\windows\system32\dllcache\jsproxy.dll 2009-03-08 04:33 726,528 a------- c:\windows\system32\dllcache\jscript.dll 2009-03-08 04:33 229,376 a------- c:\windows\system32\dllcache\ieaksie.dll 2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll 2009-03-08 04:33 420,352 a------- c:\windows\system32\dllcache\vbscript.dll 2009-03-08 04:33 125,952 a------- c:\windows\system32\dllcache\ieakeng.dll 2009-03-08 04:32 72,704 a------- c:\windows\system32\dllcache\admparse.dll 2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll 2009-03-08 04:32 173,056 a------- c:\windows\system32\dllcache\ie4uinit.exe 2009-03-08 04:32 163,840 a------- c:\windows\system32\dllcache\ieakui.dll 2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll 2009-03-08 04:32 71,680 a------- c:\windows\system32\dllcache\iesetup.dll 2009-03-08 04:32 55,808 a------- c:\windows\system32\dllcache\iernonce.dll 2009-03-08 04:32 128,512 a------- c:\windows\system32\dllcache\advpack.dll 2009-03-08 04:32 94,720 a------- c:\windows\system32\dllcache\inseng.dll 2009-03-08 04:32 594,432 a------- c:\windows\system32\dllcache\msfeeds.dll 2009-03-08 04:32 1,985,024 a------- c:\windows\system32\dllcache\iertutil.dll 2009-03-08 04:32 611,840 a------- c:\windows\system32\dllcache\mstime.dll 2009-03-08 04:24 68,608 a------- c:\windows\system32\dllcache\hmmapi.dll 2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll 2009-03-08 04:22 156,160 a------- c:\windows\system32\dllcache\msls31.dll 2009-03-08 04:11 445,952 a------- c:\windows\system32\dllcache\ieapfltr.dll 2009-03-07 17:22 45,132 a------- c:\docume~1\david\applic~1\JuniperExtXP.exe 2009-03-06 10:22 284,160 a------- c:\windows\system32\pdh.dll 2009-03-06 10:22 284,160 -------- c:\windows\system32\dllcache\pdh.dll 2009-02-20 14:09 133,120 -------- c:\windows\system32\dllcache\extmgr.dll 2009-02-20 06:20 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe 2008-12-12 21:58 30,816 a------- c:\docume~1\david\applic~1\GDIPFONTCACHEV1.DAT 2008-02-02 17:25 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat 2006-02-16 12:41 10,827 a---h--- c:\program files\klustawin.GID 2006-02-02 11:45 1,105 a------- c:\program files\INSTALL.LOG 2004-07-28 15:17 137,407 a------- c:\program files\klustawin.hlp 2004-07-28 12:50 110,700 a------- c:\program files\klustawin.exe 2002-04-30 07:23 308 a------- c:\program files\klustawin.cnt 1996-10-24 13:45 59,952 a------- c:\program files\UNWISE.EXE 2006-05-03 05:06 163,328 ---shr-- c:\windows\system32\flvDX.dll 2007-02-21 06:47 31,232 ---shr-- c:\windows\system32\msfDX.dll 2008-03-16 08:30 216,064 ---shr-- c:\windows\system32\nbDX.dll 2009-01-11 01:11 0 a--sh--- c:\windows\system32\sys_drv.dat 2008-09-15 09:30 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091520080916\index.dat ============= FINISH: 13:52:11.98 =============== |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hello, and welcome to TSF.
I am currently reviewing your log. I will be back with a fix for your problem as soon as possible. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. Please be patient with me during this time. |
|
|
|
|
|
#3 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hi,
Please do the following: Download ComboFix from one of these locations: Link 1 Link 2 Link 3 VERY IMPORTANT !!! Save ComboFix.exe to your Desktop * IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here NOTE: It is very important to totally disable McAfee as it has been known to interfere with ComboFix. If you are unable to disable it, I suggest you uninstall it temporarily.
Notes: 1. Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions. Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now |
|
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: May 2009
Posts: 7
OS: xp
|
Re: Google links redirected
Hi,
Thanks for your reply. Please find attached the ComboFix.txt file requested. Thanks again, Dav. ComboFix 09-05-21.01 - David 2009-05-21 18:54.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1376 [GMT -4:00] Running from: c:\documents and settings\David\Desktop\ComboFix.exe AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\David\Application Data\.# c:\documents and settings\David\Application Data\pidle c:\documents and settings\David\Application Data\wiaserva.log c:\program files\INSTALL.LOG c:\windows\BMc3267301.txt c:\windows\BMc3267301.xml c:\windows\cookies.ini c:\windows\pskt.ini c:\windows\system32\f0gf0xo.dll c:\windows\system32\kmiuvrpy.ini c:\windows\system32\prsgrc.dll c:\windows\SYSTEM32\SvFPonnn.ini c:\windows\system32\SvFPonnn.ini2 c:\windows\system32\v2m2xrd.dll c:\windows\system32\win32x.exe c:\windows\TEMP\logishrd\LVPrcInj01.dll . ---- Previous Run ------- . c:\windows\pskt.ini c:\windows\system32\drivers\fad.sys c:\windows\system32\mcrh.tmp . ((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 ))))))))))))))))))))))))))))))) . 2009-05-21 22:41 . 2009-05-21 22:42 -------- d-----w C:\32788R22FWJFW.0.tmp 2009-05-20 23:27 . 2009-05-20 23:30 5279 ----a-w c:\documents and settings\David\Desktop.zip 2009-05-19 18:10 . 2009-03-24 18:43 43008 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll 2009-05-19 18:10 . 2009-03-24 18:43 43008 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll 2009-05-19 18:10 . 2009-03-24 18:43 338432 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll 2009-05-19 18:10 . 2009-03-24 18:42 345088 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll 2009-05-19 18:10 . 2009-03-24 18:43 235520 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff2.dll 2009-05-19 18:10 . 2009-03-24 18:42 235008 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff3.dll 2009-05-19 14:47 . 2009-03-03 16:19 39184 ----a-w c:\windows\system32\drivers\TfSysMon.sys 2009-05-19 14:47 . 2009-03-03 16:19 33040 ----a-w c:\windows\system32\drivers\TfNetMon.sys 2009-05-19 14:47 . 2009-03-03 16:19 51472 ----a-w c:\windows\system32\drivers\TfFsMon.sys 2009-05-19 14:47 . 2009-03-03 16:19 12560 ----a-w c:\windows\system32\drivers\TfKbMon.sys 2009-05-19 14:47 . 2009-05-19 14:58 -------- d-----w c:\program files\ThreatFire 2009-05-19 14:47 . 2009-05-19 14:47 -------- d-----w c:\documents and settings\All Users\Application Data\PC Tools 2009-05-19 13:58 . 2009-05-21 23:11 117760 ----a-w c:\documents and settings\David\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-05-19 13:58 . 2009-05-19 13:58 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-05-19 13:57 . 2009-05-19 13:57 -------- d-----w c:\program files\SUPERAntiSpyware 2009-05-19 13:57 . 2009-05-19 13:57 -------- d-----w c:\documents and settings\David\Application Data\SUPERAntiSpyware.com 2009-05-19 13:57 . 2009-05-19 13:57 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-05-19 03:36 . 2009-05-19 03:36 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache 2009-05-19 01:51 . 2009-05-19 13:08 -------- d-----w c:\documents and settings\David\Application Data\IObit 2009-05-19 01:51 . 2009-05-19 01:51 -------- d-----w c:\program files\IObit 2009-05-19 01:38 . 2009-05-19 01:38 6144 ----a-w c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe 2009-05-19 01:38 . 2009-05-19 01:38 5632 ----a-w c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys 2009-05-19 01:38 . 2009-05-19 01:38 142592 ----a-w c:\windows\system32\drivers\sp_rsdrv2.sys 2009-05-19 01:38 . 2009-05-19 01:39 -------- d-----w c:\documents and settings\David\Application Data\Spyware Terminator 2009-05-19 01:38 . 2009-05-19 13:08 -------- d-----w c:\documents and settings\All Users\Application Data\Spyware Terminator 2009-05-19 01:38 . 2009-05-19 13:07 -------- d-----w c:\program files\Spyware Terminator 2009-05-19 00:33 . 2008-06-19 21:24 28544 ----a-w c:\windows\system32\drivers\pavboot.sys 2009-05-19 00:32 . 2009-05-19 00:32 -------- d-----w c:\program files\Panda Security 2009-05-19 00:14 . 2009-05-19 00:14 -------- d-sh--w c:\documents and settings\David\PrivacIE 2009-05-18 14:25 . 2008-04-14 00:11 21504 ----a-w c:\windows\system32\hidserv.dll 2009-05-18 14:25 . 2008-04-14 00:11 21504 ----a-w c:\windows\system32\dllcache\hidserv.dll 2009-05-18 14:24 . 2008-04-13 18:39 14592 ----a-w c:\windows\system32\drivers\kbdhid.sys 2009-05-18 14:24 . 2008-04-13 18:39 14592 ----a-w c:\windows\system32\dllcache\kbdhid.sys 2009-05-18 13:56 . 2009-04-14 00:39 4656976 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{72E2968F-DF88-46AC-853C-9FE13F9AF12D}\mpengine.dll 2009-05-17 02:06 . 2009-05-17 02:06 -------- d-sh--w c:\documents and settings\LocalService\IETldCache 2009-05-15 22:38 . 2009-05-15 22:38 -------- d-----w c:\windows\MSICacheSigmaPlot 2009-05-15 22:37 . 2009-05-15 22:37 -------- d-----w c:\program files\SigmaPlot 2009-05-13 14:09 . 2009-05-13 14:09 -------- d-sh--w c:\documents and settings\David\IETldCache 2009-05-12 22:28 . 2009-05-12 22:28 -------- d-----w c:\windows\ie8updates 2009-05-12 22:26 . 2009-04-25 05:30 102400 ------w c:\windows\system32\dllcache\iecompat.dll 2009-05-12 22:22 . 2009-05-12 22:25 -------- dc-h--w c:\windows\ie8 2009-05-11 14:59 . 2009-05-11 14:59 -------- d-----w c:\program files\Common Files\xing shared 2009-05-11 14:55 . 2009-05-11 14:55 390664 ----a-w c:\documents and settings\David\Application Data\Real\RealPlayer\setup\AU_setup6.exe 2009-05-10 20:24 . 2009-05-10 20:24 102664 ----a-w c:\windows\system32\drivers\tmcomm.sys 2009-05-10 20:24 . 2009-05-19 00:23 -------- d-----w c:\documents and settings\David\.housecall6.6 2009-05-06 17:13 . 2009-05-06 17:13 -------- d-----w C:\New Folder . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-21 23:06 . 2007-03-12 14:01 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2009-05-21 04:03 . 2008-02-02 20:17 0 ----a-w c:\windows\system32\drivers\lvuvc.hs 2009-05-21 04:03 . 2008-02-02 21:36 0 ----a-w c:\windows\system32\drivers\logiflt.iad 2009-05-18 18:51 . 2008-04-22 19:47 -------- d-----w c:\documents and settings\David\Application Data\EndNote 2009-05-15 23:47 . 2007-03-12 14:00 -------- d-----w c:\documents and settings\David\Application Data\VideoReDoPlus 2009-05-15 22:35 . 2004-08-04 04:00 1025 ----a-w c:\windows\system32\iy33zkj.dll 2009-05-15 22:34 . 2004-08-04 04:00 1025 ----a-w c:\windows\system32\grcauth2.dll 2009-05-15 22:34 . 2004-08-04 04:00 1025 ----a-w c:\windows\system32\grcauth1.dll 2009-05-13 04:44 . 2005-10-21 21:03 81408 ----a-w c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-12 22:31 . 2008-12-22 19:05 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help 2009-05-12 22:11 . 2008-12-22 19:19 -------- d-----w c:\program files\Microsoft Works 2009-05-12 13:32 . 2008-07-07 17:46 -------- d-----w c:\documents and settings\David\Application Data\Juniper Networks 2009-05-11 14:58 . 2005-10-22 13:30 -------- d-----w c:\program files\Common Files\Real 2009-05-11 14:58 . 2003-02-21 03:42 348160 ----a-w c:\windows\system32\msvcr71.dll 2009-05-11 14:58 . 2003-03-18 21:14 499712 ----a-w c:\windows\system32\msvcp71.dll 2009-04-21 18:02 . 2009-04-21 17:48 -------- d-----w c:\program files\MestRe-C 2009-04-21 18:00 . 2009-04-21 18:00 -------- d-----w c:\documents and settings\All Users\Application Data\CambridgeSoft 2009-04-21 17:46 . 2009-04-21 17:46 -------- d-----w c:\program files\CambridgeSoft 2009-04-20 00:13 . 2005-10-22 13:46 -------- d-----w c:\program files\Spybot - Search & Destroy 2009-04-20 00:12 . 2005-10-22 13:46 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-04-19 22:30 . 2008-07-07 04:09 -------- d-----w c:\documents and settings\David\Application Data\uTorrent 2009-04-19 19:43 . 2005-10-22 13:53 -------- d-----w c:\documents and settings\David\Application Data\Skype 2009-04-19 17:02 . 2008-02-02 21:25 -------- d-----w c:\documents and settings\David\Application Data\skypePM 2009-04-14 00:39 . 2008-07-28 00:01 4656976 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2009-04-12 03:15 . 2005-10-23 12:22 -------- d-----w c:\program files\eMule 2009-04-08 02:17 . 2005-10-06 13:10 -------- d-----w c:\program files\Java 2009-04-08 02:16 . 2009-04-08 02:16 152576 ----a-w c:\documents and settings\David\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-03-24 22:33 . 2009-03-24 22:33 237264 ----a-w c:\documents and settings\David\Application Data\Mozilla\plugins\npgoogletalk.dll 2009-03-15 03:33 . 2009-03-15 03:33 152576 ----a-w c:\documents and settings\David\Application Data\Sun\Java\jre1.6.0_12\lzma.dll 2009-03-09 09:19 . 2008-12-23 10:42 410984 ----a-w c:\windows\system32\deploytk.dll 2009-03-08 08:34 . 2004-08-04 04:00 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 08:34 . 2004-08-04 04:00 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 08:33 . 2004-08-04 04:00 18944 ----a-w c:\windows\system32\corpol.dll 2009-03-08 08:33 . 2004-08-04 04:00 420352 ----a-w c:\windows\system32\vbscript.dll 2009-03-08 08:32 . 2004-08-04 04:00 72704 ----a-w c:\windows\system32\admparse.dll 2009-03-08 08:32 . 2004-08-04 04:00 71680 ----a-w c:\windows\system32\iesetup.dll 2009-03-08 08:31 . 2004-08-04 04:00 34816 ----a-w c:\windows\system32\imgutil.dll 2009-03-08 08:31 . 2004-08-04 04:00 48128 ----a-w c:\windows\system32\mshtmler.dll 2009-03-08 08:31 . 2004-08-04 04:00 45568 ----a-w c:\windows\system32\mshta.exe 2009-03-08 08:22 . 2004-08-04 04:00 156160 ----a-w c:\windows\system32\msls31.dll 2009-03-07 21:22 . 2009-03-07 21:22 45132 ----a-w c:\documents and settings\David\Application Data\JuniperExtXP.exe 2009-03-07 21:22 . 2009-03-07 21:22 45132 ----a-w c:\documents and settings\David\Application Data\JuniperExtXP.exe 2009-03-06 14:22 . 2004-08-04 04:00 284160 ----a-w c:\windows\system32\pdh.dll 2009-02-24 07:00 . 2009-02-24 07:00 45056 ----a-w c:\documents and settings\All Users\Application Data\McAfee\Common Framework\Current\EPOAGENT3000META\Plugin\0000\keyinst.exe 2006-02-16 16:41 . 2006-02-02 15:46 10827 ---ha-w c:\program files\klustawin.GID 2004-07-28 19:17 . 2006-02-02 15:45 137407 ----a-w c:\program files\klustawin.hlp 2004-07-28 16:50 . 2006-02-02 15:45 110700 ----a-w c:\program files\klustawin.exe 2002-04-30 11:23 . 2006-02-02 15:45 308 ----a-w c:\program files\klustawin.cnt 1996-10-24 17:45 . 2006-02-02 15:45 59952 ----a-w c:\program files\UNWISE.EXE 2008-09-30 14:37 . 2006-09-19 07:32 122880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2006-05-03 09:06 . 2008-10-02 21:29 163328 --sh--r c:\windows\SYSTEM32\flvDX.dll 2007-02-21 10:47 . 2008-10-02 21:29 31232 --sh--r c:\windows\SYSTEM32\msfDX.dll 2008-03-16 12:30 . 2008-10-02 21:29 216064 --sh--r c:\windows\SYSTEM32\nbDX.dll 2009-01-11 05:11 . 2009-01-11 05:11 0 --sha-w c:\windows\SYSTEM32\sys_drv.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 68856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "Google Update"="c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-20 133104] "Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-05-01 2329936] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-14 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024] "Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [2005-03-04 606208] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-30 29744] "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560] "CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-23 112216] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-11 198160] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2009-03-03 263440] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304] "KeyAccess"="kass.exe" - c:\windows\kass.exe [2008-10-08 82624] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-6 24576] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-6-14 805392] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 16:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless] 2004-09-07 15:08 110592 ----a-w c:\program files\Intel\Wireless\Bin\LgNotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 06:42 72208 ----a-w c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ETH Zürich VPN Service.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ETH Zürich VPN Service.lnk backup=c:\windows\pss\ETH Zürich VPN Service.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quick Help.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quick Help.lnk backup=c:\windows\pss\Quick Help.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk backup=c:\windows\pss\VPN Client.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^David^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\David\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0 HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BLUEWIN_McciTrayApp HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2 HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Apoint"=c:\program files\Apoint\Apoint.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\eMule\\emule.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\Adobe\\Illustrator CS\\Support Files\\Contents\\Windows\\Illustrator.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"= "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "c:\\WINDOWS\\keyacc32.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\David\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\David\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\AppliedBiosystems\\SDS2.3\\SDS2.3.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"= "c:\\WINDOWS\\SYSTEM32\\dwwin.exe"= "c:\\Program Files\\CambridgeSoft\\ChemOffice2008\\ChemDraw\\ChemDraw.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 pavboot;pavboot;c:\windows\SYSTEM32\DRIVERS\pavboot.sys [2009-05-18 28544] R0 TfFsMon;TfFsMon;c:\windows\SYSTEM32\DRIVERS\TfFsMon.sys [2009-05-19 51472] R0 TfSysMon;TfSysMon;c:\windows\SYSTEM32\DRIVERS\TfSysMon.sys [2009-05-19 39184] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-05-14 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-05-14 72944] R2 KeyAccess;KeyAccess;c:\windows\keyacc32.exe [2008-10-08 1041088] R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592] R3 GTIPCI21;GTIPCI21;c:\windows\SYSTEM32\DRIVERS\gtipci21.sys [1979-12-31 80384] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-05-14 7408] R3 TfNetMon;TfNetMon;c:\windows\SYSTEM32\DRIVERS\TfNetMon.sys [2009-05-19 33040] S3 Agilent Chemstation Data Service;Agilent Chemstation Data Service;c:\chem32\SYS\DataServer.exe [2006-03-01 86098] S3 camvid20;Philips ToUcam Camera; Video;c:\windows\SYSTEM32\DRIVERS\camdrv21.sys [2005-10-22 223232] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-09-19 29744] --- Other Services/Drivers In Memory --- *Deregistered* - mchInjDrv [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-05-19 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2009-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-633116873-3234251241-3694225674-1005.job - c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-20 16:55] 2009-05-21 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] . - - - - ORPHANS REMOVED - - - - Notify-ssqNFWpO - ssqNFWpO.dll Notify-wintfj32 - wintfj32.dll . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mWindow Title = Windows Internet Explorer provided by Comcast uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - plugin: c:\documents and settings\David\Application Data\Mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\David\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDP32.DLL FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-21 19:09 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1528) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll c:\program files\common files\logishrd\bluetooth\LBTServ.dll c:\program files\Intel\Wireless\Bin\LgNotify.dll c:\program files\ThreatFire\TFWAH.dll c:\program files\ThreatFire\TFNI.dll - - - - - - - > 'lsass.exe'(1584) c:\windows\system32\relog_ap.dll c:\program files\ThreatFire\TFWAH.dll - - - - - - - > 'explorer.exe'(5936) c:\program files\ThreatFire\TFWAH.dll c:\windows\TEMP\logishrd\LVPrcInj01.dll c:\program files\Logitech\SetPoint\lgscroll.dll c:\windows\system32\ieframe.dll c:\program files\ThreatFire\TFNI.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Intel\Wireless\Bin\WLKEEPER.exe c:\windows\SYSTEM32\scardsvr.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\windows\SYSTEM32\BAsfIpM.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Cisco Systems\VPN Client\cvpnd.exe c:\program files\Juniper Networks\Common Files\dsNcService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\program files\McAfee\Common Framework\FrameworkService.exe c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe c:\program files\McAfee\Common Framework\naPrdMgr.exe c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe c:\program files\Spyware Terminator\sp_rsser.exe c:\program files\ThreatFire\TFService.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\McAfee\Common Framework\Mctray.exe c:\program files\Common Files\LogiShrd\KHAL2\KHALMNPR.exe c:\program files\McAfee\VirusScan Enterprise\mcshield.exe . ************************************************************************** . Completion time: 2009-05-21 19:20 - machine was rebooted ComboFix-quarantined-files.txt 2009-05-21 23:20 Pre-Run: 19,939,090,432 bytes free Post-Run: 20,051,374,080 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\windows [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\windows="Microsoft Windows XP Professional" /noexecute=optin /fastdetect Current=4 Default=4 Failed=1 LastKnownGood=3 Sets=1,2,3,4 410 --- E O F --- 2009-05-18 13:56 Last edited by Ried; 05-21-2009 at 05:39 PM. |
|
|
|
|
|
#5 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hi,
Please do the following:
Here's how to do that: Click Start > Run type Notepad click OK. This will open an empty notepad file: Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy') Code:
http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/377865-google-links-redirected.html#post2148757 Suspect::[28] c:\windows\system32\iy33zkj.dll c:\windows\system32\grcauth2.dll c:\windows\system32\grcauth1.dll FileLook:: c:\windows\system32\iy33zkj.dll c:\windows\system32\grcauth2.dll c:\windows\system32\grcauth1.dll File:: c:\windows\system32\drivers\lvuvc.hs c:\windows\system32\drivers\logiflt.iad Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste') Save this file to your desktop, Save this as "CFScript" Here's how to do that: 1.Click File; 2.Click Save As... Change the directory to your desktop; 3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript 5.Click Save ... ![]()
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. |
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: May 2009
Posts: 7
OS: xp
|
Re: Google links redirected
Hi,
here is the log. Thanks Dav. ComboFix 09-05-21.01 - David 2009-05-22 0:56.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1517 [GMT -4:00] Running from: c:\documents and settings\David\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\David\Desktop\CFScript.txt AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} * Resident AV is active file zipped: c:\windows\SYSTEM32\Suspect_grcauth1.dll.vir file zipped: c:\windows\SYSTEM32\Suspect_grcauth2.dll.vir file zipped: c:\windows\SYSTEM32\Suspect_iy33zkj.dll.vir . The following files were disabled during the run: c:\windows\TEMP\logishrd\LVPrcInj01.dll ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\TEMP\logishrd\LVPrcInj01.dll c:\windows\TEMP\logishrd\LVPrcInj01.dll . . . . failed to delete . ((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-22 12:41 . 2009-05-19 13:58 117760 ----a-w c:\documents and settings\David\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-05-22 05:05 . 2007-03-12 14:01 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2009-05-22 05:05 . 2005-10-06 13:01 2048 --s-a-w c:\windows\BOOTSTAT.DAT 2009-05-22 05:05 . 2008-07-27 03:21 4194304000 --sha-w C:\pagefile.sys 2009-05-22 05:04 . 2005-10-21 17:35 11010048 ---ha-w c:\documents and settings\David\NTUSER.DAT 2009-05-22 05:04 . 1980-01-01 12:00 1310720 ---ha-w c:\documents and settings\NetworkService\NTUSER.DAT 2009-05-22 05:04 . 1980-01-01 12:00 1310720 ---ha-w c:\documents and settings\LocalService\NTUSER.DAT 2009-05-22 04:39 . 2009-05-22 04:39 389120 ----a-w c:\windows\system32\CF2886.exe 2009-05-22 04:35 . 2006-01-02 20:34 -------- d-----w c:\program files\Mozilla Firefox 2009-05-22 04:34 . 2009-05-19 01:38 -------- d-----w c:\documents and settings\All Users\Application Data\Spyware Terminator 2009-05-22 04:34 . 2009-05-19 01:38 -------- d-----w c:\program files\Spyware Terminator 2009-05-21 23:33 . 2009-05-19 01:38 -------- d-----w c:\documents and settings\David\Application Data\Spyware Terminator 2009-05-21 22:59 . 2005-10-06 12:47 -------- d-----w c:\program files\Common Files 2009-05-21 04:03 . 2008-02-02 20:17 0 ----a-w c:\windows\system32\drivers\lvuvc.hs 2009-05-21 04:03 . 2008-02-02 21:36 0 ----a-w c:\windows\system32\drivers\logiflt.iad 2009-05-21 00:37 . 2009-05-21 22:44 130048 ----a-w c:\windows\PEV.exe 2009-05-20 23:30 . 2009-05-20 23:27 5279 ----a-w c:\documents and settings\David\Desktop.zip 2009-05-19 15:38 . 2006-01-02 20:28 -------- d-----w c:\documents and settings\David\Application Data\Mozilla 2009-05-19 14:58 . 2009-05-19 14:47 -------- d-----w c:\program files\ThreatFire 2009-05-19 14:47 . 2009-05-19 14:47 -------- d-----w c:\documents and settings\All Users\Application Data\PC Tools 2009-05-19 13:58 . 2009-05-19 13:58 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-05-19 13:57 . 2009-05-19 13:57 -------- d-----w c:\program files\SUPERAntiSpyware 2009-05-19 13:57 . 2009-05-19 13:57 -------- d-----w c:\documents and settings\David\Application Data\SUPERAntiSpyware.com 2009-05-19 13:57 . 2009-05-19 13:57 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-05-19 13:08 . 2009-05-19 01:51 -------- d-----w c:\documents and settings\David\Application Data\IObit 2009-05-19 01:51 . 2009-05-19 01:51 -------- d-----w c:\program files\IObit 2009-05-19 01:38 . 2009-05-19 01:38 6144 ----a-w c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe 2009-05-19 01:38 . 2009-05-19 01:38 5632 ----a-w c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys 2009-05-19 01:38 . 2009-05-19 01:38 142592 ----a-w c:\windows\system32\drivers\sp_rsdrv2.sys 2009-05-19 00:32 . 2009-05-19 00:32 -------- d-----w c:\program files\Panda Security 2009-05-18 18:51 . 2008-04-22 19:47 -------- d-----w c:\documents and settings\David\Application Data\EndNote 2009-05-15 23:47 . 2007-03-12 14:00 -------- d-----w c:\documents and settings\David\Application Data\VideoReDoPlus 2009-05-15 22:37 . 2009-05-15 22:37 -------- d-----w c:\program files\SigmaPlot 2009-05-15 22:35 . 2004-08-04 04:00 1025 ----a-w c:\windows\system32\iy33zkj.dll 2009-05-15 22:34 . 2004-08-04 04:00 1025 ----a-w c:\windows\system32\grcauth2.dll 2009-05-15 22:34 . 2004-08-04 04:00 1025 ----a-w c:\windows\system32\grcauth1.dll 2009-05-13 14:08 . 2004-08-11 16:20 300128 ----a-w c:\windows\system32\FNTCACHE.DAT 2009-05-13 14:08 . 2005-10-06 12:47 -------- d-----w c:\program files\Internet Explorer 2009-05-13 04:44 . 2005-10-21 21:03 81408 ----a-w c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-12 22:31 . 2008-12-22 19:05 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help 2009-05-12 22:12 . 2005-10-06 12:47 -------- d-----w c:\program files\Common Files\Microsoft Shared 2009-05-12 22:11 . 2008-12-22 19:19 -------- d-----w c:\program files\Microsoft Works 2009-05-12 13:32 . 2008-07-07 17:46 -------- d-----w c:\documents and settings\David\Application Data\Juniper Networks 2009-05-11 14:59 . 2009-05-11 14:59 -------- d-----w c:\program files\Common Files\xing shared 2009-05-11 14:58 . 2005-10-22 13:30 -------- d-----w c:\program files\Common Files\Real 2009-05-11 14:58 . 2005-10-22 13:31 185920 ----a-w c:\windows\system32\rmoc3260.dll 2009-05-11 14:58 . 2005-10-22 13:31 6656 ----a-w c:\windows\system32\pndx5016.dll 2009-05-11 14:58 . 2005-10-22 13:31 5632 ----a-w c:\windows\system32\pndx5032.dll 2009-05-11 14:58 . 2003-02-21 03:42 348160 ----a-w c:\windows\system32\msvcr71.dll 2009-05-11 14:58 . 2005-10-22 13:31 278528 ----a-w c:\windows\system32\pncrt.dll 2009-05-11 14:58 . 2003-03-18 21:14 499712 ----a-w c:\windows\system32\msvcp71.dll 2009-05-11 14:55 . 2009-05-11 14:55 390664 ----a-w c:\documents and settings\David\Application Data\Real\RealPlayer\setup\AU_setup6.exe 2009-05-10 20:24 . 2009-05-10 20:24 102664 ----a-w c:\windows\system32\drivers\tmcomm.sys 2009-05-07 04:16 . 2009-05-12 22:18 24699336 ----a-w c:\windows\system32\MRT.exe 2009-05-06 18:06 . 2009-05-22 10:31 4784464 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{ACD75B99-7995-45EB-AF69-45C94314E6AD}\mpengine.dll 2009-04-30 19:50 . 2005-10-22 14:02 -------- d-----w c:\documents and settings\All Users\Application Data\Adobe 2009-04-30 19:50 . 2005-10-22 14:00 -------- d-----w c:\documents and settings\David\Application Data\Adobe 2009-04-21 18:02 . 2009-04-21 17:48 -------- d-----w c:\program files\MestRe-C 2009-04-21 18:00 . 2009-04-21 18:00 -------- d-----w c:\documents and settings\All Users\Application Data\CambridgeSoft 2009-04-21 17:46 . 2009-04-21 17:46 -------- d-----w c:\program files\CambridgeSoft 2009-04-20 16:56 . 2008-07-27 02:24 31232 ----a-w c:\windows\Nircmd.exe 2009-04-20 00:13 . 2005-10-22 13:46 -------- d-----w c:\program files\Spybot - Search & Destroy 2009-04-20 00:12 . 2005-10-22 13:46 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-04-19 22:30 . 2008-07-07 04:09 -------- d-----w c:\documents and settings\David\Application Data\uTorrent 2009-04-19 19:43 . 2005-10-22 13:53 -------- d-----w c:\documents and settings\David\Application Data\Skype 2009-04-19 17:02 . 2008-02-02 21:25 -------- d-----w c:\documents and settings\David\Application Data\skypePM 2009-04-18 20:38 . 2005-10-06 13:00 72920 ----a-w c:\windows\system32\PERFC009.DAT 2009-04-18 20:38 . 2005-10-06 13:00 445498 ----a-w c:\windows\system32\PERFH009.DAT 2009-04-14 00:39 . 2008-07-28 00:01 4656976 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2009-04-12 03:15 . 2005-10-23 12:22 -------- d-----w c:\program files\eMule 2009-04-08 02:17 . 2005-10-06 13:10 -------- d-----w c:\program files\Java 2009-04-08 02:16 . 2009-04-08 02:16 152576 ----a-w c:\documents and settings\David\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-03-24 22:33 . 2009-03-24 22:33 237264 ----a-w c:\documents and settings\David\Application Data\Mozilla\plugins\npgoogletalk.dll 2009-03-24 18:43 . 2009-05-19 18:10 43008 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll 2009-03-24 18:43 . 2009-05-19 18:10 43008 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll 2009-03-24 18:43 . 2009-05-19 18:10 235520 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff2.dll 2009-03-24 18:43 . 2009-05-19 18:10 338432 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll 2009-03-24 18:42 . 2009-05-19 18:10 235008 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff3.dll 2009-03-24 18:42 . 2009-05-19 18:10 345088 ----a-w c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll 2009-03-21 14:06 . 2004-08-04 04:00 989696 ----a-w c:\windows\system32\kernel32.dll 2009-03-15 03:33 . 2009-03-15 03:33 152576 ----a-w c:\documents and settings\David\Application Data\Sun\Java\jre1.6.0_12\lzma.dll 2009-03-11 02:18 . 2006-06-19 14:19 1482112 ----a-w c:\windows\system32\LegitCheckControl.dll 2009-03-11 02:18 . 2006-06-19 14:19 934792 ------w c:\windows\system32\WgaTray.exe 2009-03-11 02:18 . 2006-06-19 14:20 239496 ----a-w c:\windows\system32\WgaLogon.dll 2009-03-09 09:19 . 2009-04-08 02:18 148888 ----a-w c:\windows\system32\javaws.exe 2009-03-09 09:19 . 2009-04-08 02:18 144792 ----a-w c:\windows\system32\javaw.exe 2009-03-09 09:19 . 2009-04-08 02:18 144792 ----a-w c:\windows\system32\java.exe 2009-03-09 09:19 . 2008-12-23 10:42 410984 ----a-w c:\windows\system32\deploytk.dll 2009-03-08 18:09 . 2004-08-04 04:00 391536 ----a-w c:\windows\system32\iedkcs32.dll 2009-03-08 08:41 . 2004-08-04 04:00 5937152 ----a-w c:\windows\system32\mshtml.dll 2009-03-08 08:39 . 2007-08-13 22:54 11063808 ----a-w c:\windows\system32\ieframe.dll 2009-03-08 08:34 . 2004-08-04 04:00 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 08:34 . 2004-08-04 04:00 1206784 ----a-w c:\windows\system32\urlmon.dll 2009-03-08 08:34 . 2007-08-13 22:45 208384 ----a-w c:\windows\system32\WinFXDocObj.exe 2009-03-08 08:34 . 2004-08-04 04:00 236544 ----a-w c:\windows\system32\webcheck.dll 2009-03-08 08:34 . 2004-08-04 04:00 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 08:34 . 2004-08-04 04:00 105984 ----a-w c:\windows\system32\url.dll 2009-03-08 08:34 . 2004-08-04 04:00 193536 ----a-w c:\windows\system32\msrating.dll 2009-03-08 08:34 . 2004-08-04 04:00 109568 ----a-w c:\windows\system32\occache.dll 2009-03-08 08:33 . 2004-08-04 04:00 18944 ----a-w c:\windows\system32\corpol.dll 2008-09-30 14:37 . 2006-09-19 07:32 122880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2006-05-03 09:06 . 2008-10-02 21:29 163328 --sh--r c:\windows\SYSTEM32\flvDX.dll 2007-02-21 10:47 . 2008-10-02 21:29 31232 --sh--r c:\windows\SYSTEM32\msfDX.dll 2008-03-16 12:30 . 2008-10-02 21:29 216064 --sh--r c:\windows\SYSTEM32\nbDX.dll 2009-01-11 05:11 . 2009-01-11 05:11 0 --sha-w c:\windows\SYSTEM32\sys_drv.dat . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . --- c:\windows\system32\grcauth1.dll --- Company: !VERINFO: NOT PE FILE! File Description: !VERINFO: NOT PE FILE! File Version: !VERINFO: NOT PE FILE! Product Name: !VERINFO: NOT PE FILE! Copyright: !VERINFO: NOT PE FILE! Original Filename: !VERINFO: NOT PE FILE! File size: 1025 Created time: 2004-08-04 04:00 Modified time: 2009-05-15 22:34 MD5: 9B8B8C0A2639E1FA77574C8F0AA7C1A3 SHA1: 47C26678FF25E76F4C9A1A5C54F62CB9E76C0B75 --- c:\windows\system32\grcauth2.dll --- Company: !VERINFO: NOT PE FILE! File Description: !VERINFO: NOT PE FILE! File Version: !VERINFO: NOT PE FILE! Product Name: !VERINFO: NOT PE FILE! Copyright: !VERINFO: NOT PE FILE! Original Filename: !VERINFO: NOT PE FILE! File size: 1025 Created time: 2004-08-04 04:00 Modified time: 2009-05-15 22:34 MD5: 9B8B8C0A2639E1FA77574C8F0AA7C1A3 SHA1: 47C26678FF25E76F4C9A1A5C54F62CB9E76C0B75 --- c:\windows\system32\iy33zkj.dll --- Company: !VERINFO: NOT PE FILE! File Description: !VERINFO: NOT PE FILE! File Version: !VERINFO: NOT PE FILE! Product Name: !VERINFO: NOT PE FILE! Copyright: !VERINFO: NOT PE FILE! Original Filename: !VERINFO: NOT PE FILE! File size: 1025 Created time: 2004-08-04 04:00 Modified time: 2009-05-15 22:35 MD5: A923770E31FCC8FE88F055C04380863C SHA1: 2E9EB5B0897B143E8EF47C4895448AFF7E5A6B98 ((((((((((((((((((((((((((((( SnapShot@2009-05-21_23.11.26 ))))))))))))))))))))))))))))))))))))))))) . + 2009-05-22 04:43 . 2009-05-22 04:43 16384 c:\windows\Temp\Perflib_Perfdata_55c.dat + 2009-05-22 05:05 . 2009-05-22 05:05 16384 c:\windows\Temp\Perflib_Perfdata_4f0.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-6 24576] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-6-14 805392] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ETH Zürich VPN Service.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ETH Zürich VPN Service.lnk backup=c:\windows\pss\ETH Zürich VPN Service.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quick Help.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quick Help.lnk backup=c:\windows\pss\Quick Help.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk backup=c:\windows\pss\VPN Client.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^David^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\David\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Apoint"=c:\program files\Apoint\Apoint.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\eMule\\emule.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\Adobe\\Illustrator CS\\Support Files\\Contents\\Windows\\Illustrator.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"= "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "c:\\WINDOWS\\keyacc32.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\David\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\David\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\AppliedBiosystems\\SDS2.3\\SDS2.3.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"= "c:\\WINDOWS\\SYSTEM32\\dwwin.exe"= "c:\\Program Files\\CambridgeSoft\\ChemOffice2008\\ChemDraw\\ChemDraw.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 pavboot;pavboot;c:\windows\SYSTEM32\DRIVERS\pavboot.sys [2009-05-18 28544] R0 TfFsMon;TfFsMon;c:\windows\SYSTEM32\DRIVERS\TfFsMon.sys [2009-05-19 51472] R0 TfSysMon;TfSysMon;c:\windows\SYSTEM32\DRIVERS\TfSysMon.sys [2009-05-19 39184] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-05-14 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-05-14 72944] R2 KeyAccess;KeyAccess;c:\windows\keyacc32.exe [2008-10-08 1041088] R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592] R3 GTIPCI21;GTIPCI21;c:\windows\SYSTEM32\DRIVERS\gtipci21.sys [1979-12-31 80384] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-05-14 7408] R3 TfNetMon;TfNetMon;c:\windows\SYSTEM32\DRIVERS\TfNetMon.sys [2009-05-19 33040] S3 Agilent Chemstation Data Service;Agilent Chemstation Data Service;c:\chem32\SYS\DataServer.exe [2006-03-01 86098] S3 camvid20;Philips ToUcam Camera; Video;c:\windows\SYSTEM32\DRIVERS\camdrv21.sys [2005-10-22 223232] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-09-19 29744] --- Other Services/Drivers In Memory --- *Deregistered* - mchInjDrv [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-05-19 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2009-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-633116873-3234251241-3694225674-1005.job - c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-20 16:55] 2009-05-22 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mWindow Title = Windows Internet Explorer provided by Comcast uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\lfaz9fxx.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - plugin: c:\documents and settings\David\Application Data\Mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\David\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDP32.DLL FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-22 08:39 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1528) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll c:\program files\common files\logishrd\bluetooth\LBTServ.dll c:\program files\ThreatFire\TFWAH.dll c:\program files\ThreatFire\TFNI.dll c:\program files\Intel\Wireless\Bin\LgNotify.dll - - - - - - - > 'lsass.exe'(1584) c:\windows\system32\relog_ap.dll c:\program files\ThreatFire\TFWAH.dll - - - - - - - > 'explorer.exe'(7936) c:\program files\ThreatFire\TFWAH.dll c:\windows\TEMP\logishrd\LVPrcInj01.dll c:\program files\Logitech\SetPoint\lgscroll.dll c:\windows\system32\ieframe.dll c:\program files\ThreatFire\TFNI.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Intel\Wireless\Bin\WLKEEPER.exe c:\windows\SYSTEM32\scardsvr.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\windows\SYSTEM32\BAsfIpM.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Cisco Systems\VPN Client\cvpnd.exe c:\program files\Juniper Networks\Common Files\dsNcService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\program files\McAfee\Common Framework\FrameworkService.exe c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe c:\program files\McAfee\Common Framework\naPrdMgr.exe c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe c:\program files\Spyware Terminator\sp_rsser.exe c:\program files\ThreatFire\TFService.exe c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe c:\program files\Intel\Wireless\Bin\iFrmewrk.exe c:\program files\Dell\QuickSet\quickset.exe c:\windows\SYSTEM32\dla\tfswctrl.exe c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe c:\windows\SYSTEM32\TaskSwitch.exe c:\program files\McAfee\VirusScan Enterprise\shstat.exe c:\program files\McAfee\Common Framework\UdaterUI.exe c:\windows\kass.exe c:\program files\Java\jre6\bin\jusched.exe c:\program files\McAfee\Common Framework\Mctray.exe c:\program files\Common Files\Real\Update_OB\realsched.exe c:\program files\Microsoft Office\Office12\GrooveMonitor.exe c:\program files\ThreatFire\TFTray.exe c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe c:\program files\IObit\Advanced SystemCare 3\AWC.exe c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe c:\program files\Common Files\LogiShrd\KHAL2\KHALMNPR.exe c:\program files\McAfee\VirusScan Enterprise\mcshield.exe . ************************************************************************** . Completion time: 2009-05-22 8:50 - machine was rebooted ComboFix-quarantined-files.txt 2009-05-22 12:50 ComboFix2.txt 2009-05-21 23:20 Pre-Run: 20,067,155,968 bytes free Post-Run: 20,053,491,712 bytes free Current=4 Default=4 Failed=1 LastKnownGood=3 Sets=1,2,3,4 412 --- E O F --- 2009-05-22 10:31 |
|
|
|
|
|
#7 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hi,
We need to submit some suspicious files for analysis: First we need to find and identify the file to upload, it will be a zip file. There should be a file named [28]-Submit_(date@time).zip with today's date, located here: C:\QooBox\Quarantine\[28]-Submit_(date@time).zipUsing the 'Browse' button located at the following link, please submit it to this site ==> http://www.bleepingcomputer.com/subm...php?channel=28 Please let me know if you successfully submitted the file. Thanks. ===================== |
|
|
|
|
|
#9 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hi,
As mentioned in our pre-posting topic: NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help P2P - I see you have peer2peer programs µTorrent and eMule installed on your computer. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity will always make you more susceptible to infection. It likely contributed to your current situation. This page will give you further information. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. Please see this topic for more information: Perils of P2P File Sharing. I would strongly recommend that you uninstall these programs now.
NEXT You have some old Java programs still on your system. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and.
NEXT Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.) For Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
Last edited by CatByte; 05-22-2009 at 11:45 AM. |
|
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: May 2009
Posts: 7
OS: xp
|
Re: Google links redirected
Hi,
I cannot download the Kaspersky WebScanner. Here is the error message that pops up after 3 minutes of downloading: Update has failed. Program has failed to start. Close the Kaspersky Online Scanner 7.0 window and open it again to install the program. You must be online to update the Kaspersky Online Scanner 7.0 database. With the latest database updates, you can find new viruses and other threats. Please go online to use Kaspersky Online Scanner 7.0. [ERROR: Invalid file signature] Any idea what happened ? I repeated the procedure several times and I always get that same message. Hope you have a solution, Cheers, Dav. |
|
|
|
|
|
#11 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hi,
It usually means the site is really busy. Try this scan instead. Please run the following online scan: Eset Online Scanner
|
|
|
|
|
|
#12 (permalink) |
|
Registered User
Join Date: May 2009
Posts: 7
OS: xp
|
Re: Google links redirected
Hi,
Here is the log of Eset Online Scanner. Thanks, Dav. ESETSmartInstaller@High as downloader log: all ok # version=6 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=e28fa8706689ef4fa98e77a40fda5b48 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-05-22 11:29:40 # local_time=2009-05-22 07:29:40 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=5889 61 66 100 674745903437500 # compatibility_mode=7937 61 100 100 3378672187500 # scanned=249288 # found=9 # cleaned=0 # scan_time=9075 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DNSFlushcws1.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DNSFlushcws3.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\IRCcrt1.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\kmiuvrpy.ini.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\SvFPonnn.ini.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\SvFPonnn.ini2.vir Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP882\A0200856.exe Win32/Spy.Zbot.PJ trojan 00000000000000000000000000000000 C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP911\A0208763.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP911\A0208764.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 |
|
|
|
|
|
#13 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hi,
When files found by other scanners are in the Recovery directory inside the Spybot-S&D directory, it is only a backup. It is no longer of any harm there, as the file won't be loaded from there. But once you are sure you don't need the backup, go to the Recovery section inside Spybot-S&D and purge the files. Open Spybot.
The rest of what ESET found is in quarantine or old sytem restore points which we will clean up now: Please do the following: Visit ADOBEand download the latest version of Acrobat Reader (version 9,1) Having the latest updates ensures there are no security vulnerabilities in your system. NEXT You can delete the DDS and GMER folders from your desktop. NEXT Follow these steps to uninstall Combofix
![]() NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
|
|
#14 (permalink) |
|
Registered User
Join Date: May 2009
Posts: 7
OS: xp
|
Re: Google links redirected
Thank you so much for your help !
It looks like my computer is cleaner now. Last question: I have about 70 processes running at the same time when my computer is on. I was wondering if there was a way to scan/delete unnecessary processes, or at least know what they are for. If you had some info about that, it would be great ! Thanks again for your help, Best, Dav. |
|
|
|
|
|
#15 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Google links redirected
Hi,
Check this site HEREfor the unnecessary startup process list by RubbeR DuckY You can also check Bleeping Computer's site for the startup programs list to determine what they are for. It is normal to have a large number of processes running - most of them are necessary. You can also check IS YOUR PC RUNNING SLOW |
|
|
|
![]() |
| Thread Tools | |
|
|