I downloaded a malicious file(s) and now am experiencing the following symptoms:
1. Persistent pop ups
2. Google searches made using any other field besides the google homepage result in a redirect to a Babylon search results page. Yahoo searches seem unaffected.
3. Running GMER in regular operating mode results in a blue screen crash. Runs ok is safe mode.
4. Malwarebytes did not detect any threats.
5. AVG detects one or more threats and then blocks them upon start up in some cases.
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Johnson at 18:48:36.67 on Sat 04/02/2011
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.907 [GMT -8:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\DOCUME~1\Johnson\LOCALS~1\Temp\Lqs.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\Lsiqoa.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\AVG\AVG9\avgscanx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Documents and Settings\Johnson\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Johnson\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Johnson\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Johnson\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Johnson\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Johnson\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Google Update] "c:\documents and settings\johnson\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [IKXGVMFZHI] c:\docume~1\johnson\locals~1\temp\Lqr.exe
mRun: [8169Diag] c:\program files\realtek\diagnostics utility\8169Diag.exe /hw
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [DigidesignMMERefresh] c:\program files\digidesign\drivers\MMERefresh.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\docume~1\johnson\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\johnson\applic~1\mozilla\firefox\profiles\4o8tgvys.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=17823
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=adbartrp&AF=17823&q=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\johnson\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: StumbleUpon: {AE93811A-5C9A-4d34-8462-F7B864FC4696} - %profile%\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg9\Firefox
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-7-8 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-7-8 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-7-8 243024]
R3 a4djavs;Audio 4 DJ WDM Audio;c:\windows\system32\drivers\a4djavs.sys [2011-1-11 342096]
R3 a4djusb_svc;Audio 4 DJ;c:\windows\system32\drivers\a4djusb.sys [2011-1-11 88656]
R3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [2009-10-13 11264]
S1 AAAAAAa;AAAAAAa;c:\windows\system32\drivers\aaaaaaa.sys --> c:\windows\system32\drivers\AAAAAAa.sys [?]
S2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys --> c:\windows\system32\drivers\diginet.sys [?]
.
=============== Created Last 30 ================
.
2011-04-03 01:58:14 388096 ----a-r- c:\docume~1\johnson\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-04-03 01:58:13 -------- d-----w- c:\program files\Trend Micro
2011-04-03 01:25:46 -------- d-----w- c:\docume~1\johnson\locals~1\applic~1\VS Revo Group
2011-04-03 01:25:17 27064 ----a-w- c:\windows\system32\drivers\revoflt.sys
2011-04-03 01:25:14 -------- d-----w- c:\program files\VS Revo Group
2011-04-03 00:51:57 -------- d-----w- c:\docume~1\johnson\applic~1\BabylonToolbar
2011-04-03 00:45:06 163328 ----a-w- c:\windows\Lsiqoa.exe
2011-04-03 00:45:02 91136 --sha-r- c:\windows\system32\editg.dll
2011-03-31 06:35:14 -------- d-----w- c:\docume~1\johnson\applic~1\Blue Cat Audio
2011-03-26 02:28:16 -------- d-----w- c:\program files\JDownloader
2011-03-23 03:17:18 -------- d-----w- c:\docume~1\johnson\locals~1\applic~1\MixedInKey
2011-03-22 07:56:45 -------- d-----w- c:\program files\Mixed In Key
2011-03-22 07:56:03 -------- d-----w- c:\program files\Mixed In Key v2.5 (Full)
2011-03-22 07:22:41 -------- d-----w- c:\program files\__MACOSX
2011-03-14 16:20:41 -------- d--h--w- c:\docume~1\alluse~1\applic~1\Common Files
.
==================== Find3M ====================
.
2010-02-02 13:10:20 453024 ----a-w- c:\program files\setup.exe
2010-02-02 13:09:06 10177536 ----a-w- c:\program files\openofficeorg32.msi
2008-12-10 23:14:40 4411392 ----a-w- c:\program files\mplayerc.exe
.
============= FINISH: 18:51:28.00 ===============
Attached File(s)
-
attach.txt (5.19K)
Number of downloads: 0 -
ark.txt (258.11K)
Number of downloads: 1

Help
This topic is locked

Back to top












