I was infected by Windows Fix Disk. Manually fixed it following instructions. Ran Spybot S&D & Malwarebytes Anti-malware, which removed a couple other entries. Now both run clean.
However, I am getting Internet Explorer pop-up script errors for various sites as soon as I log in. Closing just brings up more and then randomly it plays audio ads. Task manager does not appear to show any apps or processes running during these ads.
Also, Google search redirects to various other search sites, if I click on any search result.
These problems all started at the same time and I feel like they are remnants of Windows Fix Disk that I can't remove.
Any help is greatly appreciated!
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by James Freeman at 13:19:02.43 on Mon 04/25/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.5.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.480 [GMT -4:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
H:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
H:\WINDOWS\System32\svchost.exe -k netsvcs
H:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
H:\Program Files\AVG\AVG9\avgchsvx.exe
H:\Program Files\AVG\AVG9\avgrsx.exe
H:\Program Files\AVG\AVG9\avgcsrvx.exe
H:\WINDOWS\system32\spoolsv.exe
svchost.exe
H:\WINDOWS\system32\agrsmsvc.exe
H:\Program Files\AVG\AVG9\avgwdsvc.exe
H:\Program Files\Juniper Networks\Common Files\dsNcService.exe
H:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\HPZipm12.exe
H:\WINDOWS\System32\svchost.exe -k imgsvc
H:\WINDOWS\system32\SearchIndexer.exe
H:\Program Files\AVG\AVG9\avgnsx.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\System32\svchost.exe -k HTTPFilter
H:\Documents and Settings\James Freeman\Application Data\Dropbox\bin\Dropbox.exe
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\WINDOWS\system32\taskmgr.exe
H:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
H:\Program Files\AVG\AVG9\avgcsrvx.exe
H:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\WINDOWS\system32\SearchProtocolHost.exe
H:\Documents and Settings\James Freeman\Local Settings\Temporary Internet Files\Content.IE5\63QQGLMX\dds[1].scr
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.facebook.com/home.php
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - h:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - h:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - h:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - h:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - h:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - h:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [cdloader] "h:\documents and settings\james freeman\application data\mjusbsp\cdloader2.exe" MAGICJACK
mRun: [AntiSpywareMaster] h:\program files\antispywaremaster\asm.exe
mRun: [QuickTime Task] "h:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: h:\docume~1\jamesf~1\startm~1\programs\startup\dropbox.lnk - h:\documents and settings\james freeman\application data\dropbox\bin\Dropbox.exe
IE: Add to Google Photos Screensa&ver - h:\windows\system32\GPhotos.scr/200
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - h:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - h:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - h:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: westlaw.com
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} - hxxps://jran.uscourts.gov/whalecomed36a580762db7cb8d65abf0a0c357b3e95b82c2926b902b/whalecom0/iNotes6W.cab
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/34.09/uploader2.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188158620797
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188161423984
DPF: {7B62F6EE-D046-11D3-9C5E-0060082627F7} - hxxps://secured.lsi-lps.com/messenger/download/TWDownload.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://jran.uscourts.gov/InternalSite/WhlCompMgr.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - h:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - h:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - h:\progra~1\wifd1f~1\MpShHook.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - h:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 AvgLdx86;AVG AVI Loader Driver x86;h:\windows\system32\drivers\avgldx86.sys [2008-4-24 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;h:\windows\system32\drivers\avgmfx86.sys [2007-8-26 29584]
R1 AvgTdiX;AVG Free8 Network Redirector;h:\windows\system32\drivers\avgtdix.sys [2009-4-13 243024]
R2 avg9wd;AVG Free WatchDog;h:\program files\avg\avg9\avgwdsvc.exe [2010-7-16 308136]
R3 CardReaderFilter;Card Reader Filter;h:\windows\system32\drivers\USBCRFT.SYS [2007-9-10 13440]
R3 cmudax;C-Media High Definition Audio Interface;h:\windows\system32\drivers\cmudax.sys [2005-5-12 1287296]
S3 IIUSBISP;USB Mass Storage for USB ISP;h:\windows\system32\drivers\iiusbisp.sys --> h:\windows\system32\drivers\iiusbisp.sys [?]
S4 WinDefend;Windows Defender;h:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
.
=============== Created Last 30 ================
.
2011-04-07 18:56:15 -------- d-----w- h:\docume~1\jamesf~1\locals~1\applic~1\Temp
.
==================== Find3M ====================
.
2011-03-07 05:33:50 692736 ----a-w- h:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 ----a-w- h:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- h:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- h:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ----a-w- h:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ----a-w- h:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59 385024 ----a-w- h:\windows\system32\html.iec
2011-02-18 21:36:58 4184352 ----a-w- h:\windows\system32\usbaaplrc.dll
2011-02-17 12:32:12 5120 ----a-w- h:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- h:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ------w- h:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ------w- h:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- h:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- h:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- h:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- h:\windows\system32\mstsc.exe
.
============= FINISH: 13:25:30.67 ===============
Attached File(s)
-
Attach.txt (20.07K)
Number of downloads: 2

Help
This topic is locked

Back to top










