So in all of my years of computer experience I've never encountered a virus this stubborn. This problem initially started as a fake "anti virus" scanner, having encountered these before, I immediately disabled it and removed it manually. By the way this problem is on my parents computer, they got the virus and asked me to remove it for them, they had almost zero virus and firewall protection. Anyways, after removing the fake anti virus, I downloaded and ran SuperANTImaleware, spybot, and malewarebytes (not at the same time) this removed a few Trojans and spyware. After a reboot I noticed a few more problems, iexplorer.exe was reproducing itself many times in taskmanager, and I also noticed that both IE and firefox had been hijacked by a browser redirection virus. I used comodo firewall to block the iexplorer processes temporarily, and after a boot scan with unhackme and avast antivirus, a few more Trojans and a rootkit were found and fixed. This solved the iexporer problem, but I still am unable to get rid of the browser redirection problem. I've rescanned the system with superANTI, malewarebytes, Avast, and Panda cloud (individually of course, with live protection turned off to prevent complications). Nothing. I scanned the system with TDSS killer and nothing malicious was revealed. Pleases help!
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Owner at 16:36:35 on 2011-11-25
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1526.725 [GMT -5:00]
.
AV: Panda Cloud Antivirus *Disabled/Updated* {5AD27692-540A-464E-B625-78275FA38393}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Program Files\WTouch\WTouchService.exe
svchost.exe
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\afasrv32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\WTouch\WTouchUser.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\Program Files\Carbonite\CarbonitePreinstaller.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe
C:\Program Files\USIM Editor\iconcs916839438.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANToManager.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://yahoo.com/
uSearch Page =
uWindow Title = Internet Explorer, optimized for Bing and MSN
uDefault_Page_URL = hxxp://www.msn.com
uSearch Bar =
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:1044
mSearchAssistant =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Panda Security Toolbar: {b821bf60-5c2d-41eb-92dc-3e4ccd3a22e4} - c:\program files\panda security\panda security toolbar\PandaSecurityDx.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: @c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Panda Security Toolbar: {b821bf60-5c2d-41eb-92dc-3e4ccd3a22e4} - c:\program files\panda security\panda security toolbar\PandaSecurityDx.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [OneTouch Monitor] c:\program files\visioneer onetouch\OneTouchMon.exe
mRun: [CarboniteSetupLite] "c:\program files\carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb11.exe
mRun: [HPHUPD06] c:\program files\hp\{aac4fc36-8f89-4587-8dd3-ebc57c83374d}\hphupd06.exe
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPHmon06] c:\windows\system32\hphmon06.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Bing Bar] "c:\program files\msn toolbar\platform\5.0.1449.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [USBestCR] c:\program files\usim editor\iconcs916839438.exe RunFromReg
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [PSUNMain] "c:\program files\panda security\panda cloud antivirus\PSUNMain.exe" /Traybar
mRun: [Panda Security URL Filtering] "c:\documents and settings\all users\application data\panda security url filtering\Panda_URL_Filtering.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250525517718
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: Interfaces\{447E196F-78FF-4308-B6B6-E6867A76DA08} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D0A550AE-0745-4D5B-9504-55F8216C9509} : NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{F985F99A-EA74-4FAD-AB95-1DD04CC1D11F} : NameServer = 8.26.56.26,156.154.70.22
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: SDWinLogon - SDWinLogon.dll
LSA: Authentication Packages = msv1_0 nwprovau
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\c4687ves.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.mystart.com/?pr=vmn&id=pandasecuritytb&v=2_0
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=panda&type=PCAFSI1190&p=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\owner\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\owner\application data\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-11-22 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-11-22 320856]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-10-7 492768]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-10-7 31704]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 165264]
R1 MpKsl1798c327;MpKsl1798c327;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{59e12f0e-799d-44ab-8028-bbae630cd4be}\MpKsl1798c327.sys [2011-11-25 28752]
R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [2011-4-28 129992]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2008-9-3 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-9-3 67656]
R1 SDHookDriver;Spybot-S&D 2 Hook Driver;c:\program files\spybot - search & destroy 2\SDHookDrv32.sys [2011-11-19 38504]
R2 AfaService;Afa Card Reader Service;c:\windows\system32\afasrv32.exe [2011-6-28 65536]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-11-22 20568]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-11-22 44768]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2011-10-7 1883328]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-9-25 189736]
R2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\panda security\panda cloud antivirus\PSANHost.exe [2011-4-28 140608]
R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [2011-7-5 143752]
R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [2011-4-28 97096]
R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [2011-4-28 111688]
R2 PSINProt;PSINProt;c:\windows\system32\drivers\PSINProt.sys [2011-4-28 112456]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2011-11-19 955816]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2010-8-8 4408616]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-11-13 92008]
R2 WTouchService;WTouch Service;c:\program files\wtouch\WTouchService.exe [2010-8-8 112936]
R3 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2011-11-19 892336]
S1 MpKsl01f05f3e;MpKsl01f05f3e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9d1e9b9d-e208-4974-b83c-0533f4781ffb}\mpksl01f05f3e.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9d1e9b9d-e208-4974-b83c-0533f4781ffb}\MpKsl01f05f3e.sys [?]
S1 MpKsl24e89010;MpKsl24e89010;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b0d54b5b-4eeb-4ff1-aabc-ca46ffd710a6}\mpksl24e89010.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b0d54b5b-4eeb-4ff1-aabc-ca46ffd710a6}\MpKsl24e89010.sys [?]
S1 MpKsl4540303a;MpKsl4540303a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{76f7db37-5bd8-43d2-b106-e25f6520d684}\mpksl4540303a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{76f7db37-5bd8-43d2-b106-e25f6520d684}\MpKsl4540303a.sys [?]
S1 MpKsl7cb86acc;MpKsl7cb86acc;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7768c778-3850-4fd4-afc9-447a1514eb9b}\mpksl7cb86acc.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7768c778-3850-4fd4-afc9-447a1514eb9b}\MpKsl7cb86acc.sys [?]
S1 MpKsla93b85ec;MpKsla93b85ec;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7768c778-3850-4fd4-afc9-447a1514eb9b}\mpksla93b85ec.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7768c778-3850-4fd4-afc9-447a1514eb9b}\MpKsla93b85ec.sys [?]
S1 MpKslc202d5b0;MpKslc202d5b0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1536b829-b650-4b00-86d8-c3ba2b7e789f}\mpkslc202d5b0.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1536b829-b650-4b00-86d8-c3ba2b7e789f}\MpKslc202d5b0.sys [?]
S1 MpKsldfb179c9;MpKsldfb179c9;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fab5b5b0-a690-4a5e-bd8d-a48807b395f3}\mpksldfb179c9.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fab5b5b0-a690-4a5e-bd8d-a48807b395f3}\MpKsldfb179c9.sys [?]
S1 MpKslf0040c87;MpKslf0040c87;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4e74e441-00e0-4c0f-97f9-7d69ad505b4c}\mpkslf0040c87.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4e74e441-00e0-4c0f-97f9-7d69ad505b4c}\MpKslf0040c87.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-26 136176]
S2 SDHookService;Spybot S&D 2 Live Protection Service;c:\program files\spybot - search & destroy 2\SDHookSvc.exe [2011-11-19 130976]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2010-3-3 20160]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-26 136176]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\50.tmp --> c:\windows\system32\50.tmp [?]
S3 MHIKEY10;MHIKEY10;c:\windows\system32\drivers\MHIKEY10.sys [2011-6-28 51072]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [2011-11-22 24416]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-9-3 12872]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2010-8-8 15656]
.
=============== Created Last 30 ================
.
2011-11-25 19:56:31 518144 ----a-w- c:\windows\SWREG.exe
2011-11-25 19:56:00 -------- d-s---w- C:\ComboFix
2011-11-25 19:31:57 289144 ----a-w- c:\windows\system32\VCCLSID.exe
2011-11-25 19:31:54 51200 ----a-w- c:\windows\system32\dumphive.exe
2011-11-25 19:31:53 288417 ----a-w- c:\windows\system32\SrchSTS.exe
2011-11-25 19:31:48 53248 ----a-w- c:\windows\system32\Process.exe
2011-11-25 08:51:10 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{59e12f0e-799d-44ab-8028-bbae630cd4be}\MpKsl1798c327.sys
2011-11-25 08:51:00 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{59e12f0e-799d-44ab-8028-bbae630cd4be}\offreg.dll
2011-11-25 08:50:45 6668624 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{59e12f0e-799d-44ab-8028-bbae630cd4be}\mpengine.dll
2011-11-24 00:54:28 -------- d-----w- c:\windows\RR2IOTZXV0LTZXV0
2011-11-23 07:15:38 -------- d-----w- c:\documents and settings\owner\application data\Panda Security
2011-11-23 07:14:20 -------- d-----w- c:\program files\Toolbar Cleaner
2011-11-23 07:14:10 -------- d-----w- c:\documents and settings\owner\local settings\application data\panda2_0dn
2011-11-23 07:13:57 -------- d-----w- c:\documents and settings\all users\application data\Panda Security URL Filtering
2011-11-23 07:13:29 -------- d-----w- c:\documents and settings\owner\application data\pandasecuritytb
2011-11-23 07:12:10 -------- d-----w- c:\program files\Panda Security
2011-11-23 07:12:10 -------- d-----w- c:\documents and settings\all users\application data\Panda Security
2011-11-23 07:11:15 -------- d-----w- C:\temp
2011-11-23 05:06:08 -------- d-----w- C:\WTablet
2011-11-23 04:05:50 24416 ----a-w- c:\windows\system32\drivers\regguard.sys
2011-11-23 04:00:32 39192 ----a-w- c:\windows\system32\Partizan.exe
2011-11-23 04:00:32 35816 ----a-w- c:\windows\system32\drivers\Partizan.sys
2011-11-23 03:59:55 2 --shatr- c:\windows\winstart.bat
2011-11-23 03:59:25 12800 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
2011-11-23 03:59:00 -------- d-----w- c:\program files\UnHackMe
2011-11-23 03:49:09 -------- d-----w- C:\TDSSKiller_Quarantine
2011-11-22 16:42:20 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-22 16:41:18 41184 ----a-w- c:\windows\avastSS.scr
2011-11-22 16:40:57 -------- d-----w- c:\program files\AVAST Software
2011-11-22 16:40:57 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2011-11-22 15:40:13 4338 ----a-w- c:\windows\system32\tmp.reg
2011-11-22 01:50:45 -------- d--h--w- C:\VritualRoot
2011-11-21 22:20:40 -------- d--h--w- c:\windows\PIF
2011-11-21 21:31:34 -------- d-----w- c:\documents and settings\all users\application data\Comodo
2011-11-21 21:30:46 -------- d-----w- c:\program files\COMODO
2011-11-21 21:29:41 -------- d-----w- c:\documents and settings\all users\application data\Comodo Downloader
2011-11-20 16:29:56 -------- d-----w- c:\program files\Sophos
2011-11-20 16:16:41 -------- d-----w- C:\ProcAlyzer Dumps
2011-11-20 16:15:45 -------- d-----w- C:\SpybotBootCD
2011-11-20 01:18:21 819 ----a-w- c:\documents and settings\all users\application data\amqnaaa.tmp
2011-11-19 17:33:25 15224 ----a-w- c:\windows\system32\sdnclean.exe
2011-11-19 17:33:13 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2011-11-19 06:49:51 -------- d-----w- c:\windows\system32\NtmsData
2011-11-06 00:11:02 -------- d-----w- c:\documents and settings\owner\local settings\application data\AOL
2011-11-06 00:11:02 -------- d-----w- c:\documents and settings\owner\local settings\application data\AIM
2011-11-06 00:10:55 -------- d-----w- c:\documents and settings\all users\application data\AIM
2011-11-06 00:10:48 -------- d-----w- c:\program files\AIM
2011-11-06 00:10:46 -------- d-----w- c:\program files\common files\Software Update Utility
.
==================== Find3M ====================
.
2011-10-07 23:48:02 492768 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 23:48:02 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 23:48:00 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 23:47:12 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-07 23:47:12 300200 ----a-w- c:\windows\system32\guard32.dll
2011-08-31 22:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 16:39:40.67 ===============
Attached File(s)
-
attach.txt (13.9K)
Number of downloads: 1 -
GMER.txt (315.81K)
Number of downloads: 0

Help
This topic is locked

Back to top










