He's been battling the XP Internet Security 2012 and has a Website Re-director for about 2 weeks or so. Normally MBAM will take care of the XP Internet Security in my past experience, but because of the re-director, it keeps coming back.
When opening a browser, and doing a search, the page loads, then immediately redirects to one or more other sites. He's also then getting the XP Internet Security 2012. After MBAM hadn't removed it completely, I followed the directions for removing it, but due to the re-director, it just keeps coming back.
Thanks in advance!
Here is the DDS Log
+++++++++++++++++++++++++++++++++++++
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by John at 10:28:41 on 2011-12-30
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1004 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Nuance\dgnsvc.exe
C:\Program Files\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\WINDOWS\system32\java.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\Nuance\Nuance Cloud Connector\GladinetClient.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\agent.exe
C:\WINDOWS\System32\svchost.exe -k NecUsbSevice
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [ccleaner] "c:\program files\ccleaner\CCleaner.exe" /AUTO
uRun: [ISUSPM] c:\documents and settings\all users\application data\flexnet\connect\11\ISUSPM.exe -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil11c_Plugin.exe -update plugin
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HPHUPD06] c:\program files\hp\{aac4fc36-8f89-4587-8dd3-ebc57c83374d}\hphupd06.exe
mRun: [HPHmon06] c:\windows\system32\hphmon06.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb11.exe
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [OmniPage Preload] c:\program files\nuance\omnipage18\OmniPage18.exe /preload
mRun: [Nuance OmniPage 18-reminder] "c:\program files\nuance\omnipage18\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\omnipage 18\ereg\Ereg.ini"
mRun: [DNS7reminder] "c:\program files\nuance\naturallyspeaking11\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\nuance\naturallyspeaking11\Ereg.ini
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\msiwir~1.lnk - c:\program files\msi\common\RaUI.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nuance~1.lnk - c:\program files\nuance\nuance cloud connector\GladLauncher.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{8DF24447-C38B-446E-BCF7-6ED05769CA7C} : DhcpNameServer = 192.168.1.1
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
Notify: NecUsb3Sevice - USB3Nw32.dll
Notify: USB3Nw32 - USB3Nw32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\john\application data\mozilla\firefox\profiles\ighazaan.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165648]
R1 MpKsl80cff221;MpKsl80cff221;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8785ae2d-929b-4f6c-ba6b-6e5d44a31495}\MpKsl80cff221.sys [2011-12-27 29904]
R2 DragonSvc;Dragon Service;c:\program files\common files\nuance\dgnsvc.exe [2010-9-24 296808]
R2 GladFileMonSvc;GladFileMonSvc;c:\program files\nuance\nuance cloud connector\GladFileMonSvc.exe [2011-5-9 29552]
R2 LinksysUpdater;Linksys Updater;c:\program files\linksys\linksys updater\bin\LinksysUpdater.exe [2008-1-15 204800]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-10-23 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-2-28 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-7-20 47640]
R2 NecUsb;USB Service;c:\windows\system32\svchost.exe -k NecUsbSevice [2006-2-28 14336]
S1 MpKsl6f1db4b5;MpKsl6f1db4b5;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8b9cec97-a3ed-4448-a86c-3e2420be292f}\mpksl6f1db4b5.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8b9cec97-a3ed-4448-a86c-3e2420be292f}\MpKsl6f1db4b5.sys [?]
S1 MpKslb1811aa7;MpKslb1811aa7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8b9cec97-a3ed-4448-a86c-3e2420be292f}\mpkslb1811aa7.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8b9cec97-a3ed-4448-a86c-3e2420be292f}\MpKslb1811aa7.sys [?]
S1 MpKslf2d9c308;MpKslf2d9c308;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8b9cec97-a3ed-4448-a86c-3e2420be292f}\mpkslf2d9c308.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8b9cec97-a3ed-4448-a86c-3e2420be292f}\MpKslf2d9c308.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
2011-12-30 17:20:11 54016 ----a-w- c:\windows\system32\drivers\eppjbaey.sys
2011-12-29 16:59:46 37888 ----a-w- c:\windows\system32\USB3Nw32.dll
2011-12-29 16:59:46 157184 ------w- c:\windows\system32\NUSB3w32.dll
2011-12-28 01:28:12 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8785ae2d-929b-4f6c-ba6b-6e5d44a31495}\MpKsl80cff221.sys
2011-12-28 01:27:59 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8785ae2d-929b-4f6c-ba6b-6e5d44a31495}\offreg.dll
2011-12-28 01:27:53 6823496 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8785ae2d-929b-4f6c-ba6b-6e5d44a31495}\mpengine.dll
2011-12-28 00:58:11 64512 -c--a-w- c:\windows\system32\dllcache\serial.sys
2011-12-28 00:58:11 64512 ----a-w- c:\windows\system32\drivers\serial.sys
2011-12-28 00:56:07 -------- d-sha-r- C:\cmdcons
2011-12-28 00:54:15 98816 ----a-w- c:\windows\sed.exe
2011-12-28 00:54:15 518144 ----a-w- c:\windows\SWREG.exe
2011-12-28 00:54:15 256000 ----a-w- c:\windows\PEV.exe
2011-12-28 00:54:15 208896 ----a-w- c:\windows\MBR.exe
2011-12-22 22:53:01 -------- d-----w- c:\program files\common files\IVA
2011-12-22 22:52:30 -------- d-----w- c:\program files\common files\Nuance
2011-12-22 22:47:27 -------- d-----w- c:\windows\speech
2011-12-22 21:59:23 -------- d-----w- c:\documents and settings\john\local settings\application data\gladinet
2011-12-22 21:59:10 -------- d-----w- c:\documents and settings\all users\application data\Nuance
2011-12-22 21:54:01 -------- d-----w- C:\Gladinet
2011-12-22 21:50:03 -------- d-----w- c:\windows\pixtran
.
==================== Find3M ====================
.
2011-12-16 21:03:07 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-12-16 21:03:06 87424 ----a-w- c:\windows\system32\LMIinit.dll
2011-12-16 21:03:06 52096 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2011-12-16 21:03:06 30592 ----a-w- c:\windows\system32\LMIport.dll
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-11 15:07:38 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-06 21:02:47 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll.000.bak
2011-10-06 21:02:45 87424 ----a-w- c:\windows\system32\LMIinit.dll.000.bak
2006-02-28 12:00:00 94784 --sh--w- c:\windows\twain.dll
2008-04-14 00:12:07 50688 --sh--w- c:\windows\twain_32.dll
2011-02-08 13:33:55 978944 --sha-w- c:\windows\system32\mfc42.dll
2008-04-14 00:12:01 57344 --sh--w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12:01 413696 --sh--w- c:\windows\system32\msvcp60.dll
2010-12-20 17:32:15 551936 --sh--w- c:\windows\system32\oleaut32.dll
2008-04-14 00:12:32 11776 --sh--w- c:\windows\system32\regsvr32.exe
.
============= FINISH: 10:29:02.12 ===============
Attached File(s)
-
attach.txt (115.68K)
Number of downloads: 0 -
gmerlog.log (20.5K)
Number of downloads: 0

Help
This topic is locked

Back to top












