Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

trojan zlob.dnschanger trojan downloaderpopuper


  • This topic is locked This topic is locked
29 replies to this topic

#1 onedead

onedead

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 04 January 2009 - 12:32 PM

Hi all, I have been fighting this problem for a month now with no luck. spybot S&D flags this as the zlob.dnschanger, and malwarebytes flags as the same. I was funning spyware docter and it was flaging it as popuper downloader. I have it on two computers. One with xp home, and this one with vista business. I have re-installed both operating systems and its still there. The symptom is that I can't update windows or many anti-spyware and anti-virus software. Some I can't even download. On XP when I try to update windows it re-directs me to msn.com.


DDS (Version 1.1.0) - NTFSx86
Run by Paul at 11:11:18.59 on Sun 01/04/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.2047.1345 [GMT -6:00]

AV: AVG Internet Security *On-access scanning enabled* (Outdated)
FW: AVG Firewall *enabled*

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Paul\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [FTweakFCleaner] c:\program files\fcleaner\FCleaner.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RtHDVCpl] RtHDVCpl.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-12-28 12424]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-28 96520]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-12-28 902424]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-28 282904]
R2 avgfws8;AVG8 Firewall;c:\progra~1\avg\avg8\avgfws8.exe [2008-12-28 930584]
R3 AvgWfpX;AVG8 Firewall Driver x86;c:\windows\system32\drivers\avgwfpx.sys [2008-12-28 67080]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-7-22 180736]

=============== Created Last 30 ================

2009-01-04 10:11 <DIR> --d----- c:\windows\system32\RTCOM
2009-01-04 10:10 678,408 a------- c:\windows\system32\gpprefcl.dll
2009-01-03 23:30 <DIR> --d----- c:\programdata\NVIDIA
2009-01-03 23:19 1,383,424 a------- c:\windows\system32\mshtml.tlb
2009-01-03 23:17 1,108,512 a------- c:\windows\system32\nvcpluir.dll
2009-01-03 23:17 797,216 a------- c:\windows\system32\nvcplui.exe
2009-01-03 23:17 453,152 a------- c:\windows\system32\nvuninst.exe
2009-01-03 23:17 420,384 a------- c:\windows\system32\nvcpl.cpl
2009-01-03 23:16 <DIR> --d----- c:\users\paul\{030b466e-2888-4fa0-b131-0d7bc0902e27}
2009-01-03 23:15 2,048 a------- c:\windows\system32\tzres.dll
2009-01-03 20:16 12,240,896 a------- c:\windows\system32\NlsLexicons0007.dll
2009-01-03 20:16 2,644,480 a------- c:\windows\system32\NlsLexicons0009.dll
2009-01-03 20:16 801,280 a------- c:\windows\system32\NaturalLanguage6.dll
2009-01-03 20:11 712,704 a------- c:\windows\system32\WindowsCodecs.dll
2009-01-03 20:01 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-01-03 20:01 83,456 a------- c:\windows\system32\wudriver.dll
2009-01-03 20:01 162,064 a------- c:\windows\system32\wuwebv.dll
2009-01-03 20:01 31,232 a------- c:\windows\system32\wuapp.exe
2008-12-29 21:48 <DIR> --d-h--- C:\$AVG8.VAULT$
2008-12-28 13:46 10,520 a------- c:\windows\system32\avgrsstx.dll
2008-12-28 13:46 12,424 a------- c:\windows\system32\drivers\avgrkx86.sys
2008-12-28 13:46 67,080 a------- c:\windows\system32\drivers\avgwfpx.sys
2008-12-28 13:46 96,520 a------- c:\windows\system32\drivers\avgldx86.sys
2008-12-28 13:46 <DIR> --d----- c:\windows\system32\drivers\Avg
2008-12-28 11:46 <DIR> --d----- c:\program files\Trend Micro
2008-12-28 00:19 <DIR> --d----- c:\users\paul\appdata\roaming\Iomatic
2008-12-28 00:19 <DIR> --d----- c:\programdata\FTWeak
2008-12-28 00:19 <DIR> --d----- c:\program files\FCleaner
2008-12-28 00:19 <DIR> --d----- c:\progra~2\FTWeak
2008-12-26 23:47 <DIR> --d----- c:\programdata\Kaspersky Lab Setup Files
2008-12-26 23:47 <DIR> --d----- c:\progra~2\Kaspersky Lab Setup Files
2008-12-26 21:11 <DIR> --d----- c:\programdata\PrevxCSI
2008-12-26 21:11 <DIR> --d----- c:\progra~2\PrevxCSI
2008-12-26 19:37 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-26 16:21 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2008-12-26 16:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2008-12-26 16:21 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2008-12-26 11:44 <DIR> --d----- c:\programdata\avg8
2008-12-26 11:44 <DIR> --d----- c:\program files\AVG
2008-12-26 11:44 <DIR> --d----- c:\progra~2\avg8
2008-12-26 11:44 <DIR> --dsh--- c:\windows\Installer
2008-12-25 19:53 <DIR> --d----- c:\users\Paul
2008-12-24 13:23 <DIR> --dsh--- C:\$RECYCLE.BIN

==================== Find3M ====================

2009-01-04 10:11 51,200 a------- c:\windows\inf\infpub.dat
2009-01-04 10:11 86,016 a------- c:\windows\inf\infstrng.dat
2009-01-04 10:11 86,016 a------- c:\windows\inf\infstor.dat
2009-01-03 23:25 665,600 a------- c:\windows\inf\drvindex.dat
2008-10-31 21:44 52,736 a------- c:\windows\apppatch\iebrshim.dll
2008-10-31 21:44 2,154,496 a------- c:\windows\apppatch\AcGenral.dll
2008-10-31 21:44 541,696 a------- c:\windows\apppatch\AcLayers.dll
2008-10-31 21:44 460,288 a------- c:\windows\apppatch\AcSpecfc.dll
2008-10-31 21:44 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2008-10-31 21:44 28,672 a------- c:\windows\system32\Apphlpdm.dll
2008-10-31 19:21 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2008-10-29 00:29 2,927,104 a------- c:\windows\explorer.exe
2008-10-21 21:57 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2008-10-20 23:25 296,960 a------- c:\windows\system32\gdi32.dll
2008-10-20 23:25 1,645,568 a------- c:\windows\system32\connect.dll
2008-10-15 22:47 827,392 a------- c:\windows\system32\wininet.dll
2008-01-20 20:43 174 a--sh--- c:\program files\desktop.ini
2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 11:11:57.22 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 05 January 2009 - 02:09 PM

If I didn't do this right would someone prease let me know.

#3 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:19 PM

Posted 12 January 2009 - 05:28 PM

Hello. I am PropagandaPanda (Panda or PP for short), and I will be helping you with your log.

I apologize for the delay in response. We get overwhelmed with logs at times, but we are trying our best to keep up. If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following so I can have a look at the current condition of your machine.

You may want to keep the link to this topic in your favourites. Alternatively, you can click the Posted Image button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.

Download and Run DDS
If you already have a copy of DDS, there is not need to download a new one.

Download DDS by sUBs from any of the links below:
DDS.com, DDS.scr, DDS.pif

Double click its icon to run it. If you are using Windows Vista, right click it and select "Run as Administrator".
When the scan is finished, two logs will open.
Post DDS.txt directly into your reply. Attach Attach.txt.

Download and Run Scan with GMER
We will use GMER to scan for rootkits.

Please download GMER.zip to your desktop from any of the links below:
LINK1, LINK2
  • Right click on GMER.zip and select "Extract All".
  • Close all other open programs as there is a slight chance your computer will crash.
  • Double click GMER.exe. If you are using Windows Vista, right click the icon and select "Run as Administrator". Your security programs may detect GMER's driver trying to load. Allow it.
  • You may see a warning saying "GMER has detected rootkit activity". If so, select NO.
  • Leaving the settings at default, click Scan.
  • When the scan is complete, click Save and save the log onto your desktop.
Please include the log in your next reply.
Please tell me what changes have been made to the computer since your topic was started. Also give me an update on any symptoms.

With Regards,
The Panda

#4 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 14 January 2009 - 12:22 PM

Hey PP, Thanks for getting back to me. Im not sure if you wanted a new dss file as well but I will send those too. No new news, but here is a recap. I got this virus or whatever it is when I downloaded a codec fof a pirated movie ( I though ). spybot S & D calls it a trojan dns changer. I was running spyware docter and it kept blocking a trojan downloader popuper. This thing has survived everything I have tried in the last month or so including re-installing the OS. I have even ran many anti virus and antispyware, including malwarebytes, superantispyware, avast, avira, and many others. I also ran hiren 9.6 boot cd and reformated and wiped out partitions with partitions magic pro, and then ran boot and nuke several times. I also have this on a computer running xp home, but I took it off the network for now. Anyhoo here are those logs.


DDS (Version 1.1.0) - NTFSx86
Run by Paul at 11:08:35.36 on Wed 01/14/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.2047.1048 [GMT -6:00]

AV: AVG Internet Security *On-access scanning enabled* (Outdated)
FW: AVG Firewall *enabled*

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Paul\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [FTweakFCleaner] c:\program files\fcleaner\FCleaner.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RtHDVCpl] RtHDVCpl.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-12-28 12424]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-28 96520]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-12-28 902424]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-28 282904]
R2 avgfws8;AVG8 Firewall;c:\progra~1\avg\avg8\avgfws8.exe [2008-12-28 930584]
R3 AvgWfpX;AVG8 Firewall Driver x86;c:\windows\system32\drivers\avgwfpx.sys [2008-12-28 67080]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-7-22 180736]

=============== Created Last 30 ================

2009-01-14 10:18 250 a------- c:\windows\gmer.ini
2009-01-09 21:19 <DIR> --d----- c:\users\paul\SmitfraudFix
2009-01-07 16:58 <DIR> --d----- c:\program files\Netflix
2009-01-06 17:39 <DIR> --d----- c:\windows\LastGood.Tmp
2009-01-06 17:38 885,248 a------- c:\windows\system32\RacEngn.dll
2009-01-06 17:38 468,992 a------- c:\windows\system32\newdev.dll
2009-01-06 17:38 74,752 a------- c:\windows\system32\newdev.exe
2009-01-06 17:38 9,127 a------- c:\windows\system32\RacUR.xml
2009-01-06 17:38 153 a------- c:\windows\system32\RacUREx.xml
2009-01-04 10:11 <DIR> --d----- c:\windows\system32\RTCOM
2009-01-04 10:10 678,408 a------- c:\windows\system32\gpprefcl.dll
2009-01-03 23:30 <DIR> --d----- c:\programdata\NVIDIA
2009-01-03 23:19 1,383,424 a------- c:\windows\system32\mshtml.tlb
2009-01-03 23:17 1,108,512 a------- c:\windows\system32\nvcpluir.dll
2009-01-03 23:17 797,216 a------- c:\windows\system32\nvcplui.exe
2009-01-03 23:17 453,152 a------- c:\windows\system32\nvuninst.exe
2009-01-03 23:17 420,384 a------- c:\windows\system32\nvcpl.cpl
2009-01-03 23:16 <DIR> --d----- c:\users\paul\{030b466e-2888-4fa0-b131-0d7bc0902e27}
2009-01-03 23:15 2,048 a------- c:\windows\system32\tzres.dll
2009-01-03 20:16 12,240,896 a------- c:\windows\system32\NlsLexicons0007.dll
2009-01-03 20:16 2,644,480 a------- c:\windows\system32\NlsLexicons0009.dll
2009-01-03 20:16 801,280 a------- c:\windows\system32\NaturalLanguage6.dll
2009-01-03 20:11 712,704 a------- c:\windows\system32\WindowsCodecs.dll
2009-01-03 20:01 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-01-03 20:01 83,456 a------- c:\windows\system32\wudriver.dll
2009-01-03 20:01 162,064 a------- c:\windows\system32\wuwebv.dll
2009-01-03 20:01 31,232 a------- c:\windows\system32\wuapp.exe
2008-12-29 21:48 <DIR> --d-h--- C:\$AVG8.VAULT$
2008-12-28 13:46 10,520 a------- c:\windows\system32\avgrsstx.dll
2008-12-28 13:46 12,424 a------- c:\windows\system32\drivers\avgrkx86.sys
2008-12-28 13:46 67,080 a------- c:\windows\system32\drivers\avgwfpx.sys
2008-12-28 13:46 96,520 a------- c:\windows\system32\drivers\avgldx86.sys
2008-12-28 13:46 <DIR> --d----- c:\windows\system32\drivers\Avg
2008-12-28 11:46 <DIR> --d----- c:\program files\Trend Micro
2008-12-28 00:19 <DIR> --d----- c:\users\paul\appdata\roaming\Iomatic
2008-12-28 00:19 <DIR> --d----- c:\programdata\FTWeak
2008-12-28 00:19 <DIR> --d----- c:\program files\FCleaner
2008-12-28 00:19 <DIR> --d----- c:\progra~2\FTWeak
2008-12-26 23:47 <DIR> --d----- c:\programdata\Kaspersky Lab Setup Files
2008-12-26 23:47 <DIR> --d----- c:\progra~2\Kaspersky Lab Setup Files
2008-12-26 21:11 <DIR> --d----- c:\programdata\PrevxCSI
2008-12-26 21:11 <DIR> --d----- c:\progra~2\PrevxCSI
2008-12-26 19:37 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-26 16:21 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2008-12-26 16:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2008-12-26 16:21 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2008-12-26 11:44 <DIR> --d----- c:\programdata\avg8
2008-12-26 11:44 <DIR> --d----- c:\program files\AVG
2008-12-26 11:44 <DIR> --d----- c:\progra~2\avg8
2008-12-26 11:44 <DIR> --dsh--- c:\windows\Installer
2008-12-25 19:53 <DIR> --d----- c:\users\Paul
2008-12-24 13:23 <DIR> --dsh--- C:\$RECYCLE.BIN

==================== Find3M ====================

2009-01-06 17:39 86,016 a------- c:\windows\inf\infstrng.dat
2009-01-06 17:39 51,200 a------- c:\windows\inf\infpub.dat
2009-01-06 17:39 86,016 a------- c:\windows\inf\infstor.dat
2009-01-03 23:25 665,600 a------- c:\windows\inf\drvindex.dat
2008-10-31 21:44 52,736 a------- c:\windows\apppatch\iebrshim.dll
2008-10-31 21:44 2,154,496 a------- c:\windows\apppatch\AcGenral.dll
2008-10-31 21:44 541,696 a------- c:\windows\apppatch\AcLayers.dll
2008-10-31 21:44 460,288 a------- c:\windows\apppatch\AcSpecfc.dll
2008-10-31 21:44 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2008-10-31 21:44 28,672 a------- c:\windows\system32\Apphlpdm.dll
2008-10-31 19:21 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2008-10-29 00:29 2,927,104 a------- c:\windows\explorer.exe
2008-10-21 21:57 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2008-10-20 23:25 296,960 a------- c:\windows\system32\gdi32.dll
2008-10-20 23:25 1,645,568 a------- c:\windows\system32\connect.dll
2008-01-20 20:43 174 a--sh--- c:\program files\desktop.ini
2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 11:08:59.40 ===============

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-14 10:58:02
Windows 6.0.6001 Service Pack 1


---- User code sections - GMER 1.0.14 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!DialogBoxIndirectParamW 767CBD25 5 Bytes JMP 6C5B5BF3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!DialogBoxParamW 767E1FD5 5 Bytes JMP 6C5B5B7D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!DialogBoxParamA 768080B2 5 Bytes JMP 6C5B5BB8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!DialogBoxIndirectParamA 768083DD 5 Bytes JMP 6C5B5C2E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!MessageBoxIndirectA 7681D471 5 Bytes JMP 6C5B5B39 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!MessageBoxIndirectW 7681D56B 5 Bytes JMP 6C5B5AF5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!MessageBoxExA 7681D5D1 5 Bytes JMP 6C5B5ABB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] USER32.dll!MessageBoxExW 7681D5F5 5 Bytes JMP 6C5B5A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] SHELL32.dll!SHRestricted + DFD 769C8390 4 Bytes [ 99, 0B, D7, 70 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] SHELL32.dll!SHRestricted + E05 769C8398 8 Bytes [ A7, 0A, D7, 70, A4, 32, D6, ... ]
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] SHELL32.dll!SHBindToObject + 693 769CA9B8 4 Bytes [ 99, 0B, D7, 70 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[2664] SHELL32.dll!SHBindToObject + 69B 769CA9C0 4 Bytes [ A7, 0A, D7, 70 ]

---- User IAT/EAT - GMER 1.0.14 ----

IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [70D5D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [70D5D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [70D5B6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [70D5D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [70D5BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [70D5F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [70D5C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [70D5F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [70D5D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [70D5B6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [70D5DE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [70D5C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [70D5F49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [70D60D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [70D5FC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [70D602A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [70D5D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [70D5BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [70D5B114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [70D5D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [70D5A970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [70D6DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [70D6E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [70D6CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [70D6D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [70D6CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [70D6C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [70D6CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [70D5D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [70D5E151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [70D5B114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [70D5A970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [70D5A819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [70D5C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [70D5D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [70D58D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [70D5BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [70D602A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [70D5FC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [70D5F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [70D58AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [70D58C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [70D5BBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [70D5FF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [70D5FB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [70D60D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [70D5EFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [70D589D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [70D5D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [70D5CF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [70D5CE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [70D6CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [70D6C49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [70D6CD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [70D6D913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [70D6CA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [70D6C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [70D6CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [70D6E169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [70D6D437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [70D6CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [70D6DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [70D6D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [70D6E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [70D6DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [70D6DFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [70D6E2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [70D6DD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [70D6D5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [70D5A460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [70D5FC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [70D5E151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [70D5A6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [70D5AE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [70D5B114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [70D5C023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [70D5B6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [70D59700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [70D5D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [70D5DE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [70D602A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [70D60D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [70D59362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [70D589D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [70D5F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [70D5A1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [70D5A970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [70D5EAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [70D5E4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [70D5C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [70D58D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [70D58AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [70D5DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [70D594A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [70D5D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [70D5BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [70D58FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [70D5D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [70D59231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [70D5F49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [70D5C58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [70D5CF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [70D5CA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [70D6CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [70D6C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW] [70D6DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW] [70D6E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW] [70D6CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [70D6DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [70D6D913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW] [70D6E169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [70D6D13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW] [70D6D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW] [70D6D437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW] [70D6C8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [70D6C35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA] [70D6D5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [70D6CA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [70D6CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [70D691AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [70D60D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [70D602A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [70D5D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [70D5F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [70D5C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [70D594A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [70D58FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [70D5BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [70D5D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [70D58AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [70D5D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW] [70D6D13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] [70D6D28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW] [70D6E169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW] [70D6E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA] [70D6DD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA] [70D6CD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [70D6DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [70D6D913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW] [70D6D437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW] [70D6DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [70D6CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW] [70D6D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [70D6CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW] [70D6CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [70D6C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA] [70D6D5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [70D6CA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueW] [70D65CFD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueA] [70D65C9F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathUnExpandEnvStringsA] [70D64D95] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteKeyA] [70D650AF] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteValueW] [70D6519F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCreateFromUrlW] [70D640A2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueA] [70D65357] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueA] [70D6619F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueW] [70D653B2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueW] [70D661FA] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2664] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCombineW] [70D63FFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)

---- EOF - GMER 1.0.14 ----

Attached Files



#5 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:19 PM

Posted 14 January 2009 - 12:27 PM

Hello onedead.

This thing has survived everything I have tried in the last month or so including re-installing the OS.

Just to clarify, it is still there after you reinstalled?

I probably can't reply until later this afternoon. Thanks for your patience.

With Regards,
The Panda

#6 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 14 January 2009 - 05:26 PM

yes still there

#7 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:19 PM

Posted 14 January 2009 - 06:39 PM

Hello.

Could you please tell me what item is being flagged by your security programs?

Are there any other symptoms? Do you get any redirects?

Download and Run SmitFruadFix Scan
Let's check your DNS.
  • Please download SmitFraudFix by S!Ri to your desktop.
  • Double click the icon to run it.
  • Select Option 1 by typing 1 and hitting Enter.
  • When the scan is complete, a log file will appear. Please copy the contents of the log into your next post.
With Regards,
The Panda

#8 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 14 January 2009 - 07:33 PM

I had flags from other software but I havn.t added that software since reinstall. Here are the results of spybot S&D

Zlob.DNSChanger: [SBI $041D1396] TCP/IP Settings #1 (Undefined) (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer=208.67.220.220,208.67.222.222 1.2.3.4

Zlob.DNSChanger: [SBI $041D1396] TCP/IP Settings #2 (Undefined) (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{759EF170-8912-4F30-AE1B-A9E55946E83B}\DhcpNameServer=208.67.220.220,208.67.222.222 1.2.3.4


--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---

2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-09-16 TeaTimer.exe (1.6.3.25)
2008-12-26 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-10-22 advcheck.dll (1.6.2.13)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2008-11-04 Includes\Adware.sbi (*)
2008-12-22 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-12-22 Includes\HijackersC.sbi (*)
2008-12-09 Includes\Keyloggers.sbi (*)
2008-12-22 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-22 Includes\MalwareC.sbi (*)
2008-12-16 Includes\PUPS.sbi (*)
2008-12-16 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-12-16 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-12-10 Includes\Spyware.sbi (*)
2008-12-10 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-12-23 Includes\Trojans.sbi (*)
2008-12-22 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

I do get redirected to diferent search results. On vista I can't connect for windows updates unless spybot S&D successfully removes the problem, but then it comes back after some time or a reboot. On other computer running xp home I would get redirected to msn.com. I still can't google windows update site it comes back as not found. Also can't update virus deffinitions for most antivirus or anti spyware software. Here is the smitfraudfix report.

SmitFraudFix v2.388

Scan done at 18:26:29.04, Wed 01/14/2009
Run from C:\Users\Paul\Desktop\SmitfraudFix
OS: Microsoft Windows [Version 6.0.6001] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Windows\system32\svchost.exe
C:\Users\Paul\Desktop\SmitfraudFix\Policies.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

hosts file corrupted !

127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Paul


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Paul\AppData\Local\Temp


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Paul\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Paul\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, following keys are not inevitably infected!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, following keys are not inevitably infected!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, following keys are not inevitably infected!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"
"LoadAppInit_DLLs"=dword:00000001


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\Windows\\system32\\userinit.exe,"


»»»»»»»»»»»»»»»»»»»»»»»» RK



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Your computer may be victim of a DNS Hijack: 85.255.x.x detected !

Description: Broadcom NetXtreme Gigabit Ethernet
DNS Server Search Order: 85.255.112.233
DNS Server Search Order: 85.255.112.91
DNS Server Search Order: 1.2.3.4

HKLM\SYSTEM\CCS\Services\Tcpip\..\{759EF170-8912-4F30-AE1B-A9E55946E83B}: DhcpNameServer=85.255.112.233 85.255.112.91 1.2.3.4
HKLM\SYSTEM\CS1\Services\Tcpip\..\{759EF170-8912-4F30-AE1B-A9E55946E83B}: DhcpNameServer=85.255.112.233 85.255.112.91 1.2.3.4
HKLM\SYSTEM\CS2\Services\Tcpip\..\{759EF170-8912-4F30-AE1B-A9E55946E83B}: DhcpNameServer=85.255.112.233 85.255.112.91 1.2.3.4
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.233 85.255.112.91 1.2.3.4
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.233 85.255.112.91 1.2.3.4
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.233 85.255.112.91 1.2.3.4


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

#9 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:19 PM

Posted 14 January 2009 - 07:58 PM

Hello.

Let's see if ComboFix can remove the DNS hijack.

Disable Realtime Protection
Antimalware programs can interfere with the tools we need to run. Please temporarily disable all realtime protections you have enabled. Refer to this page, if you are unsure how.

To disable AVG:
  • Please navigate to the system tray on the bottom right hand corner and look for this Posted Image sign.
  • Right click it-> select Quit Control Center.
  • A warning will pop up, click Yes
To disable SpyBot's TeaTimer:
You can find instructions with visuals here.
  • Run Spybot-S&D in Advanced Mode. If it is not already set to do this Go to the Mode menu select Advanced Mode.
  • On the left hand side, Click on Tools.
  • Click on the Resident icon in the list.
  • Uncheck Resident TeaTimer and OK any prompts.
  • Download ResetTeaTimer.bat and run it to remove entries set by TeaTimer. If you are not using Internet Explorer, you may not be prompted to download the file when you click it. In that case, right click it and select "Save Target/Link as" and save the file onto your desktop.
    The file should take only a second to finish. Delete this file after use.
Restart your computer for the changes to take affect.

Download and Run ComboFix
Download Combofix by sUBs from any of the links below, and save it to your desktop.
Link 1, Link 2, Link 3
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click on ComboFix.exe and follow the prompts. If you are using Windows Vista, right click the icon and select "Run as Administrator". You will not recieve the prompts below if you are not using Windows XP. ComboFix will check to see if you have the Windows Recovery Console installed.
  • If you did not have it installed, you will see the prompt below. Choose YES.
    Posted ImagePosted Image

  • When the Recovery Console has been installed, you will see the prompt below. Choose YES.
    Posted Image
  • When finished, ComboFix will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Give me an update on the symptoms.

With Regards,
The Panda

#10 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 14 January 2009 - 09:53 PM

Sorry so long had to get my kids. I had a little trouble so I uninstalled avg all together. then after combofix ran I couldn't get connected to the net. here is the log.

ComboFix 09-01-13.04 - Paul 2009-01-14 20:41:34.1 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.2047.1464 [GMT -6:00]
Running from: c:\users\Paul\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2008-12-15 to 2009-01-15 )))))))))))))))))))))))))))))))
.

2009-01-14 20:20 . 2009-01-14 20:20 <DIR> d-------- c:\users\All Users\Avg8
2009-01-14 20:20 . 2009-01-14 20:20 <DIR> d-------- c:\programdata\Avg8
2009-01-14 10:18 . 2009-01-14 10:51 250 --a------ c:\windows\gmer.ini
2009-01-09 21:19 . 2009-01-14 18:22 <DIR> d-------- c:\users\Paul\SmitfraudFix
2009-01-07 16:58 . 2009-01-07 16:58 <DIR> d-------- c:\program files\Netflix
2009-01-06 17:38 . 2008-05-09 21:35 885,248 --a------ c:\windows\System32\RacEngn.dll
2009-01-06 17:38 . 2008-09-02 21:59 468,992 --a------ c:\windows\System32\newdev.dll
2009-01-06 17:38 . 2008-09-02 21:58 74,752 --a------ c:\windows\System32\newdev.exe
2009-01-06 17:38 . 2008-05-09 16:22 9,127 --a------ c:\windows\System32\RacUR.xml
2009-01-06 17:38 . 2008-05-09 16:22 153 --a------ c:\windows\System32\RacUREx.xml
2009-01-04 10:11 . 2009-01-04 10:11 <DIR> d-------- c:\windows\System32\RTCOM
2009-01-04 10:10 . 2008-08-17 04:33 678,408 --a------ c:\windows\System32\gpprefcl.dll
2009-01-03 23:30 . 2009-01-03 23:30 <DIR> d-------- c:\users\All Users\NVIDIA
2009-01-03 23:30 . 2009-01-03 23:30 <DIR> d-------- c:\programdata\NVIDIA
2009-01-03 23:19 . 2008-10-01 19:32 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-01-03 23:17 . 2008-09-17 23:55 1,108,512 --a------ c:\windows\System32\nvcpluir.dll
2009-01-03 23:17 . 2008-09-17 23:55 797,216 --a------ c:\windows\System32\nvcplui.exe
2009-01-03 23:17 . 2008-09-17 23:55 453,152 --a------ c:\windows\System32\nvuninst.exe
2009-01-03 23:17 . 2008-09-17 23:55 420,384 --a------ c:\windows\System32\nvcpl.cpl
2009-01-03 23:16 . 2009-01-03 23:17 <DIR> d-------- c:\users\Paul\{030b466e-2888-4fa0-b131-0d7bc0902e27}
2009-01-03 23:15 . 2008-10-21 19:22 2,048 --a------ c:\windows\System32\tzres.dll
2009-01-03 20:16 . 2008-06-25 19:45 12,240,896 --a------ c:\windows\System32\NlsLexicons0007.dll
2009-01-03 20:16 . 2008-06-25 19:45 2,644,480 --a------ c:\windows\System32\NlsLexicons0009.dll
2009-01-03 20:16 . 2008-06-25 21:29 801,280 --a------ c:\windows\System32\NaturalLanguage6.dll
2009-01-03 20:11 . 2008-09-17 23:09 3,601,464 --a------ c:\windows\System32\ntkrnlpa.exe
2009-01-03 20:01 . 2008-10-16 15:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2009-01-03 20:01 . 2008-10-16 14:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2009-01-03 20:01 . 2008-10-16 15:12 561,688 --a------ c:\windows\System32\wuapi.dll
2009-01-03 20:01 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2009-01-03 20:01 . 2008-10-16 14:55 83,456 --a------ c:\windows\System32\wudriver.dll
2009-01-03 20:01 . 2008-10-16 15:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2009-01-03 20:01 . 2008-10-16 15:09 43,544 --a------ c:\windows\System32\wups2.dll
2009-01-03 20:01 . 2008-10-16 15:08 34,328 --a------ c:\windows\System32\wups.dll
2009-01-03 20:01 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-12-29 21:48 . 2008-12-29 21:48 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-28 11:46 . 2008-12-28 11:46 <DIR> d-------- c:\program files\Trend Micro
2008-12-28 00:19 . 2008-12-28 00:19 <DIR> d-------- c:\users\Paul\AppData\Roaming\Iomatic
2008-12-28 00:19 . 2008-12-28 00:19 <DIR> d-------- c:\users\All Users\FTWeak
2008-12-28 00:19 . 2008-12-28 00:19 <DIR> d-------- c:\programdata\FTWeak
2008-12-28 00:19 . 2008-12-28 00:19 <DIR> d-------- c:\program files\FCleaner
2008-12-26 23:47 . 2008-12-26 23:47 <DIR> d-------- c:\users\All Users\Kaspersky Lab Setup Files
2008-12-26 23:47 . 2008-12-26 23:47 <DIR> d-------- c:\programdata\Kaspersky Lab Setup Files
2008-12-26 21:11 . 2008-12-28 00:22 <DIR> d-------- c:\users\All Users\PrevxCSI
2008-12-26 21:11 . 2008-12-28 00:22 <DIR> d-------- c:\programdata\PrevxCSI
2008-12-26 19:37 . 2008-12-26 19:37 <DIR> d-------- c:\program files\Java
2008-12-26 19:37 . 2008-12-26 19:37 410,984 --a------ c:\windows\System32\deploytk.dll
2008-12-26 16:21 . 2008-12-27 22:06 <DIR> d-------- c:\users\All Users\Spybot - Search & Destroy
2008-12-26 16:21 . 2008-12-27 22:06 <DIR> d-------- c:\programdata\Spybot - Search & Destroy
2008-12-26 16:21 . 2008-12-26 16:22 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-26 11:44 . 2009-01-07 16:59 <DIR> d--hs---- c:\windows\Installer
2008-12-25 23:31 . 2008-12-27 00:26 <DIR> d-------- c:\windows\System32\Macromed
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Videos
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Searches
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Saved Games
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Pictures
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Music
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Links
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Downloads
2008-12-25 19:53 . 2008-12-26 11:55 <DIR> dr------- c:\users\Paul\Documents
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> dr------- c:\users\Paul\Contacts
2008-12-25 19:53 . 2008-12-25 19:53 <DIR> d--h----- c:\users\Paul\AppData
2008-12-25 19:53 . 2009-01-14 18:22 <DIR> d-------- c:\users\Paul
2008-12-24 13:23 . 2008-12-25 19:53 <DIR> d--hs---- C:\$RECYCLE.BIN
2008-12-24 11:28 . 2008-12-24 11:28 <DIR> dr------- c:\windows\System32\config\systemprofile\Contacts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 05:25 --------- d-----w c:\program files\Windows Mail
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-10-16 04:47 827,392 ----a-w c:\windows\System32\wininet.dll
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
"FTweakFCleaner"="c:\program files\FCleaner\FCleaner.exe" [2008-12-19 1636352]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-20 c:\windows\System32\oobefldr.dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-26 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-27 c:\windows\RtHDVCpl.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2007-07-22 180736]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 20:42:30
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-01-14 20:44:12
ComboFix-quarantined-files.txt 2009-01-15 02:44:11

Pre-Run: 124,197,122,048 bytes free
Post-Run: 124,180,770,816 bytes free

144 --- E O F --- 2009-01-06 23:39:18

#11 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:19 PM

Posted 15 January 2009 - 08:28 AM

Hello.

Please refer to here on restoring your connection.

Is the hijack gone?

With Regards,
The Panda

#12 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 15 January 2009 - 12:11 PM

grr lost the first reply so here we go again. I ran spybot this mourning and got the zlob.dnschanger flag again. I let spybot fix the problem, and was able to connect to windows update and get my updates. I waited a little wile and ran spybot S&D again and the problem is back. Then I can't connect to update anymore. This what usually happens. Also when I google windows update and click on the first link it takes me back to googles web page. All the other links say can not be found. Here is the spybot S&D report. I also let it fix the problem again.

Hint of the Day: Click the bar at the right of this to see more information! ()


Zlob.DNSChanger: [SBI $041D1396] TCP/IP Settings #1 (Undefined) (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer=208.67.220.220,208.67.222.222 1.2.3.4

Zlob.DNSChanger: [SBI $041D1396] TCP/IP Settings #2 (Undefined) (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{759EF170-8912-4F30-AE1B-A9E55946E83B}\DhcpNameServer=208.67.220.220,208.67.222.222 1.2.3.4


--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---

2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-09-16 TeaTimer.exe (1.6.3.25)
2008-12-26 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-10-22 advcheck.dll (1.6.2.13)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2008-11-04 Includes\Adware.sbi (*)
2008-12-22 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-12-22 Includes\HijackersC.sbi (*)
2008-12-09 Includes\Keyloggers.sbi (*)
2008-12-22 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-22 Includes\MalwareC.sbi (*)
2008-12-16 Includes\PUPS.sbi (*)
2008-12-16 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-12-16 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-12-10 Includes\Spyware.sbi (*)
2008-12-10 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-12-23 Includes\Trojans.sbi (*)
2008-12-22 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

#13 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 15 January 2009 - 12:14 PM

Also should I install avg and turn on tea timer again.

#14 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:19 PM

Posted 15 January 2009 - 03:25 PM

Hello.

Leave your protection off for now please.

Let's try something else.

Please follow the directions given here on setting Open DNS.

Tell me if the hijack still occurs after.

With Regards,
The Panda

#15 onedead

onedead
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:illinois, us
  • Local time:11:19 AM

Posted 17 January 2009 - 12:22 PM

I think I got the open dns stuff right. I also had to do my router. I rebooted and did a scan with spybot S&D and the zlob.dnschanger is still there and I once again can't connect to windows update and am getting redirected or can't connect when I google windows update and click on the links.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users