Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cannot run MBAM or Rootrepeal


  • This topic is locked This topic is locked
11 replies to this topic

#1 mozley411

mozley411

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:05:30 AM

Posted 24 June 2009 - 06:30 PM

Referred from: http://www.bleepingcomputer.com/forums/t/235081/ie-8-and-google-link-problems/ ~ OB

Pasting in some information from that initial post. ~ OB

When I click on a google link it redirects me to another page, not the link I wanted. Internet Explorer 8 is constantly giving me error messages and sometimes closes abruptly.
Microsoft Windows XP Professional Version 2002 Service Pack 3
IE 8 error message:
AppName: iexplore.exe AppVer: 8.0.6001.18702 ModName: unknown
ModVer: 0.0.0.0 Offset: 051c9c5c

End of added material. ~ OB

DDS (Ver_09-05-14.01) - NTFSx86
Run by Administrator at 18:22:07.65 on Wed 06/24/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.356 [GMT -5:00]

AV: avast! antivirus 4.8.1335 [VPS 090624-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Linksys\WMP110\gtwpssrv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys\WMP110\WLSngS.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Linksys\WMP110\WMP110.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.tattoodle.com?tid={05224636-BD79-4dff-998A-71E18D958B67}&v=12
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://www.aol.com/?ncid=customie8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll
uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\fast browser search\ie\tbhelper.dll
mURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Gamevance: {0ed403e8-470a-4a8a-85a4-d7688cfe39a3} - c:\program files\gamevance\gamevancelib32.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AOL Toolbar Loader: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol toolbar\aoltb.dll
BHO: {84aa61c2-a977-4fd8-9e2f-c768f0387572} - c:\windows\system32\cbXOGWpq.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: {e1d147a3-ab30-38b9-1ca4-512db4d574da}: {ad475d4b-d215-4ac1-9b83-03ba3a741d1e} - c:\windows\system32\vajgsu.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Gamevance Text: {beac7dc8-e106-4c6a-931e-5a42e7362883} - c:\program files\gamevance\gvtl.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Search Assistant: {f0626a63-410b-45e2-99a1-3f2475b2d695} - c:\program files\sgpsa\BHO.dll
BHO: {f4ed6fc6-a6a2-4137-a878-1feab18e4b62} - c:\windows\system32\cbXQhIBQ.dll
BHO: Fast Browser Search Toolbar Helper: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\fast browser search\ie\FBStoolbar.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol toolbar\aoltb.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Fast Browser Search Toolbar: {1bb22d38-a411-4b13-a746-c2a4f4ec7344} - c:\program files\fast browser search\ie\FBStoolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [A00F41A89.exe] c:\docume~1\admini~1\locals~1\temp\_A00F41A89.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [DrvLsnr] c:\program files\analog devices\soundmax\DrvLsnr.exe
mRun: [srmclean] c:\cpqs\scom\srmclean.exe
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [removecpl] RemoveCpl.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [WMP110] c:\program files\linksys\wmp110\WMP110.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Gamevance] c:\program files\gamevance\gamevance32.exe a
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [SGPUpdater] c:\program files\search guard plusu\sgpUpdaters.exe
mRun: [FBSearch] c:\program files\search guard plus\SearchGuardPlus.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\antispy\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn311\wlancfg5.exe
IE: &AOL Toolbar Search - c:\documents and settings\all users\application data\aol\ietoolbar\resources\en-us\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://aol.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {26E6B759-DEEB-42A1-A21C-78CD29098411} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fitness-dash/FitnessDashWeb.1.0.0.11.cab
DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} - hxxp://www.worldwinner.com/games/v45/moneylist/moneylist.cab
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager/plugin/IEGetPlugin.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} - hxxp://www.worldwinner.com/games/v63/bjattack/bja.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab
DPF: {64CD313F-F079-4D93-959F-4D28B5519449} - hxxp://www.worldwinner.com/games/v50/jeopardy/jeopardy.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215296670125
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} - hxxp://www.worldwinner.com/games/v49/luxor/luxor.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} - hxxp://www.worldwinner.com/games/v46/monopoly/monopoly.cab
DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-zenerchi/ZenerchiWeb.1.0.0.10.cab
DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} - hxxp://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab
DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} - hxxp://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 85.255.112.73,85.255.112.7
TCP: {C2723FB6-F821-42A7-83ED-171F238BEC60} = 85.255.112.73,85.255.112.7
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: 19aa3be1577 - c:\windows\system32\eappcfg32.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: cbXOGWpq - cbXOGWpq.dll
Notify: igfxcui - igfxsrvc.dll
Notify: __c0097304 - c:\windows\system32\__c0097304.dat
AppInit_DLLs: c:\windows\system32\eappcfg32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {84aa61c2-a977-4fd8-9e2f-c768f0387572} - c:\windows\system32\cbXOGWpq.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\cbXQhIBQ
LSA: Notification Packages = scecli emsjsd.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-17 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-17 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-17 138680]
R2 GTWPSService;GTWPSSRV;c:\program files\linksys\wmp110\gtwpssrv.exe [2009-1-25 34816]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-26 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R2 WLSng Service;WLSng Service;c:\program files\linksys\wmp110\WLSngS.exe [2009-1-25 233472]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-17 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-17 352920]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-1-25 57344]
R3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Wireless Driver;c:\windows\system32\drivers\WMP110v2.sys [2009-1-25 625024]
S3 getPlus® Installer;getPlus® Installer;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-5-9 59552]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\linksys\wmp110\jswpsapi.exe [2009-1-25 352338]
S3 Linker2K;LeapPort/MS2002 Driver;c:\windows\system32\drivers\Linker2K.sys [2009-4-7 23040]

=============== Created Last 30 ================

2009-06-24 16:35 -cd----- C:\backup
2009-06-24 16:29 -cd----- c:\windows\system32\NtmsData
2009-06-20 22:54 -cd----- c:\program files\Malwarebytes' Anti-Malware
2009-06-20 22:54 -cd----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-19 01:11 -cd----- c:\program files\Search Guard PlusU
2009-06-19 01:11 -cd----- c:\program files\Search Guard Plus
2009-06-19 01:11 -cd----- c:\program files\SGPSA
2009-06-19 01:11 -cd----- c:\program files\Fast Browser Search
2009-06-17 06:59 -cdsh--- c:\documents and settings\administrator\IECompatCache
2009-06-17 06:55 -cdsh--- c:\documents and settings\administrator\PrivacIE
2009-06-17 06:52 -cdsh--- c:\documents and settings\administrator\IETldCache
2009-06-17 06:21 -cd----- c:\program files\common files\Software Update Utility
2009-06-17 06:20 -cd----- c:\program files\AOL Toolbar
2009-06-17 06:20 -cd-h--- c:\windows\msdownld.tmp
2009-06-17 06:17 -cd-h--- c:\windows\ie8
2009-06-16 14:44 129,784 -c------ c:\windows\system32\pxafs.dll
2009-06-16 14:44 120,056 -c------ c:\windows\system32\pxcpyi64.exe
2009-06-16 14:44 118,520 -c------ c:\windows\system32\pxinsi64.exe
2009-06-16 14:43 -cd----- c:\program files\DivX
2009-06-16 14:43 -cd----- c:\program files\common files\DivX Shared
2009-06-09 09:21 -cd----- c:\program files\HDQuality
2009-06-09 06:29 -cd----- c:\program files\AviSynth 2.5
2009-06-09 06:28 -cd----- c:\program files\eRightSoft
2009-06-05 11:20 -cd----- c:\program files\AskSearch
2009-06-05 11:20 -cd----- c:\program files\AskBarDis
2009-06-05 11:19 -cd----- c:\program files\Gamevance
2009-05-26 20:21 38 ac------ c:\windows\pbMv.INI

==================== Find3M ====================

2009-05-26 20:21 2,828 ac-sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-05-26 20:16 88 -c-shr-- c:\docume~1\alluse~1\applic~1\DEBFC84715.sys
2009-05-01 16:02 90,112 ac------ c:\windows\system32\dpl100.dll
2009-05-01 16:02 823,296 ac------ c:\windows\system32\divx_xx0c.dll
2009-05-01 16:02 823,296 ac------ c:\windows\system32\divx_xx07.dll
2009-05-01 16:02 815,104 ac------ c:\windows\system32\divx_xx0a.dll
2009-05-01 16:02 811,008 ac------ c:\windows\system32\divx_xx16.dll
2009-05-01 16:02 802,816 ac------ c:\windows\system32\divx_xx11.dll
2009-05-01 16:02 685,056 ac------ c:\windows\system32\DivX.dll
2009-05-01 13:30 3,366,912 ac------ c:\windows\system32\GPhotos.scr
2009-04-19 15:51 331 -c------ C:\xcrashdump.dat
2009-04-18 07:24 87,944 ac------ c:\windows\pchealth\helpctr\offlinecache\index.dat
2006-12-04 11:57 35,232 ac------ c:\windows\inf\wpn311\ME_INST.EXE
2006-12-04 11:57 26,112 ac------ c:\windows\inf\wpn311\install.exe
2006-07-05 05:33 472,000 ac------ c:\windows\inf\wpn311\WPN311.sys
2006-05-03 05:06 163,328 -c-shr-- c:\windows\system32\flvDX.dll
2007-02-21 06:47 31,232 -c-shr-- c:\windows\system32\msfDX.dll
2008-03-16 08:30 216,064 -c-shr-- c:\windows\system32\nbDX.dll
2008-07-18 16:55 449 ac-sh--- c:\windows\system32\QBIhQXbc.ini2

============= FINISH: 18:22:40.34 ===============


NEXT LOG:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/24/2006 4:20:07 PM
System Uptime: 6/23/2009 7:00:56 PM (23 hours ago)

Motherboard: Hewlett-Packard | | 0830h
Processor: AMD Athlon™ XP 2600+ | XU1 PROCESSOR | 2129/266mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 37 GiB total, 21.832 GiB free.
D: is FIXED (NTFS) - 19 GiB total, 0.744 GiB free.
E: is CDROM ()
F: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 3Com 3C920B-EMB Integrated Fast Ethernet Controller
Device ID: PCI\VEN_10B7&DEV_9201&SUBSYS_12B8103C&REV_40\4&3939CDF2&0&0860
Manufacturer: 3Com
Name: 3Com 3C920B-EMB Integrated Fast Ethernet Controller
PNP Device ID: PCI\VEN_10B7&DEV_9201&SUBSYS_12B8103C&REV_40\4&3939CDF2&0&0860
Service: EL90Xbc

==== System Restore Points ===================

RP494: 4/21/2009 2:25:02 AM - Windows Defender Checkpoint
RP495: 4/22/2009 12:00:21 AM - Software Distribution Service 3.0
RP496: 4/23/2009 12:00:14 AM - Software Distribution Service 3.0
RP497: 4/24/2009 12:00:14 AM - Software Distribution Service 3.0
RP498: 4/24/2009 1:37:24 AM - Software Distribution Service 3.0
RP499: 4/25/2009 12:00:15 AM - Software Distribution Service 3.0
RP500: 4/26/2009 12:00:59 AM - Software Distribution Service 3.0
RP501: 4/27/2009 12:00:15 AM - Software Distribution Service 3.0
RP502: 4/27/2009 11:16:22 AM - Software Distribution Service 3.0
RP503: 4/28/2009 12:00:13 AM - Software Distribution Service 3.0
RP504: 4/29/2009 12:00:15 AM - Software Distribution Service 3.0
RP505: 4/30/2009 12:00:14 AM - Software Distribution Service 3.0
RP506: 4/30/2009 4:43:02 PM - Software Distribution Service 3.0
RP507: 5/1/2009 12:00:17 AM - Software Distribution Service 3.0
RP508: 5/2/2009 12:00:15 AM - Software Distribution Service 3.0
RP509: 5/3/2009 12:00:14 AM - Software Distribution Service 3.0
RP510: 5/4/2009 12:55:02 AM - System Checkpoint
RP511: 5/5/2009 12:00:15 AM - Software Distribution Service 3.0
RP512: 5/5/2009 1:29:10 AM - Software Distribution Service 3.0
RP513: 5/6/2009 12:00:17 AM - Software Distribution Service 3.0
RP514: 5/7/2009 12:00:21 AM - Software Distribution Service 3.0
RP515: 5/7/2009 7:50:44 PM - Software Distribution Service 3.0
RP516: 5/8/2009 12:00:13 AM - Software Distribution Service 3.0
RP517: 5/9/2009 12:00:14 AM - Software Distribution Service 3.0
RP518: 5/9/2009 7:18:36 PM - Installed Windows Media Player 11
RP519: 5/9/2009 7:21:25 PM - Installed Windows XP MSCompPackV1.
RP520: 5/9/2009 7:51:15 PM - Installed Driver Detective
RP521: 5/9/2009 7:56:15 PM - Removed Driver Detective
RP522: 5/9/2009 8:32:09 PM - Installed DirectX
RP523: 5/9/2009 8:32:55 PM - Installed WinDVD
RP524: 5/10/2009 12:00:20 AM - Software Distribution Service 3.0
RP525: 5/11/2009 12:00:18 AM - Software Distribution Service 3.0
RP526: 5/11/2009 9:10:47 PM - Software Distribution Service 3.0
RP527: 5/12/2009 10:28:18 PM - System Checkpoint
RP528: 5/13/2009 12:00:13 AM - Software Distribution Service 3.0
RP529: 5/13/2009 9:11:08 PM - Installed Microsoft Office Professional 2007 Trial
RP530: 5/14/2009 9:14:01 PM - System Checkpoint
RP531: 5/15/2009 12:00:17 AM - Software Distribution Service 3.0
RP532: 5/15/2009 12:44:57 AM - Software Distribution Service 3.0
RP533: 5/16/2009 1:14:03 AM - System Checkpoint
RP534: 5/17/2009 1:53:09 AM - System Checkpoint
RP535: 5/18/2009 2:07:18 AM - System Checkpoint
RP536: 5/18/2009 9:52:15 AM - Software Distribution Service 3.0
RP537: 5/19/2009 9:54:47 AM - System Checkpoint
RP538: 5/20/2009 10:54:47 AM - System Checkpoint
RP539: 5/21/2009 11:05:25 AM - System Checkpoint
RP540: 5/21/2009 11:45:40 PM - Software Distribution Service 3.0
RP541: 5/23/2009 1:26:47 AM - System Checkpoint
RP542: 5/24/2009 1:39:51 AM - System Checkpoint
RP543: 5/25/2009 6:16:22 AM - System Checkpoint
RP544: 5/26/2009 12:15:25 AM - Software Distribution Service 3.0
RP545: 5/27/2009 12:20:12 AM - System Checkpoint
RP546: 5/28/2009 12:32:39 AM - System Checkpoint
RP547: 5/28/2009 10:00:03 AM - Software Distribution Service 3.0
RP548: 5/29/2009 10:31:34 AM - System Checkpoint
RP549: 5/30/2009 10:39:31 AM - System Checkpoint
RP550: 5/31/2009 11:26:50 AM - System Checkpoint
RP551: 6/1/2009 10:37:31 PM - Software Distribution Service 3.0
RP552: 6/2/2009 11:58:51 PM - System Checkpoint
RP553: 6/4/2009 1:05:57 AM - System Checkpoint
RP554: 6/4/2009 2:23:25 PM - Software Distribution Service 3.0
RP555: 6/5/2009 2:24:27 PM - System Checkpoint
RP556: 6/6/2009 4:30:08 PM - System Checkpoint
RP557: 6/7/2009 5:00:07 PM - System Checkpoint
RP558: 6/8/2009 5:49:13 PM - System Checkpoint
RP559: 6/9/2009 12:00:21 AM - Software Distribution Service 3.0
RP560: 6/18/2009 12:26:27 AM - Software Distribution Service 3.0

==== Installed Programs ======================

AAC Decoder
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9
Adobe Shockwave Player
AOL Toolbar
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
AutoUpdate
avast! Antivirus
Bonjour
Bookworm Deluxe 1.13
Broadcom Management Programs
Broadcom NetXtreme Ethernet Controller
Classroom Jeopardy!® Editor 1.0
Critical Update for Windows Media Player 11 (KB959772)
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
Download Updater (AOL LLC)
Fast Browser Search (My Web Tattoo)
getPlus® for Corel
Google Toolbar for Internet Explorer
H.264 Decoder
HDQuality
Hotfix for Microsoft .NET Framework 2.0 (KB922981)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Product Detection
Intel® Extreme Graphics Driver
InterVideo WinDVD
iTunes
Java™ 6 Update 7
Kazaa 3.2.7
LimeWire 4.18.8
Linksys WMP110 RangePlus Wireless PCI Adapter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Professional 2007 Trial
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MKV Splitter
Move Networks Media Player for Internet Explorer
MP3 Player Utilities 4.18
MSXML 4.0 SP2 (KB954430)
NETGEAR WPN311 Wireless Adapter
NVIDIA nForce Drivers
Octoshape add-in for Adobe Flash Player
Picasa 3
QuickTime
RealPlayer
Search Guard Plus (My Web Tattoo)
Search Guard Plus Updater (My Web Tattoo)
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB960003)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Microsoft Office Excel 2007 (KB959997)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Outlook 2007 (KB946983)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
Software Setup
SoundMAX
SUPER © Version 2009.bld.35 (Jan 5, 2009)
System Requirements Lab
U-Storage Service
Update for 2007 Microsoft Office System (KB967642)
Update for Office 2007 (KB934391)
Update for Outlook 2007 Junk Email Filter (kb968503)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC80CRTRedist - 8.0.50727.762
Ventrilo Client
Viewpoint Media Player
WebFldrs XP
Windows Defender
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft
Yahoo! Messenger
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

6/24/2009 6:17:47 PM, error: Removable Storage Service [15] - RSM cannot manage library CdRom1. The database is corrupt.
6/24/2009 4:31:34 PM, error: Removable Storage Service [15] - RSM cannot manage library CdRom0. The database is corrupt.
6/23/2009 7:02:00 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
6/17/2009 6:44:47 AM, error: Service Control Manager [7000] - The Ventrilo service failed to start due to the following error: The system cannot find the path specified.
6/17/2009 6:09:03 AM, error: Cdrom [11] - The driver detected a controller error on \Device\CdRom0.

==== End Of File ===========================
:thumbup2:

Edited by Orange Blossom, 24 June 2009 - 07:35 PM.


BC AdBot (Login to Remove)

 


#2 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,205 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:01:30 PM

Posted 28 June 2009 - 04:58 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#3 mozley411

mozley411
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:05:30 AM

Posted 28 June 2009 - 09:18 AM

Problem:
When I click on a google link it redirects me to some other site - I have to click the back button and click on the link again to go to the site that I selected. I am constantly getting Internet Ex error messages that ask me if I want to send a report of the error.

DDS notepad file:

DDS (Ver_09-06-26.01) - NTFSx86
Run by Administrator at 9:08:38.59 on Sun 06/28/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.577 [GMT -5:00]

AV: avast! antivirus 4.8.1335 [VPS 090627-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Linksys\WMP110\gtwpssrv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys\WMP110\WLSngS.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Linksys\WMP110\WMP110.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.tattoodle.com?tid={05224636-BD79-4dff-998A-71E18D958B67}&v=12
uSearch Page =
uDefault_Search_URL = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://www.aol.com/?ncid=customie8
uSearch Bar =
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
mSearchAssistant =
uURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll
mURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Gamevance: {0ed403e8-470a-4a8a-85a4-d7688cfe39a3} - c:\program files\gamevance\gamevancelib32.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AOL Toolbar Loader: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol toolbar\aoltb.dll
BHO: {84aa61c2-a977-4fd8-9e2f-c768f0387572} - c:\windows\system32\cbXOGWpq.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: {e1d147a3-ab30-38b9-1ca4-512db4d574da}: {ad475d4b-d215-4ac1-9b83-03ba3a741d1e} - c:\windows\system32\vajgsu.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Gamevance Text: {beac7dc8-e106-4c6a-931e-5a42e7362883} - c:\program files\gamevance\gvtl.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Search Assistant: {f0626a63-410b-45e2-99a1-3f2475b2d695} - c:\program files\sgpsa\BHO.dll
BHO: {f4ed6fc6-a6a2-4137-a878-1feab18e4b62} - c:\windows\system32\cbXQhIBQ.dll
BHO: Fast Browser Search Toolbar Helper: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\fast browser search\ie\FBStoolbar.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol toolbar\aoltb.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [A00F41A89.exe] c:\docume~1\admini~1\locals~1\temp\_A00F41A89.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [DrvLsnr] c:\program files\analog devices\soundmax\DrvLsnr.exe
mRun: [srmclean] c:\cpqs\scom\srmclean.exe
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [removecpl] RemoveCpl.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [WMP110] c:\program files\linksys\wmp110\WMP110.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Gamevance] c:\program files\gamevance\gamevance32.exe a
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [SGPUpdater] c:\program files\search guard plusu\sgpUpdaters.exe
mRun: [FBSearch] c:\program files\search guard plus\SearchGuardPlus.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn311\wlancfg5.exe
IE: &AOL Toolbar Search - c:\documents and settings\all users\application data\aol\ietoolbar\resources\en-us\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://aol.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {26E6B759-DEEB-42A1-A21C-78CD29098411} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fitness-dash/FitnessDashWeb.1.0.0.11.cab
DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} - hxxp://www.worldwinner.com/games/v45/moneylist/moneylist.cab
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager/plugin/IEGetPlugin.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} - hxxp://www.worldwinner.com/games/v63/bjattack/bja.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab
DPF: {64CD313F-F079-4D93-959F-4D28B5519449} - hxxp://www.worldwinner.com/games/v50/jeopardy/jeopardy.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215296670125
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} - hxxp://www.worldwinner.com/games/v49/luxor/luxor.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} - hxxp://www.worldwinner.com/games/v46/monopoly/monopoly.cab
DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-zenerchi/ZenerchiWeb.1.0.0.10.cab
DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} - hxxp://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab
DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} - hxxp://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 85.255.112.73,85.255.112.7
TCP: {C2723FB6-F821-42A7-83ED-171F238BEC60} = 85.255.112.73,85.255.112.7
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: 19aa3be1577 - c:\windows\system32\eappcfg32.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: cbXOGWpq - cbXOGWpq.dll
Notify: igfxcui - igfxsrvc.dll
Notify: __c0097304 - c:\windows\system32\__c0097304.dat
AppInit_DLLs: c:\windows\system32\eappcfg32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {84aa61c2-a977-4fd8-9e2f-c768f0387572} - c:\windows\system32\cbXOGWpq.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\cbXQhIBQ
LSA: Notification Packages = scecli emsjsd.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-17 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-17 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-17 138680]
R2 GTWPSService;GTWPSSRV;c:\program files\linksys\wmp110\gtwpssrv.exe [2009-1-25 34816]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-26 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R2 WLSng Service;WLSng Service;c:\program files\linksys\wmp110\WLSngS.exe [2009-1-25 233472]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-17 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-17 352920]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-1-25 57344]
R3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Wireless Driver;c:\windows\system32\drivers\WMP110v2.sys [2009-1-25 625024]
S3 getPlus® Installer;getPlus® Installer;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-5-9 59552]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\linksys\wmp110\jswpsapi.exe [2009-1-25 352338]
S3 Linker2K;LeapPort/MS2002 Driver;c:\windows\system32\drivers\Linker2K.sys [2009-4-7 23040]

=============== Created Last 30 ================

2009-06-24 16:35 <DIR> -cd----- C:\backup
2009-06-24 16:29 <DIR> -cd----- c:\windows\system32\NtmsData
2009-06-20 22:54 <DIR> -cd----- c:\program files\Malwarebytes' Anti-Malware
2009-06-20 22:54 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-19 01:11 <DIR> -cd----- c:\program files\Search Guard PlusU
2009-06-19 01:11 <DIR> -cd----- c:\program files\Search Guard Plus
2009-06-19 01:11 <DIR> -cd----- c:\program files\SGPSA
2009-06-19 01:11 <DIR> -cd----- c:\program files\Fast Browser Search
2009-06-17 06:59 <DIR> -cdsh--- c:\documents and settings\administrator\IECompatCache
2009-06-17 06:55 <DIR> -cdsh--- c:\documents and settings\administrator\PrivacIE
2009-06-17 06:52 <DIR> -cdsh--- c:\documents and settings\administrator\IETldCache
2009-06-17 06:21 <DIR> -cd----- c:\program files\common files\Software Update Utility
2009-06-17 06:20 <DIR> -cd----- c:\program files\AOL Toolbar
2009-06-17 06:20 <DIR> -cd-h--- c:\windows\msdownld.tmp
2009-06-17 06:17 <DIR> -cd-h--- c:\windows\ie8
2009-06-16 14:44 129,784 -c------ c:\windows\system32\pxafs.dll
2009-06-16 14:44 120,056 -c------ c:\windows\system32\pxcpyi64.exe
2009-06-16 14:44 118,520 -c------ c:\windows\system32\pxinsi64.exe
2009-06-16 14:43 <DIR> -cd----- c:\program files\DivX
2009-06-16 14:43 <DIR> -cd----- c:\program files\common files\DivX Shared
2009-06-09 09:21 <DIR> -cd----- c:\program files\HDQuality
2009-06-09 06:29 <DIR> -cd----- c:\program files\AviSynth 2.5
2009-06-09 06:28 <DIR> -cd----- c:\program files\eRightSoft
2009-06-05 11:20 <DIR> -cd----- c:\program files\AskSearch
2009-06-05 11:20 <DIR> -cd----- c:\program files\AskBarDis
2009-06-05 11:19 <DIR> -cd----- c:\program files\Gamevance

==================== Find3M ====================

2009-05-26 20:21 2,828 ac-sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-05-26 20:16 88 -c-shr-- c:\docume~1\alluse~1\applic~1\DEBFC84715.sys
2009-05-01 16:02 90,112 ac------ c:\windows\system32\dpl100.dll
2009-05-01 16:02 823,296 ac------ c:\windows\system32\divx_xx0c.dll
2009-05-01 16:02 823,296 ac------ c:\windows\system32\divx_xx07.dll
2009-05-01 16:02 815,104 ac------ c:\windows\system32\divx_xx0a.dll
2009-05-01 16:02 811,008 ac------ c:\windows\system32\divx_xx16.dll
2009-05-01 16:02 802,816 ac------ c:\windows\system32\divx_xx11.dll
2009-05-01 16:02 685,056 ac------ c:\windows\system32\DivX.dll
2009-05-01 13:30 3,366,912 ac------ c:\windows\system32\GPhotos.scr
2009-04-19 15:51 331 -c------ C:\xcrashdump.dat
2009-04-18 07:24 87,944 ac------ c:\windows\pchealth\helpctr\offlinecache\index.dat
2006-12-04 11:57 35,232 ac------ c:\windows\inf\wpn311\ME_INST.EXE
2006-12-04 11:57 26,112 ac------ c:\windows\inf\wpn311\install.exe
2006-07-05 05:33 472,000 ac------ c:\windows\inf\wpn311\WPN311.sys
2006-05-03 05:06 163,328 -c-shr-- c:\windows\system32\flvDX.dll
2007-02-21 06:47 31,232 -c-shr-- c:\windows\system32\msfDX.dll
2008-03-16 08:30 216,064 -c-shr-- c:\windows\system32\nbDX.dll
2008-07-18 16:55 449 ac-sh--- c:\windows\system32\QBIhQXbc.ini2

============= FINISH: 9:09:18.07 ===============

Attached Files



#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:30 AM

Posted 29 June 2009 - 01:27 PM

Hello.

Download and Run ComboFix
Download Combofix by sUBs from any of the links below, and save it to your desktop.
Link 1, Link 2, Link 3
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click on ComboFix.exe and follow the prompts. If you are using Windows Vista, right click the icon and select "Run as Administrator". You will not recieve the prompts below if you are not using Windows XP. ComboFix will check to see if you have the Windows Recovery Console installed.
  • If you did not have it installed, you will see the prompt below. Choose YES.
    Posted ImagePosted Image

  • When the Recovery Console has been installed, you will see the prompt below. Choose YES.
    Posted Image
  • When finished, ComboFix will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

With regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 mozley411

mozley411
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:05:30 AM

Posted 30 June 2009 - 12:09 AM

Thanks! Here is the combofix log:

ComboFix 09-06-29.04 - Administrator 06/29/2009 23:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.639 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix2.exe
AV: avast! antivirus 4.8.1335 [VPS 090629-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Application Data\02000000894e882c577C.manifest
c:\documents and settings\Administrator\Application Data\02000000894e882c577O.manifest
c:\documents and settings\Administrator\Application Data\02000000894e882c577P.manifest
c:\documents and settings\Administrator\Application Data\02000000894e882c577S.manifest
c:\windows\cdmxtras
c:\windows\cookies.ini
c:\windows\GnuHashes.ini
c:\windows\system32\AdCache
c:\windows\system32\augfoprs.ini
c:\windows\system32\AVSredirect.dll
c:\windows\system32\cache329
c:\windows\system32\ccdxkync.ini
c:\windows\system32\drivers\fad.sys
c:\windows\system32\drivers\MSIVXlqjeareaodoyktfoklmxpujenlmnmomx.sys
c:\windows\system32\eqcsnnlh.ini
c:\windows\system32\fjahlrcd.ini
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\KYn5jYr.vbs
c:\windows\system32\lkuijvgj.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXgvosmvjsadeppqodixyfkkcdwecyjvtx.dll
c:\windows\system32\MSIVXjyoikjdppujwghoqjtusawyrixppyaur.dll
c:\windows\system32\mxdxwkiq.ini
c:\windows\system32\nfnjvsbs.ini
c:\windows\system32\oyatfbeg.ini
c:\windows\system32\pbsilihy.ini
c:\windows\system32\QBIhQXbc.ini
c:\windows\system32\QBIhQXbc.ini2
c:\windows\system32\ruyfeguq.ini
c:\windows\system32\tfddvvtl.ini
c:\windows\system32\wfhqwvqg.ini
c:\windows\system32\whostqwh.ini
c:\windows\system32\wotgjmpd.ini
c:\windows\system32\Z3YrM8USAAmN3vz.vbs
C:\xcrashdump.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-30 )))))))))))))))))))))))))))))))
.

2009-06-24 21:35 . 2009-06-24 21:35 -------- dc----w- C:\backup
2009-06-24 21:29 . 2009-06-24 23:17 -------- dc----w- c:\windows\system32\NtmsData
2009-06-21 03:54 . 2009-06-21 04:04 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-21 03:54 . 2009-06-21 03:54 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-19 06:11 . 2009-06-19 06:11 -------- dc----w- c:\program files\Search Guard PlusU
2009-06-19 06:11 . 2009-06-19 06:11 -------- dc----w- c:\program files\Search Guard Plus
2009-06-19 06:11 . 2009-06-19 06:11 -------- dc----w- c:\program files\SGPSA
2009-06-19 06:11 . 2009-06-19 06:11 -------- dc----w- c:\program files\Fast Browser Search
2009-06-17 12:11 . 2009-02-05 20:06 23152 -c--a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-17 12:11 . 2009-02-05 20:06 51376 -c--a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-17 12:11 . 2009-02-05 20:05 26944 -c--a-w- c:\windows\system32\drivers\aavmker4.sys
2009-06-17 12:11 . 2009-02-05 20:04 97480 -c--a-w- c:\windows\system32\AvastSS.scr
2009-06-17 12:11 . 2009-02-05 20:08 93296 -c--a-w- c:\windows\system32\drivers\aswmon.sys
2009-06-17 12:11 . 2009-02-05 20:08 94032 -c--a-w- c:\windows\system32\drivers\aswmon2.sys
2009-06-17 12:11 . 2009-02-05 20:07 114768 -c--a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-17 12:11 . 2009-02-05 20:07 20560 -c--a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-17 12:11 . 2009-02-05 20:11 1256296 -c--a-w- c:\windows\system32\aswBoot.exe
2009-06-17 12:11 . 2009-06-17 12:11 -------- dc----w- c:\program files\Alwil Software
2009-06-17 11:59 . 2009-06-17 11:59 -------- dcsh--w- c:\documents and settings\Administrator\IECompatCache
2009-06-17 11:55 . 2009-06-17 11:55 -------- dcsh--w- c:\documents and settings\Administrator\PrivacIE
2009-06-17 11:52 . 2009-06-17 11:52 -------- dcsh--w- c:\documents and settings\Administrator\IETldCache
2009-06-17 11:45 . 2009-06-17 11:45 -------- dcsh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-17 11:21 . 2009-06-17 11:21 -------- dc----w- c:\program files\Common Files\Software Update Utility
2009-06-17 11:20 . 2009-06-17 11:20 -------- dc----w- c:\program files\AOL Toolbar
2009-06-17 11:20 . 2009-06-17 11:21 -------- dc-h--w- c:\windows\msdownld.tmp
2009-06-17 11:17 . 2009-06-17 11:18 -------- dc-h--w- c:\windows\ie8
2009-06-16 19:45 . 2009-06-16 19:45 -------- dc----w- c:\documents and settings\Administrator\Application Data\DivX
2009-06-16 19:44 . 2009-05-01 21:03 129784 -c----w- c:\windows\system32\pxafs.dll
2009-06-16 19:44 . 2009-05-01 21:03 120056 -c----w- c:\windows\system32\pxcpyi64.exe
2009-06-16 19:44 . 2009-05-01 21:03 118520 -c----w- c:\windows\system32\pxinsi64.exe
2009-06-16 19:43 . 2009-06-16 19:44 -------- dc----w- c:\program files\DivX
2009-06-16 19:43 . 2009-06-16 19:43 -------- dc----w- c:\program files\Common Files\DivX Shared
2009-06-09 14:21 . 2009-06-09 14:21 -------- dc----w- c:\program files\HDQuality
2009-06-09 11:29 . 2007-05-17 22:30 318976 -c--a-w- c:\windows\system32\avisynth.dll
2009-06-09 11:29 . 2004-02-22 15:11 719872 -c--a-w- c:\windows\system32\devil.dll
2009-06-09 11:29 . 2004-01-25 05:00 70656 -c--a-w- c:\windows\system32\yv12vfw.dll
2009-06-09 11:29 . 2004-01-25 05:00 70656 -c--a-w- c:\windows\system32\i420vfw.dll
2009-06-09 11:29 . 2009-06-09 11:29 -------- dc----w- c:\program files\AviSynth 2.5
2009-06-09 11:29 . 2008-03-16 13:30 216064 -csh--r- c:\windows\system32\nbDX.dll
2009-06-09 11:29 . 2007-02-21 11:47 31232 -csh--r- c:\windows\system32\msfDX.dll
2009-06-09 11:29 . 2006-05-03 10:06 163328 -csh--r- c:\windows\system32\flvDX.dll
2009-06-09 11:28 . 2009-06-09 11:28 -------- dc----w- c:\program files\eRightSoft
2009-06-05 16:20 . 2009-06-05 17:11 -------- dc----w- c:\program files\AskBarDis
2009-06-05 16:20 . 2009-06-05 16:20 -------- dc----w- c:\program files\AskSearch
2009-06-05 16:19 . 2009-06-17 22:23 -------- dc----w- c:\program files\Gamevance

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-19 04:45 . 2008-10-15 13:39 -------- dc----w- c:\program files\Google
2009-06-18 19:19 . 2006-03-24 21:21 68424 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-18 13:01 . 2007-12-04 00:36 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-18 13:00 . 2008-11-29 20:38 -------- dc----w- c:\program files\McAfee
2009-06-18 05:27 . 2009-05-10 01:38 -------- dc----w- c:\program files\Corel
2009-06-18 05:27 . 2005-05-25 00:53 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-06-17 11:20 . 2007-12-26 07:43 -------- dc----w- c:\documents and settings\All Users\Application Data\AOL
2009-06-15 17:43 . 2007-12-04 00:18 -------- dc----w- c:\documents and settings\Administrator\Application Data\LimeWire
2009-06-09 05:06 . 2009-05-14 02:12 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-04 23:15 . 2008-09-30 15:06 -------- dc----w- c:\documents and settings\LocalService\Application Data\SACore
2009-05-27 01:21 . 2009-05-10 01:45 2828 -csha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-05-27 01:21 . 2009-05-10 01:45 2828 -csha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-05-27 01:16 . 2009-05-10 01:45 88 -csh--r- c:\documents and settings\All Users\Application Data\DEBFC84715.sys
2009-05-27 01:16 . 2009-05-10 01:45 88 -csh--r- c:\documents and settings\All Users\Application Data\DEBFC84715.sys
2009-05-23 03:57 . 2009-01-26 12:46 -------- dc----w- c:\documents and settings\Administrator\Application Data\Move Networks
2009-05-14 02:37 . 2009-05-14 01:56 -------- dc----w- c:\documents and settings\Administrator\Application Data\GetRightToGo
2009-05-14 02:20 . 2009-05-14 02:20 -------- dc----w- c:\program files\Microsoft Works
2009-05-14 02:17 . 2009-05-14 02:17 -------- dc----w- c:\program files\Microsoft.NET
2009-05-11 05:00 . 2009-05-11 05:00 -------- dc----w- c:\program files\MSXML 4.0
2009-05-10 01:47 . 2009-05-10 01:45 -------- dc----w- c:\documents and settings\Administrator\Application Data\Corel
2009-05-10 01:45 . 2009-01-26 02:28 -------- dc----w- c:\documents and settings\All Users\Application Data\NOS
2009-05-10 01:41 . 2009-05-10 01:41 -------- dc----w- c:\program files\Common Files\xing shared
2009-05-10 01:41 . 2009-05-10 01:41 -------- dc----w- c:\program files\Common Files\Real
2009-05-10 01:41 . 2009-05-10 01:41 -------- dc----w- c:\program files\Real
2009-05-10 01:21 . 2009-01-26 02:28 -------- dc----w- c:\program files\NOS
2009-05-10 00:51 . 2009-05-10 00:51 -------- dc----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-05-01 21:02 . 2009-05-01 21:02 90112 -c--a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 -c--a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 -c--a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 -c--a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 -c--a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 -c--a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 -c--a-w- c:\windows\system32\DivX.dll
2009-05-01 18:30 . 2009-05-01 18:30 3366912 -c--a-w- c:\windows\system32\GPhotos.scr
2009-04-18 12:24 . 2004-08-09 13:32 87944 -c--a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-10 18:17 . 2009-04-10 18:17 34062 -c----w- c:\documents and settings\Administrator\Application Data\Move Networks\ie_bin\Uninst.exe
2009-04-10 18:17 . 2009-04-10 18:17 1047072 -c----w- c:\documents and settings\Administrator\Application Data\Move Networks\MoveMediaPlayer_071303000006.exe
2008-07-17 23:42 . 2008-07-17 23:42 1400048 -csh--w- c:\windows\system32\eqcsnnlh.tmp
2006-05-03 10:06 . 2009-06-09 11:29 163328 -csh--r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-06-09 11:29 31232 -csh--r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-06-09 11:29 216064 -csh--r- c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 22:20 279944 -c--a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-03-11 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-03-11 114688]
"DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 69632]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WMP110"="c:\program files\Linksys\WMP110\WMP110.exe" [2008-05-26 991232]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-10 180269]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-19 68592]
"SGPUpdater"="c:\program files\Search Guard PlusU\sgpUpdaters.exe" [2009-05-15 67456]
"FBSearch"="c:\program files\Search Guard Plus\SearchGuardPlus.exe" [2009-05-04 194432]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WPN311 Smart Wizard.lnk - c:\program files\NETGEAR\WPN311\wlancfg5.exe [2006-12-4 1503232]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.4.3-to-3.0.2-enUS-Win-Final-downloader.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Administrator\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/17/2009 7:11 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/17/2009 7:11 AM 20560]
R2 GTWPSService;GTWPSSRV;c:\program files\Linksys\WMP110\gtwpssrv.exe [1/25/2009 1:53 PM 34816]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/26/2007 2:43 AM 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R2 WLSng Service;WLSng Service;c:\program files\Linksys\WMP110\WLSngS.exe [1/25/2009 1:53 PM 233472]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [1/25/2009 1:53 PM 57344]
R3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Wireless Driver;c:\windows\system32\drivers\WMP110v2.sys [1/25/2009 1:53 PM 625024]
S3 getPlus® Installer;getPlus® Installer;c:\program files\NOS\bin\getPlus_HelperSvc.exe [5/9/2009 8:21 PM 59552]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Linksys\WMP110\jswpsapi.exe [1/25/2009 1:53 PM 352338]
S3 Linker2K;LeapPort/MS2002 Driver;c:\windows\system32\drivers\Linker2K.sys [4/7/2009 8:04 PM 23040]
.
Contents of the 'Scheduled Tasks' folder

2009-06-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-06-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]

2009-06-30 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 03:18]
.
- - - - ORPHANS REMOVED - - - -

BHO-{ad475d4b-d215-4ac1-9b83-03ba3a741d1e} - c:\windows\system32\vajgsu.dll
BHO-{F4ED6FC6-A6A2-4137-A878-1FEAB18E4B62} - c:\windows\system32\cbXQhIBQ.dll
HKLM-Run-srmclean - c:\cpqs\Scom\srmclean.exe
HKLM-Run-NapsterShell - c:\program files\Napster\napster.exe
HKLM-Run-Gamevance - c:\program files\Gamevance\gamevance32.exe
HKLM-Run-removecpl - RemoveCpl.exe
Notify-19aa3be1577 - c:\windows\System32\eappcfg32.dll
Notify-__c0097304 - c:\windows\system32\__c0097304.dat
Notify-cbXOGWpq - cbXOGWpq.dll
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.tattoodle.com?tid={05224636-BD79-4dff-998A-71E18D958B67}&v=12
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {26E6B759-DEEB-42A1-A21C-78CD29098411} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fitness-dash/FitnessDashWeb.1.0.0.11.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-29 23:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SGPUpdater = c:\program files\Search Guard PlusU\sgpUpdaters.exe??o?????????????????????????????????????????????
FBSearch = c:\program files\Search Guard Plus\SearchGuardPlus.exe?????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2874041570-2260895379-146704702-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,40,0e,0d,b4,f0,24,30,42,af,71,89,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,40,0e,0d,b4,f0,24,30,42,af,71,89,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,40,0e,0d,b4,f0,24,30,42,af,71,89,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(652)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3464)
c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\acs.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\UStorSrv.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-06-30 0:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-30 05:04

Pre-Run: 23,174,283,264 bytes free
Post-Run: 24,948,629,504 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

295 --- E O F --- 2009-06-30 05:04
:thumbup2:

#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:30 AM

Posted 30 June 2009 - 09:05 AM

Hello.

Please download and run malwarebytes.

Then afterwards, please take a new DDS run for me and post back with both DDS.txt and Attach.txt

Download and run MalwareBytes Anti-Malware
If you already have MBAM installed, simply update and run a quick scan.

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

You can refer to this page which has a visual of the instructions above.


With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 mozley411

mozley411
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:05:30 AM

Posted 30 June 2009 - 11:09 AM

:thumbup2:

Thanks so much!

Here is the log:

Malwarebytes' Anti-Malware 1.38
Database version: 2355
Windows 5.1.2600 Service Pack 3

6/30/2009 11:00:52 AM
mbam-log-2009-06-30 (11-00-52).txt

Scan type: Quick Scan
Objects scanned: 91843
Time elapsed: 7 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 4
Files Infected: 23

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{014c4232-6904-47b9-9144-7e0fb7277444} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0ab02d6c-f605-425f-b7cb-b9e96c9faf1e} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{32864a05-9d09-472c-abd0-081818ec713b} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\HDQuality (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDQuality (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Gamevance (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\documents and settings\Administrator\Start Menu\Programs\HDQuality (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Program Files\HDQuality (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32 (Worm.Archive) -> Quarantined and deleted successfully.

Files Infected:
c:\program files\gamevance\ars.cfg (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\gamevance\gvtl.dll (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\gamevance\icon.ico (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\start menu\Programs\hdquality\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\program files\hdquality\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\105.music.mp3 (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\109.crack.zip (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\109.crack.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\110.keygen.zip (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\110.keygen.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\111.serial.zip (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\111.serial.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\112.setup.zip (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\112.setup.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\113.music.mp3 (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\113.music.mp3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\114.music.snd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\114.music.snd.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\115.music.au (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\115.music.au.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\116.video.wmv (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\networkservice32\116.video.wmv.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

#8 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:30 AM

Posted 30 June 2009 - 11:10 AM

Please post the DDS log as well.

Then afterwards, please take a new DDS run for me and post back with both DDS.txt and Attach.txt


Thanks. :thumbup2:

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#9 mozley411

mozley411
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:05:30 AM

Posted 01 July 2009 - 09:17 PM

:thumbup2:
DDS File:

DDS (Ver_09-06-26.01) - NTFSx86
Run by Administrator at 21:10:39.76 on Wed 07/01/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.382 [GMT -5:00]

AV: avast! antivirus 4.8.1335 [VPS 090701-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Linksys\WMP110\gtwpssrv.exe
C:\WINDOWS\system32\lxducoms.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys\WMP110\WLSngS.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Linksys\WMP110\WMP110.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lexmark 5600-6600 Series\lxduMsdMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.tattoodle.com?tid={05224636-BD79-4dff-998A-71E18D958B67}&v=12
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AOL Toolbar Loader: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol toolbar\aoltb.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: {ad475d4b-d215-4ac1-9b83-03ba3a741d1e} - No File
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - c:\program files\lexmark printable web\bho.dll
BHO: {F4ED6FC6-A6A2-4137-A878-1FEAB18E4B62} - No File
BHO: Fast Browser Search Toolbar Helper: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\fast browser search\ie\FBStoolbar.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol toolbar\aoltb.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [DrvLsnr] c:\program files\analog devices\soundmax\DrvLsnr.exe
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [WMP110] c:\program files\linksys\wmp110\WMP110.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [SGPUpdater] c:\program files\search guard plusu\sgpUpdaters.exe
mRun: [FBSearch] c:\program files\search guard plus\SearchGuardPlus.exe
mRun: [lxdumon.exe] "c:\program files\lexmark 5600-6600 series\lxdumon.exe"
mRun: [lxduamon] "c:\program files\lexmark 5600-6600 series\lxduamon.exe"
mRun: [Lexmark 5600-6600 Series Fax Server] "c:\program files\lexmark 5600-6600 series\fm3032.exe" /s
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn311\wlancfg5.exe
IE: &AOL Toolbar Search - c:\documents and settings\all users\application data\aol\ietoolbar\resources\en-us\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://aol.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {26E6B759-DEEB-42A1-A21C-78CD29098411} - hxxp://aolsvc.aol.com/onlinegames/free-trial-fitness-dash/FitnessDashWeb.1.0.0.11.cab
DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} - hxxp://www.worldwinner.com/games/v45/moneylist/moneylist.cab
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager/plugin/IEGetPlugin.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} - hxxp://www.worldwinner.com/games/v63/bjattack/bja.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab
DPF: {64CD313F-F079-4D93-959F-4D28B5519449} - hxxp://www.worldwinner.com/games/v50/jeopardy/jeopardy.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215296670125
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} - hxxp://www.worldwinner.com/games/v49/luxor/luxor.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} - hxxp://www.worldwinner.com/games/v46/monopoly/monopoly.cab
DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} - hxxp://aolsvc.aol.com/onlinegames/free-trial-zenerchi/ZenerchiWeb.1.0.0.10.cab
DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} - hxxp://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab
DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} - hxxp://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-17 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-17 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-17 138680]
R2 GTWPSService;GTWPSSRV;c:\program files\linksys\wmp110\gtwpssrv.exe [2009-1-25 34816]
R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-26 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R2 WLSng Service;WLSng Service;c:\program files\linksys\wmp110\WLSngS.exe [2009-1-25 233472]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-17 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-17 352920]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-1-25 57344]
R3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Wireless Driver;c:\windows\system32\drivers\WMP110v2.sys [2009-1-25 625024]
S2 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxduserv.exe [2009-6-30 98984]
S3 getPlus® Installer;getPlus® Installer;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-5-9 59552]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\linksys\wmp110\jswpsapi.exe [2009-1-25 352338]
S3 Linker2K;LeapPort/MS2002 Driver;c:\windows\system32\drivers\Linker2K.sys [2009-4-7 23040]

=============== Created Last 30 ================

2009-07-01 00:04 <DIR> -cd----- c:\windows\ie8updates
2009-06-30 17:16 <DIR> -cd----- c:\docume~1\admini~1\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-06-30 12:31 <DIR> -cd----- c:\docume~1\admini~1\applic~1\Lexmark Productivity Studio
2009-06-30 12:29 <DIR> -cd----- c:\docume~1\admini~1\applic~1\5600-6600 Series
2009-06-30 12:25 <DIR> -cd----- c:\documents and settings\all users\Lx_cats
2009-06-30 12:11 40,960 ac------ c:\windows\system32\lxduvs.dll
2009-06-30 12:10 360,448 ac------ c:\windows\system32\lxducoin.dll
2009-06-30 12:10 61,218 ac------ c:\windows\system32\lxduprpr.chm
2009-06-30 12:10 87,040 ac------ c:\windows\system32\wiafbdrv.dll
2009-06-30 12:10 87,040 ac------ c:\windows\system32\dllcache\wiafbdrv.dll
2009-06-30 12:09 1,036,288 ac------ c:\windows\system32\lxdudrs.dll
2009-06-30 12:09 81,920 ac------ c:\windows\system32\lxducaps.dll
2009-06-30 12:09 69,632 ac------ c:\windows\system32\lxducnv4.dll
2009-06-30 12:09 45,056 ac------ c:\windows\system32\LXDUPMON.DLL
2009-06-30 12:09 32,768 ac------ c:\windows\system32\LXDUFXPU.DLL
2009-06-30 12:08 339,968 ac------ c:\windows\system32\IMGMAN32.DLL
2009-06-30 12:08 98,345 ac------ c:\windows\system32\IMHOST32.DLL
2009-06-30 12:08 98,304 ac------ c:\windows\system32\IM31XPNG.DEL
2009-06-30 12:08 86,016 ac------ c:\windows\system32\lxduoem.dll
2009-06-30 12:08 69,632 ac------ c:\windows\system32\IM31XTIF.DEL
2009-06-30 12:08 49,152 ac------ c:\windows\system32\IM31IMG.DIL
2009-06-30 12:08 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\5600-6600 Series
2009-06-30 12:08 <DIR> -cd----- c:\program files\Abbyy FineReader 6.0 Sprint
2009-06-30 12:07 <DIR> -cd----- c:\program files\Lexmark Tools for Office
2009-06-30 12:06 <DIR> -cd----- c:\program files\Lexmark Toolbar
2009-06-30 12:06 <DIR> -cd----- c:\program files\Lexmark Printable Web
2009-06-30 12:06 44 ac------ c:\windows\system32\lxdurwrd.ini
2009-06-30 12:06 352,256 ac------ c:\windows\system32\LXDUwupd.dll
2009-06-30 12:06 17,064 ac------ c:\windows\system32\LXDUwupd.exe
2009-06-30 12:04 164,316 ac------ c:\windows\system32\LexFiles.ulf
2009-06-30 12:04 <DIR> -cd----- c:\program files\Lexmark 5600-6600 Series
2009-06-30 10:51 <DIR> -cd----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-06-30 10:50 38,160 ac------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-30 10:50 19,096 ac------ c:\windows\system32\drivers\mbam.sys
2009-06-30 01:22 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-06-30 01:22 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-06-30 01:22 1,985,024 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-06-30 01:22 11,064,832 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-06-30 00:02 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-06-29 23:34 <DIR> acdshr-- C:\cmdcons
2009-06-29 23:29 161,792 ac------ c:\windows\SWREG.exe
2009-06-29 23:29 155,136 ac------ c:\windows\PEV.exe
2009-06-29 23:29 98,816 ac------ c:\windows\sed.exe
2009-06-24 16:35 <DIR> -cd----- C:\backup
2009-06-24 16:29 <DIR> -cd----- c:\windows\system32\NtmsData
2009-06-20 22:54 <DIR> -cd----- c:\program files\Malwarebytes' Anti-Malware
2009-06-20 22:54 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-19 01:11 <DIR> -cd----- c:\program files\Search Guard PlusU
2009-06-19 01:11 <DIR> -cd----- c:\program files\Search Guard Plus
2009-06-19 01:11 <DIR> -cd----- c:\program files\SGPSA
2009-06-19 01:11 <DIR> -cd----- c:\program files\Fast Browser Search
2009-06-17 06:59 <DIR> -cdsh--- c:\documents and settings\administrator\IECompatCache
2009-06-17 06:55 <DIR> -cdsh--- c:\documents and settings\administrator\PrivacIE
2009-06-17 06:52 <DIR> -cdsh--- c:\documents and settings\administrator\IETldCache
2009-06-17 06:21 <DIR> -cd----- c:\program files\common files\Software Update Utility
2009-06-17 06:20 <DIR> -cd----- c:\program files\AOL Toolbar
2009-06-17 06:20 <DIR> -cd-h--- c:\windows\msdownld.tmp
2009-06-17 06:17 <DIR> -cd-h--- c:\windows\ie8
2009-06-16 14:44 129,784 -c------ c:\windows\system32\pxafs.dll
2009-06-16 14:44 120,056 -c------ c:\windows\system32\pxcpyi64.exe
2009-06-16 14:44 118,520 -c------ c:\windows\system32\pxinsi64.exe
2009-06-16 14:43 <DIR> -cd----- c:\program files\DivX
2009-06-16 14:43 <DIR> -cd----- c:\program files\common files\DivX Shared
2009-06-09 06:29 <DIR> -cd----- c:\program files\AviSynth 2.5
2009-06-09 06:28 <DIR> -cd----- c:\program files\eRightSoft
2009-06-05 11:20 <DIR> -cd----- c:\program files\AskSearch
2009-06-05 11:20 <DIR> -cd----- c:\program files\AskBarDis

==================== Find3M ====================

2009-05-26 20:21 2,828 ac-sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-05-26 20:16 88 -c-shr-- c:\docume~1\alluse~1\applic~1\DEBFC84715.sys
2009-05-13 00:15 915,456 ac------ c:\windows\system32\wininet.dll
2009-05-07 10:32 345,600 ac------ c:\windows\system32\localspl.dll
2009-05-01 16:02 90,112 ac------ c:\windows\system32\dpl100.dll
2009-05-01 16:02 823,296 ac------ c:\windows\system32\divx_xx0c.dll
2009-05-01 16:02 823,296 ac------ c:\windows\system32\divx_xx07.dll
2009-05-01 16:02 815,104 ac------ c:\windows\system32\divx_xx0a.dll
2009-05-01 16:02 811,008 ac------ c:\windows\system32\divx_xx16.dll
2009-05-01 16:02 802,816 ac------ c:\windows\system32\divx_xx11.dll
2009-05-01 16:02 685,056 ac------ c:\windows\system32\DivX.dll
2009-05-01 13:30 3,366,912 ac------ c:\windows\system32\GPhotos.scr
2009-04-18 07:24 87,944 ac------ c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-17 07:26 1,847,168 ac------ c:\windows\system32\win32k.sys
2009-04-15 09:51 585,216 ac------ c:\windows\system32\rpcrt4.dll
2006-12-04 11:57 35,232 ac------ c:\windows\inf\wpn311\ME_INST.EXE
2006-12-04 11:57 26,112 ac------ c:\windows\inf\wpn311\install.exe
2006-07-05 05:33 472,000 ac------ c:\windows\inf\wpn311\WPN311.sys
2006-05-03 05:06 163,328 -c-shr-- c:\windows\system32\flvDX.dll
2007-02-21 06:47 31,232 -c-shr-- c:\windows\system32\msfDX.dll
2008-03-16 08:30 216,064 -c-shr-- c:\windows\system32\nbDX.dll

============= FINISH: 21:11:21.10 ===============
Thank you!

Attached Files



#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:30 AM

Posted 02 July 2009 - 10:01 AM

Hello.

Let's update Java and run an online scan.

P2P Programs Warning

Your log shows that you are using so called Peer To Peer Programs or file-sharing programs (in your case LimeWire). These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

Naturally there are also legal ways to use these services, such as downloading Linux distributions or office suites such as "Open Office."

It is your decision whether or not you wish to keep your program(s) but I suggest you remove it via add/remove. However, please refrain from using them until your computer has been declared clean.


Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "Java Runtime Environment (JRE)" JRE 6 Update 14.
  • Click the Download button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version.
-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer.

Run Scan with Kaspersky
Please do a scan with Kaspersky Online Scanner.

If you are using Windows Vista, open your browser by right-clicking on its icon and select Run as administrator to perform this scan.

  • Please disable your realtime protection software before proceeding. Refer to this page if you are unsure how.
  • Open the Kaspersky Scanner page.
  • Click on Accept and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.

This scanner will only scan. It does not remove any malware it finds.


Post back with a new DDS log afterwards as well.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:30 AM

Posted 04 July 2009 - 10:50 AM

Hello.

How's everything coming along?

~EB
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#12 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:30 AM

Posted 08 July 2009 - 01:12 PM

Hello.

Due to Lack of feedback, this topic is now Closed

If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic in the Hijackthis-Malware Removal forum.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users