Hi Elise,
Thank you for helping me.
The problem I am having is I belive caused by HijackWindowsUpdate. Malware bytes finds it, deletes it and then its just there again. I have run so many different types of spyware/malware detectors to try and rid myself of the thing. When I open Firefox and click on a link I just keep getting redirected to some random site or a 404 error page, adpage etc. Its driving me mad.
I have followed your instructions exactly but the DDR.scr opens up with a command box then closes almost instantly and does no more. I have disabled scripts in my browser, is there something else i have to do to get it to run the report scan. In the meantime I have run the gmer file and the log is pasted below. It took nearly 5.1/2 hours to run the report.
Please let me know what you would like me to do next.
Kind Regards
Mick
GMER 1.0.15.15163 -
http://www.gmer.netRootkit scan 2009-11-04 14:15:53
Windows 5.1.2600 Service Pack 3
Running: ttporqfq.exe; Driver: C:\DOCUME~1\Mick\LOCALS~1\Temp\pxtdipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service system32\drivers\ovfsthacjxfudjnjppmbnbrylyuswmfvwgefgg.sys (*** hidden *** ) [SYSTEM] ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@imagepath \systemroot\system32\drivers\ovfsthacjxfudjnjppmbnbrylyuswmfvwgefgg.sys
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@inst 0
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@ver icv310309
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@cid 01
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@bid 4034634894-1576462213-3136207814-3958095517
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@aid 303350
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@sid 4
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@feed 0x22 0x64 0x78 0x36 ...
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@cmddelay 14401
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff@extension \\?\C:\Program Files\Mozilla Firefox\extensions\{0769B548-3E5B-40B4-A1CE-6869A73EF5C5}
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff@version 1
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@iexplore.exe ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@explorer.exe ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@winlogon.exe senekaadwrem.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.dll \systemroot\system32\ovfsthxolduepdwkmothwbnshpxypxivikwwux.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.sys \systemroot\system32\drivers\ovfsthacjxfudjnjppmbnbrylyuswmfvwgefgg.sys
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthlog.dat \systemroot\system32\ovfsthimfpocugxymepraswymmntrfvkvkosrr.dat
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthwi.dll \systemroot\system32\ovfsthtslngwxivpbuiqisyaqhtipqpwjpbipr.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthff.dll \systemroot\system32\ovfsthvlbjkeqqfswgvasqaumoyyydvpqfxajm.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.dat \systemroot\system32\ovfsthpjeestywvkahvtpmwrsypytojgwcxsbw.dat
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthmal.db \systemroot\system32\ovfsthimifstfkekemfnuycrrcemgkrghxctgd.db
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthadwrem.dll \systemroot\system32\ovfsthehrxmidighfxriobphijnddolqnoqedo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@imagepath \systemroot\system32\drivers\ovfsthacjxfudjnjppmbnbrylyuswmfvwgefgg.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@inst 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@ver icv310309
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@cid 01
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@bid 4034634894-1576462213-3136207814-3958095517
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@aid 303350
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@sid 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@feed 0x22 0x64 0x78 0x36 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@cmddelay 14401
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff@extension \\?\C:\Program Files\Mozilla Firefox\extensions\{0769B548-3E5B-40B4-A1CE-6869A73EF5C5}
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff@version 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@iexplore.exe ovfsthwi.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@explorer.exe ovfsthff.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@winlogon.exe senekaadwrem.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.dll \systemroot\system32\ovfsthxolduepdwkmothwbnshpxypxivikwwux.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.sys \systemroot\system32\drivers\ovfsthacjxfudjnjppmbnbrylyuswmfvwgefgg.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthlog.dat \systemroot\system32\ovfsthimfpocugxymepraswymmntrfvkvkosrr.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthwi.dll \systemroot\system32\ovfsthtslngwxivpbuiqisyaqhtipqpwjpbipr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthff.dll \systemroot\system32\ovfsthvlbjkeqqfswgvasqaumoyyydvpqfxajm.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.dat \systemroot\system32\ovfsthpjeestywvkahvtpmwrsypytojgwcxsbw.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthmal.db \systemroot\system32\ovfsthimifstfkekemfnuycrrcemgkrghxctgd.db
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthadwrem.dll \systemroot\system32\ovfsthehrxmidighfxriobphijnddolqnoqedo.dll
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 2
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 7
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 4
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 4
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 4
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType 7
Reg HKLM\SYSTEM\controlset003\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics 256
Reg HKLM\SYSTEM\controlset003\Services\MRxDAV\EncryptedDirectories@
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@start 1
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@type 1
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@group file system
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@imagepath \systemroot\system32\drivers\ovfsthacjxfudjnjppmbnbrylyuswmfvwgefgg.sys
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby@inst 0
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@ver icv310309
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@cid 01
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@bid 4034634894-1576462213-3136207814-3958095517
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@aid 303350
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@sid 4
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@feed 0x22 0x64 0x78 0x36 ...
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main@cmddelay 14401
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\delete
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff@extension \\?\C:\Program Files\Mozilla Firefox\extensions\{0769B548-3E5B-40B4-A1CE-6869A73EF5C5}
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\ff@version 1
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@iexplore.exe ovfsthwi.dll
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@explorer.exe ovfsthff.dll
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\injector@winlogon.exe senekaadwrem.dll
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\main\tasks
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.dll \systemroot\system32\ovfsthxolduepdwkmothwbnshpxypxivikwwux.dll
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.sys \systemroot\system32\drivers\ovfsthacjxfudjnjppmbnbrylyuswmfvwgefgg.sys
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthlog.dat \systemroot\system32\ovfsthimfpocugxymepraswymmntrfvkvkosrr.dat
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthwi.dll \systemroot\system32\ovfsthtslngwxivpbuiqisyaqhtipqpwjpbipr.dll
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthff.dll \systemroot\system32\ovfsthvlbjkeqqfswgvasqaumoyyydvpqfxajm.dll
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsth.dat \systemroot\system32\ovfsthpjeestywvkahvtpmwrsypytojgwcxsbw.dat
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthmal.db \systemroot\system32\ovfsthimifstfkekemfnuycrrcemgkrghxctgd.db
Reg HKLM\SYSTEM\controlset003\Services\ovfsthloewbnyllyfucrmtnbsbrrnaeleyxdby\modules@ovfsthadwrem.dll \systemroot\system32\ovfsthehrxmidighfxriobphijnddolqnoqedo.dll
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\Temp\c71210e6-a0b3-457c-a319-6b0533a686a9.tmp (size mismatch) 500139/0 bytes executable
---- EOF - GMER 1.0.15 ----