Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possible Google Redirect virus


  • This topic is locked This topic is locked
3 replies to this topic

#1 scollett

scollett

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 23 January 2010 - 08:15 PM

Hello!

I'm posting here as a last resort since I'm generally able rid computers of viruses, etc. However, this particular infection is being very stubborn. After running MalwareBytes, Spydoctor, Trend PCillin virus scan, and Housecall, the computer is still having problems.

The main symptom I see are redirects when I click on links after doing a search in Google. Now, the information I've read about the Google redirect virus says that it redirects you to 'malicious' sites. This doesn't appear to be the case with my computer. It redirects frequently to other search engines, but sometimes it redirects to legit sites like IGN.com, etc.

The last Spyware doctor scan seemed to fix it, until I rebooted. Then the issue came back. That's when I decided to run combofix and try and petition for help from others who must know more than I do! LOL

Also, I cannot seem to boot into Safe Mode. I get a BSOD and page fault error when I try. I've also tried to fix this, but to no avail.


Thank you for any help you can provide. I promise if y'all can assist me, I'll hang around here and assist others in any way I can in the future! smile.gif

So, here's the log from DDS:

CODE
DDS (Ver_09-12-01.01) - NTFSx86  
Run by Momma at 19:15:24.04 on Sat 01/23/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3326.2584 [GMT -5:00]

AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)   {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: Trend Micro PC-cillin Internet Security *On-access scanning disabled* (Outdated)   {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro PC-cillin Internet Security (Firewall) *disabled*   {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Dell P713w\dlecmon.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWS\system32\dleccoms.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Momma\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = local;*.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Dell Toolbar: {09b71986-2ac5-482d-b6cb-42ea34f4f85b} - c:\program files\dell toolbar\toolband.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - Yahoo! IE Services Button
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: WsftpBrowserHelper Class: {601ed020-fb6c-11d3-87d8-0050da59922b} - c:\program files\ipswitch\ws_ftp pro\wsbho2k0.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: {ca6319c0-31b7-401e-a518-a07c3db8f777} - CBrowserHelperObject Object
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Ziptionary BHO: {f9ff8423-50f2-4f80-a31d-d1a03dbe9d86} - c:\program files\ziptionary\ziptionary.dll
TB: Dell Toolbar: {09b71986-2ac5-482d-b6cb-42ea34f4f85b} - c:\program files\dell toolbar\toolband.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Ziptionary Band Panel: {2579475b-a3d7-43ad-b95a-b88830e15e29} - c:\program files\ziptionary\ziptionary.dll
uRun: [OE_OEM] "c:\program files\trend micro\internet security 12\tmas_oe\TMAS_OEMon.exe"
uRun: [igndlm.exe] c:\program files\ign\download manager\DLM.exe /windowsstart /startifwork
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe"  -osboot
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [dlecmon.exe] "c:\program files\dell p713w\dlecmon.exe"
mRun: [EzPrint] "c:\program files\dell p713w\ezprint.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229403040671
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195835766531
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5249/mcfscan.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\momma\applic~1\mozilla\firefox\profiles\emb85241.default\
FF - prefs.js: browser.startup.homepage - hxxp://excite.com/
FF - component: c:\documents and settings\momma\application data\mozilla\firefox\profiles\emb85241.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
FF - component: c:\documents and settings\momma\application data\mozilla\firefox\profiles\emb85241.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\momma\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\ign\download manager\npfpdlm.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-1-23 207792]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-1-23 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-1-23 59664]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2010-1-23 233136]
R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2009-11-19 58984]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2009-11-19 334568]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-4 55024]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-1-23 112592]
R2 dlec_device;dlec_device;c:\windows\system32\dleccoms.exe -service --> c:\windows\system32\dleccoms.exe -service [?]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-1-16 236368]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2009-11-19 967912]
R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\tmxpflt.sys [2005-8-30 205328]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2005-8-30 36368]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-1-16 19160]
S2 dlecCATSCustConnectService;dlecCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dlecserv.exe [2009-7-1 98984]
S2 gupdate1c9c3882cbf3c8e;Google Update Service (gupdate1c9c3882cbf3c8e);c:\program files\google\update\GoogleUpdate.exe [2009-4-22 133104]
S2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2005-8-30 290889]
S2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2005-8-30 585792]
S2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2005-8-30 262215]
S3 JL2005;JL2005A Toy Camera;c:\windows\system32\drivers\toywdm.sys --> c:\windows\system32\drivers\toywdm.sys [?]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2010-1-23 70408]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-4 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-1-23 359624]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-1-23 1141712]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-1-23 33552]
S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]

=============== Created Last 30 ================

2010-01-23 23:24:08    0    d-sha-r-    C:\cmdcons
2010-01-23 23:22:47    98816    ----a-w-    c:\windows\sed.exe
2010-01-23 23:22:47    77312    ----a-w-    c:\windows\MBR.exe
2010-01-23 23:22:47    261632    ----a-w-    c:\windows\PEV.exe
2010-01-23 23:22:47    161792    ----a-w-    c:\windows\SWREG.exe
2010-01-23 17:15:09    59664    --s---w-    c:\windows\system32\drivers\TfSysMon.sys
2010-01-23 17:15:09    51984    --s---w-    c:\windows\system32\drivers\TfFsMon.sys
2010-01-23 17:15:09    33552    --s---w-    c:\windows\system32\drivers\TfNetMon.sys
2010-01-23 16:30:22    882    ----a-w-    c:\windows\RegSDImport.xml
2010-01-23 16:30:22    880    ----a-w-    c:\windows\RegISSImport.xml
2010-01-23 16:30:22    767952    ----a-w-    c:\windows\BDTSupport.dll
2010-01-23 16:30:22    149456    ----a-w-    c:\windows\SGDetectionTool.dll
2010-01-23 16:30:22    131    ----a-w-    c:\windows\IDB.zip
2010-01-23 16:30:21    1152444    ----a-w-    c:\windows\UDB.zip
2010-01-23 16:30:20    165840    ----a-w-    c:\windows\PCTBDRes.dll
2010-01-23 16:30:20    1640400    ----a-w-    c:\windows\PCTBDCore.dll
2010-01-23 16:28:25    7387    ----a-w-    c:\windows\system32\drivers\pctgntdi.cat
2010-01-23 16:28:25    233136    ----a-w-    c:\windows\system32\drivers\pctgntdi.sys
2010-01-23 16:28:02    87784    ----a-w-    c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-23 16:28:02    7412    ----a-w-    c:\windows\system32\drivers\PCTAppEvent.cat
2010-01-23 16:28:02    7383    ----a-w-    c:\windows\system32\drivers\pctcore.cat
2010-01-23 16:28:02    207792    ----a-w-    c:\windows\system32\drivers\PCTCore.sys
2010-01-23 16:27:55    7383    ----a-w-    c:\windows\system32\drivers\pctplsg.cat
2010-01-23 16:27:55    70408    ----a-w-    c:\windows\system32\drivers\pctplsg.sys
2010-01-23 16:27:47    0    d-----w-    c:\program files\Spyware Doctor
2010-01-23 16:27:47    0    d-----w-    c:\program files\common files\PC Tools
2010-01-23 16:27:47    0    d-----w-    c:\docume~1\momma\applic~1\PC Tools
2010-01-23 16:27:47    0    d-----w-    c:\docume~1\alluse~1\applic~1\PC Tools
2010-01-22 02:18:52    0    d-----w-    c:\program files\BitTorrent
2010-01-21 21:14:22    0    d-----w-    c:\windows\system32\wbem\Repository
2010-01-21 21:14:01    0    d-----w-    c:\program files\Mahjongg Towers
2010-01-03 12:02:26    1409    ----a-w-    c:\windows\system32\tmpAEB4C.FOT
2010-01-03 12:02:26    1409    ----a-w-    c:\windows\system32\tmp82C4C.FOT
2010-01-03 12:02:26    1409    ----a-w-    c:\windows\system32\tmp76C4C.FOT
2010-01-03 12:02:26    1409    ----a-w-    c:\windows\system32\tmp69C4C.FOT
2010-01-03 12:01:26    720896    ----a-w-    c:\windows\iun6002.exe
2009-12-28 18:25:22    0    d-----w-    c:\docume~1\momma\applic~1\FileSubmit
2009-12-28 18:25:08    0    d-----w-    c:\program files\fantasticwinter
2009-12-28 18:25:07    0    d-----w-    c:\program files\LE Designs
2009-12-28 18:25:06    0    d-----w-    c:\program files\Ghost Beach
2009-12-28 18:25:06    0    d-----w-    c:\program files\fireofjoy
2009-12-28 18:24:47    0    d-----w-    c:\program files\snowballetttransp
2009-12-28 18:24:43    0    d-----w-    c:\program files\Irene's Images
2009-12-28 18:02:33    0    d-----w-    c:\program files\RelevantKnowledge(2)
2009-12-28 17:59:36    399    ----a-w-    c:\windows\is-UF0F8.lst
2009-12-28 17:59:36    10498    ----a-w-    c:\windows\is-UF0F8.msg
2009-12-28 17:15:25    0    d-----w-    c:\program files\Logitech(2)
2009-12-28 16:11:20    0    d-----w-    c:\program files\Zwangie
2009-12-28 16:02:02    9265120    ----a-w-    c:\windows\snowballetttransp.scr
2009-12-27 14:29:29    54    ----a-w-    c:\windows\CmdFile.INI
2009-12-26 23:44:25    0    d-----w-    c:\documents and settings\all users\Dl_cats
2009-12-26 23:43:42    0    d-----w-    c:\program files\Abbyy FineReader 6.0 Sprint
2009-12-26 23:43:27    372736    ----a-w-    c:\windows\system32\DLECwupd.dll
2009-12-26 23:43:27    213672    ----a-w-    c:\windows\system32\DLECwupd.exe
2009-12-26 23:42:35    0    d-----w-    c:\program files\Dell Toolbar
2009-12-26 23:42:30    0    d-----w-    c:\program files\Dell PC Fax
2009-12-26 23:42:27    0    d-----w-    c:\program files\Dell Printable Web
2009-12-26 23:42:20    7680    ----a-w-    c:\windows\system32\NativeCall.dll
2009-12-26 23:42:18    385024    ----a-w-    c:\windows\system32\DLECinst.dll
2009-12-26 23:42:16    376832    ----a-w-    c:\windows\system32\dleccomm.dll
2009-12-26 23:40:51    154420    ----a-w-    c:\windows\system32\LexFiles.ulf
2009-12-26 23:40:29    299008    ----a-r-    c:\windows\system32\dlecsm.dll
2009-12-26 23:40:29    28672    ----a-r-    c:\windows\system32\dlecsmr.dll
2009-12-26 23:40:19    0    d-----w-    c:\program files\Dell P713w
2009-12-26 23:40:17    65106    ----a-r-    c:\windows\system32\dlecprpr.chm
2009-12-26 23:40:17    442368    ----a-r-    c:\windows\system32\dlechcp.dll
2009-12-26 23:40:16    8696    ----a-r-    c:\windows\system32\dleccommuilogo_rtl.bmp
2009-12-26 23:40:16    8696    ----a-r-    c:\windows\system32\dleccommuilogo.bmp
2009-12-26 23:40:15    425984    ----a-r-    c:\windows\system32\dleccoin.dll
2009-12-26 23:40:14    86118    ----a-r-    c:\windows\system32\dleccfg.dll
2009-12-26 23:40:14    2000    ----a-r-    c:\windows\system32\dlec.loc

==================== Find3M  ====================

2010-01-07 21:07:14    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04    19160    ----a-w-    c:\windows\system32\drivers\mbam.sys
2009-12-31 15:33:06    70656    ------w-    c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06    13824    ------w-    c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43    634648    ------w-    c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09    161792    ------w-    c:\windows\system32\dllcache\ieakui.dll
2009-12-10 04:06:49    0    ----a-w-    c:\windows\system32\drivers\lvuvc.hs
2009-12-10 04:06:43    0    ----a-w-    c:\windows\system32\drivers\logiflt.iad
2009-11-28 03:42:52    40064    ---ha-w-    c:\windows\system32\mlfcache.dat
2009-11-21 15:51:04    471552    ----a-w-    c:\windows\system32\dllcache\aclayers.dll
2008-07-29 20:52:47    774144    -c--a-w-    c:\program files\RngInterstitial.dll
2008-03-12 22:40:37    321153    ----a-w-    c:\program files\Yahoo!.zip
2002-08-01 00:55:12    108    -csh--w-    c:\windows\WSYS049.SYS
2007-02-17 21:45:51    1682    --sha-w-    c:\windows\system32\KGyGaAvL.sys
2008-12-16 22:02:39    32768    --sha-w-    c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121620081217\index.dat

============= FINISH: 19:15:39.89 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 29 January 2010 - 07:16 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

Do you still require help?

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 01 February 2010 - 12:43 PM

Hello.

Are you still there? Do you still require help?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:15 AM

Posted 03 February 2010 - 03:44 PM

Hello.

Due to Lack of feedback, this topic is now Closed

If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users