Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Had XP Smart Security 2010, browser still hijacked


  • This topic is locked This topic is locked
39 replies to this topic

#1 kingship

kingship

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 04 April 2010 - 05:33 PM

Hi, my logs are below. I wasn't able to run malwarebytes or hijackthis but I am able to run it now. I suspect I still have some problems but I'm not sure.

Please help me to see if I'm clean or if there are still issues here. By the way, I had to break up the GMER file into two parts since it was too large to upload at once.

Thanks a lot.

Update - Here are the trojans/viruses that I've found using Avast (Win32:Malware-gen) (Win32:Rootkit-gen[Rtk]) (Win32:Rootkit-gen[Rtk]) (win32:MalOb-AL[Cryp])


DDS (Ver_10-03-17.01) - NTFSx86
Run by Admin at 15:05:33.20 on Sun 04/04/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1527.917 [GMT -7:00]


============== Running Processes ===============

C:\windows\system32\svchost -k DcomLaunch
svchost.exe
C:\windows\System32\svchost.exe -k netsvcs
svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\BLOCKB~1\BLOCKB~1\MovielinkCore.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\windows\Explorer.EXE
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Blockbuster\BLOCKBUSTERMovielink\Movielink User.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dlbxcoms.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Admin\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: UberButton Class: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: YahooTaggedBM Class: {65d886a2-7ca7-479b-bb95-14d1efb7946a} - c:\program files\yahoo!\common\YIeTagBm.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [GoToMeeting] "c:\program files\citrix\gotomeeting\452\g2mstart.exe" "/Trigger RunAtLogon"
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [DLBXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLBXtime.dll,_RunDLLEntry@16
mRun: [YOP] c:\progra~1\yahoo!\yop\yop.exe /autostart
mRun: [YBrowser] c:\progra~1\yahoo!\browser\ybrwicon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IPInSightMonitor 01] "c:\program files\sbc yahoo!\connection manager\ip insight\IPMon32.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [dlbxmon.exe] "c:\program files\dell photo aio printer 962\dlbxmon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [eFax 4.3] "c:\program files\efax messenger 4.3\J2GDllCmd.exe" /R
mRun: [LoadMSvcmm] "c:\program files\blockbuster\blockbustermovielink\Movielink User.exe"
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
Trusted Zone: efax.com\www
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} - hxxps://support.microsoft.com/OAS/ActiveX/odc.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper200711281.dll
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1122014265156
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - hxxp://download.yahoo.com/dl/installs/ymail/ymmapi.dll
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - hxxp://www.photodex.com/pxplay.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\fasamifo.dll c:\windows\system32\mizukobe.dll yaruzesa.dll c:\windows\system32\bizoyuza.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: InternetProvider - {DEB51D06-A878-41DA-A75D-9A4AEED992A7} - No File
SSODL: domisasez - {4f60267c-e8a4-4361-b604-c37519f21aa4} - No File
SSODL: jasogezoj - {21a3e339-227f-4776-a391-374f198f6c32} - No File
STS: {4f60267c-e8a4-4361-b604-c37519f21aa4} - No File
STS: {21a3e339-227f-4776-a391-374f198f6c32} - No File
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli pureleye.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\wlqgx11x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/search?hl=en&q=yahoo.com&btnG=Google+Search
FF - component: c:\documents and settings\admin\application data\mozilla\firefox\profiles\wlqgx11x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\mozilla firefox\components\baecdadccbbf.dll
FF - plugin: c:\documents and settings\admin\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\admin\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\admin\application data\mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\admin\local settings\application data\yahoo!\browserplus\2.4.17\plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\documents and settings\admin\local settings\application data\yahoo!\browserplus\2.6.0\plugins\npybrowserplus_2.6.0.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npitunes.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npybrowserplus_2.4.17.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 bcbf;bcbf;c:\windows\system32\bcbf.sys [2010-2-13 73728]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R2 MSSEARCH;Microsoft Search;c:\program files\common files\system\mssearch\bin\mssearch.exe [2005-8-6 73728]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]
S0 f4d89a7139532f9e8b3a30c819c65a48;f4d89a7139532f9e8b3a30c819c65a48;c:\windows\system32\f4d89a7139532f9e8b3a30c819c65a48.sys [2009-1-22 39936]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\ICDUSB2.sys [2002-11-28 39048]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]

=============== Created Last 30 ================

2010-04-04 00:40:27 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-04-04 00:40:21 0 d-----w- c:\program files\SUPERAntiSpyware
2010-04-04 00:40:21 0 d-----w- c:\docume~1\admin\applic~1\SUPERAntiSpyware.com
2010-04-04 00:07:15 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-04-03 03:15:32 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-03-06 03:14:02 0 d-sh--w- c:\documents and settings\admin\PrivacIE

==================== Find3M ====================

2010-02-13 14:32:54 73728 ------w- c:\windows\system32\bcbf.sys
2006-01-05 04:09:27 3290299 ----a-w- c:\program files\DailyText_1_3_0_Setup.exe
2005-08-27 22:47:13 4077184 ----a-w- c:\program files\winzip90.exe

============= FINISH: 15:06:19.76 ===============

Attached Files


Edited by kingship, 04 April 2010 - 08:07 PM.


BC AdBot (Login to Remove)

 


#2 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 04 April 2010 - 05:36 PM

Edited: Removed GMER log. ~Extremeboy

Edited by extremeboy, 05 April 2010 - 06:32 PM.


#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:27 AM

Posted 05 April 2010 - 06:33 PM

Hello there,

You ran GMER with the Show All option selected causing that huge GMER report produced. ;)

Try running GMER with the following instructions and post it once done.

Download and Run GMER

We will use GMER to scan for rootkits.
  • Please download GMER from one of the following locations, and save it to your desktop:
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop. Unzip/extract the file to its own folder. (Click here for information on how to do this if not sure. Win 2000 users click here.

  • Close any and all open programs, as this process may crash your computer.
  • Double click or on your desktop.
  • When you have done this, close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Double-click on Gmer.exe to start the program. Right-click and select Run As Administrator... if you are using Vista
  • Allow the gmer.sys driver to load if asked.

    If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system... Click NO.
  • In the right panel, you will see several boxes that have been checked. Please UNCHECK the following:
    • Sections
    • Registry
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show all (Don't miss this one!)
  • Click on and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.

If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running
*Note*: Rootkit scans often produce false positives. Do NOT take any actions on "<--- ROOKIT" entries
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 06 April 2010 - 01:32 AM

Thanks a lot for helping. Here's the file.



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-05 23:31:49
Windows 5.1.2600 Service Pack 2
Running: vo7tee0h.exe; Driver: C:\DOCUME~1\Admin\LOCALS~1\Temp\uwtdqpog.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB1FDAC56]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB1FDAB12]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB1FDB0C6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB1FDAFF0]
SSDT IPVNMon.sys (IPVNMon/Visual Networks) ZwDeviceIoControlFile [0xF7888803]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB1FDA6E8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB1FDABEC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB1FDA628]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB1FDA68C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB1FDAD0C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB1FDB194]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB1FDACCC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB1FDAE4C]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB21A1320]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB1FE74FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB1FE7322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB1FE745C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisMSetAttributesEx] [F7888744] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisMRegisterMiniport] [F788851E] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F788871A] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F78886A7] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisMSetAttributesEx] [F7888744] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F7888380] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisMRegisterMiniport] [F788851E] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F7888380] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F78886A7] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F788871A] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisMSetAttributesEx] [F7888744] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisMRegisterMiniport] [F788851E] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspptp.sys[NDIS.SYS!NdisMSetAttributesEx] [F7888744] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspptp.sys[NDIS.SYS!NdisMRegisterMiniport] [F788851E] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisIMRegisterLayeredMiniport] [F788848B] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F7888380] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F78886A7] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisMSetAttributesEx] [F7888744] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F788871A] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisMSetAttributesEx] [F7888744] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisMRegisterMiniport] [F788851E] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F7888380] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F788871A] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F78886A7] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F788871A] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F78886A7] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F7888380] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F7888380] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F78886A7] IPVNMon.sys (IPVNMon/Visual Networks)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F788871A] IPVNMon.sys (IPVNMon/Visual Networks)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\windows\system32\services.exe[700] @ C:\windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00370002
IAT C:\windows\system32\services.exe[700] @ C:\windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 00370000

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----


#5 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:27 AM

Posted 06 April 2010 - 03:56 PM

Hello.

Let's start off wtih Combofix.

Download and Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

Download Combofix from any of the links below, and save it to your desktop.
Link 1
Link 2

Please refer to this page for full instructions on how to run ComboFix.
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click ComboFix.exe to start the program. Agree to the prompts.
  • When ComboFix is finished, a log report (C:\ComboFix.txt) will open. Post back with it.
Leave your computer alone while ComboFix is running.

ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#6 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 06 April 2010 - 07:30 PM

Okay, here's the ComboFix log


ComboFix 10-04-05.06 - Admin 04/06/2010 17:15:32.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1527.972 [GMT -7:00]
Running from: c:\documents and settings\Admin\Desktop\ijijiiji.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Admin\Start Menu\Programs\Personal Protector
c:\documents and settings\Admin\Start Menu\Programs\Personal Protector\Personal Protector.lnk
c:\documents and settings\Admin\Start Menu\Programs\Personal Protector\Uninstall.lnk
c:\documents and settings\All Users\Microsoft PData
c:\documents and settings\All Users\Microsoft PData\track.wid
C:\install.exe
c:\windows\microsoftdefend.dll
c:\windows\patch.exe
c:\windows\regp.exe
c:\windows\secureit.com
c:\windows\spoos.exe
c:\windows\system32\bszip.dll
c:\windows\system32\uninstall.exe
c:\windows\Tasks\kweeuqwk.job

.
((((((((((((((((((((((((( Files Created from 2010-03-07 to 2010-04-07 )))))))))))))))))))))))))))))))
.

2010-04-05 01:29 . 2010-04-05 01:29 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-04-05 01:27 . 2010-02-01 01:45 38784 ----a-w- c:\documents and settings\Admin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-04-05 01:27 . 2010-02-01 01:45 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-04-05 01:27 . 2010-04-05 01:27 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-04-05 01:25 . 2010-04-05 01:25 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-04-05 01:24 . 2010-04-05 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-04-05 00:14 . 2010-03-09 10:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-05 00:14 . 2010-03-09 10:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-04-05 00:14 . 2010-03-09 10:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-04-05 00:14 . 2010-03-09 10:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-04-05 00:14 . 2010-03-09 10:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-04-05 00:14 . 2010-03-09 10:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-04-05 00:14 . 2010-03-09 10:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-05 00:13 . 2010-03-09 10:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-04-05 00:13 . 2010-03-09 10:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-04-04 22:49 . 2010-04-05 00:13 -------- d-----w- c:\program files\Alwil Software
2010-04-04 22:49 . 2010-04-04 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-04-04 00:41 . 2010-04-04 00:41 52224 ----a-w- c:\documents and settings\Admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-04-04 00:40 . 2010-04-05 00:38 117760 ----a-w- c:\documents and settings\Admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-04-04 00:40 . 2010-04-04 00:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-04-04 00:40 . 2010-04-04 00:40 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-04 00:40 . 2010-04-04 00:40 -------- d-----w- c:\documents and settings\Admin\Application Data\SUPERAntiSpyware.com
2010-04-04 00:07 . 2009-05-07 07:04 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-04-03 19:18 . 2010-04-03 19:18 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-04-03 03:15 . 2010-04-04 00:35 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-05 01:33 . 2005-07-22 19:44 -------- d-----w- c:\program files\Yahoo!
2010-04-05 01:33 . 2006-07-14 05:30 -------- d-----w- c:\documents and settings\All Users\Application Data\yahoo!
2010-04-05 01:32 . 2006-07-14 05:33 -------- d-----w- c:\program files\Common Files\Scanner
2010-04-05 01:29 . 2005-07-25 20:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-04 22:04 . 2005-07-22 06:58 -------- d-----w- c:\program files\Microsoft AntiSpyware
2010-04-03 18:33 . 2005-07-22 06:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-03 05:40 . 2008-12-31 02:03 -------- d-----w- c:\program files\Angle Interactive
2010-03-31 00:53 . 2008-12-30 01:36 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-26 01:14 . 2005-10-22 15:56 -------- d-----w- c:\program files\Dl_cats
2010-03-22 13:41 . 2010-02-02 00:25 79488 ----a-w- c:\documents and settings\Admin\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-08 04:32 . 2008-11-24 22:58 -------- d-----w- c:\program files\PokerStars
2010-02-13 14:32 . 2010-02-13 14:32 73728 ------w- c:\windows\system32\bcbf.sys
2006-01-05 04:09 . 2006-01-05 04:09 3290299 ----a-w- c:\program files\DailyText_1_3_0_Setup.exe
2005-08-27 22:47 . 2005-08-27 22:47 4077184 ----a-w- c:\program files\winzip90.exe
2010-02-02 00:24 . 2008-12-30 00:06 119312 ----a-w- c:\program files\mozilla firefox\components\baecdadccbbf.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-04-01 2010864]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"GoToMeeting"="c:\program files\Citrix\GoToMeeting\452\g2mstart.exe" [2010-02-13 39816]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll" [2004-12-07 69632]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 57344]
"IPInSightMonitor 01"="c:\program files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [2003-07-14 98304]
"dlbxmon.exe"="c:\program files\Dell Photo AIO Printer 962\dlbxmon.exe" [2005-01-18 425984]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"LoadMSvcmm"="c:\program files\Blockbuster\BLOCKBUSTERMovielink\Movielink User.exe" [2009-03-27 455112]
"eFax 4.3"="c:\program files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 116224]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-08-16 271672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-11 148888]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-10-2 815104]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-8-6 69632]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\windows\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/4/2010 5:14 PM 162640]
R1 bcbf;bcbf;c:\windows\system32\bcbf.sys [2/13/2010 7:32 AM 73728]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 11:15 AM 66632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/4/2010 5:14 PM 19024]
R2 MSSEARCH;Microsoft Search;c:\program files\Common Files\System\MSSearch\Bin\mssearch.exe [8/6/2005 5:35 PM 73728]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 11:15 AM 12872]
S0 f4d89a7139532f9e8b3a30c819c65a48;f4d89a7139532f9e8b3a30c819c65a48;c:\windows\system32\f4d89a7139532f9e8b3a30c819c65a48.sys [1/22/2009 4:33 PM 39936]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\ICDUSB2.sys [11/28/2002 10:23 PM 39048]

--- Other Services/Drivers In Memory ---

*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder

2010-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 20:34]

2010-04-07 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-29 06:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: efax.com\www
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\wlqgx11x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/search?hl=en&q=yahoo.com&btnG=Google+Search
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\wlqgx11x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Mozilla Firefox\components\baecdadccbbf.dll
FF - plugin: c:\documents and settings\Admin\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Admin\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Yahoo!\BrowserPlus\2.6.0\Plugins\npybrowserplus_2.6.0.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npybrowserplus_2.4.17.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
SharedTaskScheduler-{4f60267c-e8a4-4361-b604-c37519f21aa4} - (no file)
SharedTaskScheduler-{21a3e339-227f-4776-a391-374f198f6c32} - (no file)
SSODL-InternetProvider-{DEB51D06-A878-41DA-A75D-9A4AEED992A7} - (no file)
SSODL-domisasez-{4f60267c-e8a4-4361-b604-c37519f21aa4} - (no file)
SSODL-jasogezoj-{21a3e339-227f-4776-a391-374f198f6c32} - (no file)
AddRemove-SLABCOMM - c:\windows\system32\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-06 17:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(660)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(2880)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\BLOCKB~1\BLOCKB~1\MovielinkCore.exe
c:\progra~1\MI6841~1\MSSQL\binn\sqlservr.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Citrix\GoToMeeting\452\g2mcomm.exe
c:\program files\Citrix\GoToMeeting\452\g2mlauncher.exe
c:\windows\system32\dlbxcoms.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-04-06 17:27:48 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-07 00:27

Pre-Run: 51,126,861,824 bytes free
Post-Run: 51,019,591,680 bytes free

- - End Of File - - 932F5FF16CEBB8B595FA7F79CE09636D


#7 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:27 AM

Posted 07 April 2010 - 08:30 PM

Download and Run OTM
  1. Please download OTM by OldTimer and save it to your desktop.
  2. Double click the icon on your desktop If you are running on Vista, right click on the file and choose Run As Administrator.
  3. Paste the following code under the area. Do not include the word "Code".
    CODE
    :services
    f4d89a7139532f9e8b3a30c819c65a48
    :files
    c:\windows\system32\f4d89a7139532f9e8b3a30c819c65a48.sys
    :Commands
    [CREATERESTOREPOINT]
    [resethosts]
    [emptytemp]
  4. Click the large button.
  5. If OTM requires are reboot, please allow it to do so.
  6. Copy/Paste the contents under the line here in your next reply.
Note: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Update and Scan with MalwareBytes Anti-Malware
  • Launch Malwarebytes' Anti-Malware
  • Go to the Update tab
  • Select Check for Update and let MBAM download and install any available updates.
  • After the update is complete go to the Scanner tab.
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#8 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 07 April 2010 - 09:27 PM

Heres the OTM. I'll post the MWB shortly.

All processes killed
========== SERVICES/DRIVERS ==========
Service f4d89a7139532f9e8b3a30c819c65a48 stopped successfully!
Service f4d89a7139532f9e8b3a30c819c65a48 deleted successfully!
========== FILES ==========
c:\windows\system32\f4d89a7139532f9e8b3a30c819c65a48.sys moved successfully.
========== COMMANDS ==========
Restore point Set: OTM Restore Point (64424509440)
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 86036 bytes
->Temporary Internet Files folder emptied: 217746 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 14279802 bytes
->Flash cache emptied: 1935834 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 7974318 bytes
->Flash cache emptied: 405 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 12983296 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 511 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33661 bytes
RecycleBin emptied: 3932448 bytes

Total Files Cleaned = 40.00 mb


OTM by OldTimer - Version 3.1.10.1 log created on 04072010_191733


#9 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 07 April 2010 - 09:34 PM

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3967

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

4/7/2010 7:34:13 PM
mbam-log-2010-04-07 (19-34-13).txt

Scan type: Quick scan
Objects scanned: 107680
Time elapsed: 6 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Angle Interactive\RD2010 (Rogue.RegDefender) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\config\systemprofile\Desktop\Personal Protector.lnk (Rogue.PersonalProtector) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Desktop\Advanced Virus Remover.lnk (Rogue.AdvancedVirusRemover) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Start Menu\Advanced Virus Remover.lnk (Rogue.AdvancedVirusRemover) -> Quarantined and deleted successfully.


#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:27 AM

Posted 07 April 2010 - 09:37 PM

That's looking good.

Let's just get an online scan + another DDS log afterward.

Run ESET Online Scan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
You can refer to this animation by neomage if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 08 April 2010 - 11:28 AM

Thanks for your help. I will be posting the rest once I get home from work today. I had to leave the house after the mwb scan

#12 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:27 AM

Posted 08 April 2010 - 04:57 PM

Okay. Thanks for letting me know.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#13 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 09 April 2010 - 12:00 AM

Here are the logs. I noticed that I'm still getting redirects when clicking on certain search results from Google. For instance, I searched for "Superantispyware" and the results came back. When I click on the link for the official site, it begins to redirect.



DDS (Ver_10-03-17.01) - NTFSx86
Run by Admin at 21:57:27.62 on Thu 04/08/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1527.967 [GMT -7:00]

AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\windows\system32\svchost -k DcomLaunch
svchost.exe
C:\windows\System32\svchost.exe -k netsvcs
svchost.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\windows\SOUNDMAN.EXE
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\system32\dlbxcoms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [GoToMeeting] "c:\program files\citrix\gotomeeting\452\g2mstart.exe" "/Trigger RunAtLogon"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DLBXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLBXtime.dll,_RunDLLEntry@16
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [IPInSightMonitor 01] "c:\program files\sbc yahoo!\connection manager\ip insight\IPMon32.exe"
mRun: [dlbxmon.exe] "c:\program files\dell photo aio printer 962\dlbxmon.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [LoadMSvcmm] "c:\program files\blockbuster\blockbustermovielink\Movielink User.exe"
mRun: [eFax 4.3] "c:\program files\efax messenger 4.3\J2GDllCmd.exe" /R
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
Trusted Zone: efax.com\www
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} - hxxps://support.microsoft.com/OAS/ActiveX/odc.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1122014265156
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - hxxp://download.yahoo.com/dl/installs/ymail/ymmapi.dll
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - hxxp://www.photodex.com/pxplay.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\wlqgx11x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/search?hl=en&q=yahoo.com&btnG=Google+Search
FF - component: c:\program files\mozilla firefox\components\baecdadccbbf.dll
FF - plugin: c:\documents and settings\admin\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\admin\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\admin\application data\mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\admin\local settings\application data\yahoo!\browserplus\2.6.0\plugins\npybrowserplus_2.6.0.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npitunes.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npybrowserplus_2.4.17.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-4 162640]
R1 bcbf;bcbf;c:\windows\system32\bcbf.sys [2010-2-13 73728]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-4 19024]
R2 MSSEARCH;Microsoft Search;c:\program files\common files\system\mssearch\bin\mssearch.exe [2005-8-6 73728]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-4 40384]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-4 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-4 40384]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\ICDUSB2.sys [2002-11-28 39048]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]

=============== Created Last 30 ================

2010-04-08 02:26:28 0 d-----w- c:\docume~1\admin\applic~1\Malwarebytes
2010-04-08 02:26:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-08 02:26:19 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-08 02:26:13 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-08 02:26:13 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-08 02:17:33 0 d-----w- C:\_OTM
2010-04-07 00:34:14 0 d-----w- c:\windows\ie8updates
2010-04-07 00:29:36 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-04-07 00:29:36 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-04-07 00:29:35 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-07 00:29:35 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-04-07 00:29:34 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-04-07 00:13:15 98816 ----a-w- c:\windows\sed.exe
2010-04-07 00:13:15 77312 ----a-w- c:\windows\MBR.exe
2010-04-07 00:13:15 261632 ----a-w- c:\windows\PEV.exe
2010-04-07 00:13:15 161792 ----a-w- c:\windows\SWREG.exe
2010-04-04 22:49:25 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-04-04 00:40:27 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-04-04 00:40:21 0 d-----w- c:\program files\SUPERAntiSpyware
2010-04-04 00:40:21 0 d-----w- c:\docume~1\admin\applic~1\SUPERAntiSpyware.com
2010-04-04 00:07:15 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-04-03 03:15:32 0 d-----w- c:\program files\common files\Wise Installation Wizard

==================== Find3M ====================

2010-02-25 06:24:37 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-13 14:32:54 73728 ------w- c:\windows\system32\bcbf.sys
2006-01-05 04:09:27 3290299 ----a-w- c:\program files\DailyText_1_3_0_Setup.exe
2005-08-27 22:47:13 4077184 ----a-w- c:\program files\winzip90.exe

============= FINISH: 21:58:12.45 ===============

Attached Files



#14 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:27 AM

Posted 09 April 2010 - 08:47 PM

Hello again,

Yes the redirects, follow the instructions below -it should take care of it. smile.gif

Run ComboFix with CFScript

We will run ComboFix again. This time, the instructions are slightly different.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    CODE
    FireFox::
    FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\wlqgx11x.default\
    FF - component: c:\program files\Mozilla Firefox\components\baecdadccbbf.dll
    File::
    c:\program files\mozilla firefox\components\baecdadccbbf.dll
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)

    Refering to the picture above, drag CFScript into ComboFix.exe.
When finished, it shall produce a log for you at "C:\ComboFix.txt". Post back with that log.

Do not mouseclick ComboFix's window while it's running. That may cause it to stall

Then, let's update your Java...

Update Java to Version 6 Update 19

Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 19 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u19-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
-- Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
-- Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer.

Edited by extremeboy, 09 April 2010 - 08:57 PM.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#15 kingship

kingship
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:09:27 PM

Posted 09 April 2010 - 11:20 PM

ComboFix 10-04-09.01 - Admin 04/09/2010 21:12:17.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1527.1109 [GMT -7:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\program files\mozilla firefox\components\baecdadccbbf.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Mozilla Firefox\components\baecdadccbbf.dll

.
((((((((((((((((((((((((( Files Created from 2010-03-10 to 2010-04-10 )))))))))))))))))))))))))))))))
.

2010-04-10 02:36 . 2010-04-10 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-04-10 02:36 . 2010-04-10 02:36 -------- d-----w- c:\documents and settings\Admin\Application Data\Office Genuine Advantage
2010-04-08 02:26 . 2010-04-08 02:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2010-04-08 02:26 . 2010-03-30 07:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-08 02:26 . 2010-04-08 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-08 02:26 . 2010-04-08 02:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-08 02:26 . 2010-03-30 07:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-08 02:17 . 2010-04-08 02:17 -------- d-----w- C:\_OTM
2010-04-07 05:18 . 2010-04-07 05:18 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-04-07 00:34 . 2010-04-07 05:10 -------- d-----w- c:\windows\ie8updates
2010-04-07 00:29 . 2010-02-25 06:24 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-04-07 00:29 . 2010-02-25 06:24 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-04-07 00:29 . 2010-02-25 06:24 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-04-07 00:29 . 2010-02-25 06:24 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-07 00:29 . 2010-02-25 06:24 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-04-05 01:29 . 2010-04-05 01:29 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-04-05 01:27 . 2010-04-05 01:27 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-04-05 01:25 . 2010-04-05 01:25 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-04-05 01:24 . 2010-04-05 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-04-05 00:14 . 2010-03-09 10:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-05 00:14 . 2010-03-09 10:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-04-05 00:14 . 2010-03-09 10:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-04-05 00:14 . 2010-03-09 10:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-04-05 00:14 . 2010-03-09 10:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-04-05 00:14 . 2010-03-09 10:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-04-05 00:14 . 2010-03-09 10:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-05 00:13 . 2010-03-09 10:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-04-05 00:13 . 2010-03-09 10:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-04-04 22:49 . 2010-04-05 00:13 -------- d-----w- c:\program files\Alwil Software
2010-04-04 22:49 . 2010-04-04 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-04-04 00:41 . 2010-04-04 00:41 52224 ----a-w- c:\documents and settings\Admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-04-04 00:40 . 2010-04-05 00:38 117760 ----a-w- c:\documents and settings\Admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-04-04 00:40 . 2010-04-04 00:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-04-04 00:40 . 2010-04-04 00:40 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-04 00:40 . 2010-04-04 00:40 -------- d-----w- c:\documents and settings\Admin\Application Data\SUPERAntiSpyware.com
2010-04-04 00:07 . 2009-05-07 07:04 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-04-03 19:18 . 2010-04-03 19:18 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-04-03 03:15 . 2010-04-04 00:35 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-08 02:34 . 2008-12-31 02:03 -------- d-----w- c:\program files\Angle Interactive
2010-04-05 01:33 . 2005-07-22 19:44 -------- d-----w- c:\program files\Yahoo!
2010-04-05 01:33 . 2006-07-14 05:30 -------- d-----w- c:\documents and settings\All Users\Application Data\yahoo!
2010-04-05 01:32 . 2006-07-14 05:33 -------- d-----w- c:\program files\Common Files\Scanner
2010-04-05 01:29 . 2005-07-25 20:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-04 22:04 . 2005-07-22 06:58 -------- d-----w- c:\program files\Microsoft AntiSpyware
2010-04-03 18:33 . 2005-07-22 06:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-31 00:53 . 2008-12-30 01:36 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-26 01:14 . 2005-10-22 15:56 -------- d-----w- c:\program files\Dl_cats
2010-03-22 13:41 . 2010-02-02 00:25 79488 ----a-w- c:\documents and settings\Admin\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-08 04:32 . 2008-11-24 22:58 -------- d-----w- c:\program files\PokerStars
2010-02-25 06:24 . 2004-08-04 07:56 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-13 14:32 . 2010-02-13 14:32 73728 ------w- c:\windows\system32\bcbf.sys
2006-01-05 04:09 . 2006-01-05 04:09 3290299 ----a-w- c:\program files\DailyText_1_3_0_Setup.exe
2005-08-27 22:47 . 2005-08-27 22:47 4077184 ----a-w- c:\program files\winzip90.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-04-07_00.21.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-10 03:58 . 2010-04-10 03:58 16384 c:\windows\Temp\Perflib_Perfdata_898.dat
+ 2010-04-10 03:58 . 2010-04-10 03:58 16384 c:\windows\Temp\Perflib_Perfdata_834.dat
- 2007-01-29 08:58 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
+ 2007-01-29 08:58 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
+ 2004-08-04 07:56 . 2009-10-21 06:00 75776 c:\windows\system32\strmfilt.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 75776 c:\windows\system32\strmfilt.dll
+ 2004-08-04 07:56 . 2009-10-12 13:54 69632 c:\windows\system32\raschap.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 69632 c:\windows\system32\raschap.dll
+ 2002-08-29 12:00 . 2010-04-07 05:17 86556 c:\windows\system32\perfc009.dat
- 2002-08-29 12:00 . 2010-03-15 16:10 86556 c:\windows\system32\perfc009.dat
+ 2004-08-04 00:56 . 2009-11-27 17:33 17920 c:\windows\system32\msyuv.dll
+ 2002-08-29 12:00 . 2009-11-27 16:37 28672 c:\windows\system32\msvidc32.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 11264 c:\windows\system32\msrle32.dll
+ 2004-08-04 07:56 . 2009-11-27 16:37 11264 c:\windows\system32\msrle32.dll
+ 2009-03-08 12:31 . 2010-02-25 06:24 55296 c:\windows\system32\msfeedsbs.dll
- 2009-03-08 12:31 . 2009-03-08 12:31 55296 c:\windows\system32\msfeedsbs.dll
- 2004-08-04 07:56 . 2009-03-08 12:33 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 00:56 . 2009-11-27 16:37 48128 c:\windows\system32\iyuv_32.dll
+ 2004-08-04 07:56 . 2009-10-21 06:00 25088 c:\windows\system32\httpapi.dll
+ 2002-08-29 12:00 . 2009-10-15 17:21 82432 c:\windows\system32\fontsub.dll
- 2002-08-29 12:00 . 2009-06-16 14:55 82432 c:\windows\system32\fontsub.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2004-08-04 07:56 . 2009-10-21 06:00 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2004-08-04 07:56 . 2009-10-12 13:54 69632 c:\windows\system32\dllcache\raschap.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 69632 c:\windows\system32\dllcache\raschap.dll
+ 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\system32\dllcache\msyuv.dll
+ 2002-08-29 12:00 . 2009-11-27 16:37 28672 c:\windows\system32\dllcache\msvidc32.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 11264 c:\windows\system32\dllcache\msrle32.dll
+ 2004-08-04 07:56 . 2009-11-27 16:37 11264 c:\windows\system32\dllcache\msrle32.dll
- 2004-08-04 07:56 . 2009-03-08 12:33 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\system32\dllcache\iyuv_32.dll
+ 2004-08-04 07:56 . 2009-10-21 06:00 25088 c:\windows\system32\dllcache\httpapi.dll
+ 2002-08-29 12:00 . 2009-10-15 17:21 82432 c:\windows\system32\dllcache\fontsub.dll
- 2002-08-29 12:00 . 2009-06-16 14:55 82432 c:\windows\system32\dllcache\fontsub.dll
+ 2004-08-04 07:56 . 2009-12-14 07:35 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2004-08-04 07:56 . 2009-11-27 16:37 84992 c:\windows\system32\dllcache\avifil32.dll
- 2004-08-04 07:56 . 2009-06-10 14:21 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2004-08-04 07:56 . 2009-12-14 07:35 33280 c:\windows\system32\csrsrv.dll
- 2004-08-04 07:56 . 2009-06-10 14:21 84992 c:\windows\system32\avifil32.dll
+ 2004-08-04 07:56 . 2009-11-27 16:37 84992 c:\windows\system32\avifil32.dll
+ 2005-07-22 06:31 . 2010-04-07 05:10 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-04-07 00:35 . 2009-03-08 12:33 12288 c:\windows\ie8updates\KB980182-IE8\xpshims.dll
+ 2010-04-07 00:34 . 2009-03-08 12:31 55296 c:\windows\ie8updates\KB980182-IE8\msfeedsbs.dll
+ 2010-04-07 00:34 . 2009-03-08 12:33 25600 c:\windows\ie8updates\KB980182-IE8\jsproxy.dll
+ 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\Driver Cache\i386\msyuv.dll
+ 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
+ 2001-08-17 22:36 . 2009-11-27 16:37 8704 c:\windows\system32\tsbyuv.dll
+ 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\system32\dllcache\tsbyuv.dll
- 2005-07-22 06:31 . 2009-11-11 08:15 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
+ 2004-08-04 07:56 . 2009-08-25 09:47 352256 c:\windows\system32\winhttp.dll
+ 2007-03-16 01:17 . 2009-03-11 05:18 934792 c:\windows\system32\WgaTray.exe
+ 2007-03-16 01:16 . 2009-03-11 05:18 239496 c:\windows\system32\WgaLogon.dll
+ 2004-08-04 07:56 . 2009-10-16 05:51 119808 c:\windows\system32\t2embed.dll
- 2004-08-04 07:56 . 2009-06-16 14:55 119808 c:\windows\system32\t2embed.dll
+ 2004-08-04 07:56 . 2009-12-08 09:13 474112 c:\windows\system32\shlwapi.dll
+ 2004-08-04 07:56 . 2009-10-12 13:54 112128 c:\windows\system32\rastls.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 112128 c:\windows\system32\rastls.dll
- 2002-08-29 12:00 . 2010-03-15 16:10 480446 c:\windows\system32\perfh009.dat
+ 2002-08-29 12:00 . 2010-04-07 05:17 480446 c:\windows\system32\perfh009.dat
+ 2009-08-03 22:07 . 2009-08-03 22:07 230768 c:\windows\system32\OGAEXEC.exe
+ 2009-08-03 22:07 . 2009-08-03 22:07 403816 c:\windows\system32\OGACheckControl.dll
+ 2009-08-03 22:07 . 2009-08-03 22:07 322928 c:\windows\system32\OGAAddin.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 206848 c:\windows\system32\occache.dll
+ 2004-08-04 07:56 . 2009-10-13 10:53 266752 c:\windows\system32\oakley.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 266752 c:\windows\system32\oakley.dll
- 2004-08-04 07:56 . 2009-03-08 12:32 611840 c:\windows\system32\mstime.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 611840 c:\windows\system32\mstime.dll
+ 2005-07-22 05:45 . 2009-12-16 12:58 343040 c:\windows\system32\mspaint.exe
- 2005-07-22 05:45 . 2004-08-04 07:56 343040 c:\windows\system32\mspaint.exe
+ 2009-03-08 12:32 . 2010-02-25 06:24 594432 c:\windows\system32\msfeeds.dll
- 2009-03-08 12:32 . 2009-03-08 12:32 594432 c:\windows\system32\msfeeds.dll
+ 2004-08-04 07:56 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
- 2004-08-04 07:56 . 2009-03-08 12:33 726528 c:\windows\system32\jscript.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 184320 c:\windows\system32\iepeers.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-04 07:56 . 2009-03-08 12:32 173056 c:\windows\system32\ie4uinit.exe
+ 2004-08-04 07:56 . 2010-02-24 09:54 173056 c:\windows\system32\ie4uinit.exe
+ 2004-08-04 06:14 . 2009-12-31 16:14 352640 c:\windows\system32\drivers\srv.sys
+ 2004-08-04 06:15 . 2009-12-04 14:41 453760 c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-04 06:00 . 2009-10-20 14:58 263552 c:\windows\system32\drivers\http.sys
+ 2004-08-04 07:56 . 2010-02-25 06:24 916480 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-04 07:56 . 2009-08-25 09:47 352256 c:\windows\system32\dllcache\winhttp.dll
+ 2007-03-16 01:17 . 2009-03-11 05:18 934792 c:\windows\system32\dllcache\WgaTray.exe
+ 2007-03-16 01:16 . 2009-03-11 05:18 239496 c:\windows\system32\dllcache\wgaLogon.dll
- 2004-08-04 07:56 . 2009-06-16 14:55 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2004-08-04 07:56 . 2009-10-16 05:51 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2004-08-04 06:14 . 2009-12-31 16:14 352640 c:\windows\system32\dllcache\srv.sys
+ 2004-08-04 07:56 . 2009-12-08 09:13 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2004-08-04 07:56 . 2009-10-12 13:54 112128 c:\windows\system32\dllcache\rastls.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 112128 c:\windows\system32\dllcache\rastls.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 206848 c:\windows\system32\dllcache\occache.dll
+ 2004-08-04 07:56 . 2009-10-13 10:53 266752 c:\windows\system32\dllcache\oakley.dll
- 2004-08-04 07:56 . 2004-08-04 07:56 266752 c:\windows\system32\dllcache\oakley.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 611840 c:\windows\system32\dllcache\mstime.dll
- 2004-08-04 07:56 . 2009-03-08 12:32 611840 c:\windows\system32\dllcache\mstime.dll
- 2005-07-22 05:45 . 2004-08-04 07:56 343040 c:\windows\system32\dllcache\mspaint.exe
+ 2005-07-22 05:45 . 2009-12-16 12:58 343040 c:\windows\system32\dllcache\mspaint.exe
+ 2006-05-05 09:41 . 2009-12-04 14:41 453760 c:\windows\system32\dllcache\mrxsmb.sys
- 2004-08-04 07:56 . 2009-03-08 12:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 07:56 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2004-08-04 07:56 . 2009-03-08 12:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-04 07:56 . 2010-02-24 09:54 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-10-20 14:58 . 2009-10-20 14:58 263552 c:\windows\system32\dllcache\http.sys
+ 2004-08-04 07:56 . 2009-11-21 16:36 470528 c:\windows\system32\dllcache\aclayers.dll
+ 2010-04-07 00:40 . 2010-04-07 00:40 969728 c:\windows\Installer\c2917.msi
+ 2009-09-09 22:40 . 2009-09-09 22:40 632320 c:\windows\Installer\c2910.msp
+ 2010-04-07 05:08 . 2010-04-07 05:08 119296 c:\windows\Installer\115dc1.msi
+ 2005-07-22 06:31 . 2010-04-07 05:10 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2005-07-22 06:31 . 2009-11-11 08:15 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2005-07-22 06:31 . 2010-04-07 05:10 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2007-05-10 22:35 . 2007-05-10 22:35 120160 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\MSCONV97.DLL
+ 2010-04-07 00:34 . 2009-03-08 12:34 914944 c:\windows\ie8updates\KB980182-IE8\wininet.dll
+ 2010-04-07 00:35 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB980182-IE8\spuninst\updspapi.dll
+ 2010-04-07 00:35 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB980182-IE8\spuninst\spuninst.exe
+ 2010-04-07 00:34 . 2009-03-08 12:34 109568 c:\windows\ie8updates\KB980182-IE8\occache.dll
+ 2010-04-07 00:34 . 2009-03-08 12:32 611840 c:\windows\ie8updates\KB980182-IE8\mstime.dll
+ 2010-04-07 00:34 . 2009-03-08 12:32 594432 c:\windows\ie8updates\KB980182-IE8\msfeeds.dll
+ 2010-04-07 00:35 . 2009-03-08 12:33 246784 c:\windows\ie8updates\KB980182-IE8\ieproxy.dll
+ 2010-04-07 00:34 . 2009-03-08 12:31 183808 c:\windows\ie8updates\KB980182-IE8\iepeers.dll
+ 2010-04-07 00:35 . 2009-03-08 22:09 391536 c:\windows\ie8updates\KB980182-IE8\iedkcs32.dll
+ 2010-04-07 00:35 . 2009-03-08 12:32 173056 c:\windows\ie8updates\KB980182-IE8\ie4uinit.exe
+ 2010-04-07 05:10 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
+ 2010-04-07 05:10 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
+ 2010-04-07 05:10 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
+ 2010-04-07 00:34 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2010-04-07 00:34 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2010-04-07 00:34 . 2009-03-08 12:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2004-10-28 01:14 . 2009-12-04 14:41 453760 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2004-10-08 23:48 . 2009-10-20 14:58 263552 c:\windows\Driver Cache\i386\http.sys
+ 2004-08-04 07:56 . 2009-11-21 16:36 470528 c:\windows\AppPatch\aclayers.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 1209344 c:\windows\system32\urlmon.dll
+ 2004-08-04 07:56 . 2009-11-27 17:33 1291264 c:\windows\system32\quartz.dll
- 2004-08-04 06:18 . 2009-08-04 13:58 2136064 c:\windows\system32\ntoskrnl.exe
+ 2004-08-04 06:18 . 2009-12-08 18:53 2136064 c:\windows\system32\ntoskrnl.exe
+ 2004-08-03 22:59 . 2009-12-08 18:19 2015744 c:\windows\system32\ntkrnlpa.exe
- 2004-08-03 22:59 . 2009-08-04 13:13 2015744 c:\windows\system32\ntkrnlpa.exe
+ 2009-08-20 00:07 . 2009-08-20 00:07 1415000 c:\windows\system32\msxml6.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 5944832 c:\windows\system32\mshtml.dll
+ 2005-01-28 22:38 . 2009-03-11 05:18 1482112 c:\windows\system32\LegitCheckControl.dll
+ 2009-03-08 12:32 . 2010-02-25 06:24 1985536 c:\windows\system32\iertutil.dll
+ 2004-08-04 07:56 . 2010-02-25 06:24 1209344 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 07:56 . 2009-11-27 17:33 1291264 c:\windows\system32\dllcache\quartz.dll
+ 2006-12-19 14:17 . 2009-12-08 18:55 2180352 c:\windows\system32\dllcache\ntoskrnl.exe
- 2006-12-19 14:17 . 2009-08-04 14:00 2180352 c:\windows\system32\dllcache\ntoskrnl.exe
- 2006-12-19 12:55 . 2009-08-04 13:13 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2006-12-19 12:55 . 2009-12-08 18:19 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
- 2006-12-19 12:55 . 2009-08-04 13:13 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2006-12-19 12:55 . 2009-12-08 18:19 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2006-12-19 14:15 . 2009-12-08 18:53 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2006-12-19 14:15 . 2009-08-04 13:58 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2004-08-04 07:56 . 2010-02-25 06:24 5944832 c:\windows\system32\dllcache\mshtml.dll
+ 2005-07-22 05:47 . 2009-10-23 14:27 3555328 c:\windows\system32\dllcache\moviemk.exe
- 2005-07-22 05:47 . 2004-08-04 07:56 3555328 c:\windows\system32\dllcache\moviemk.exe
+ 2010-01-28 00:53 . 2010-01-28 00:53 6820864 c:\windows\Installer\c28fb.msp
+ 2009-12-17 05:58 . 2009-12-17 05:58 5382144 c:\windows\Installer\c28e6.msp
+ 2010-01-20 01:29 . 2010-01-20 01:29 5050368 c:\windows\Installer\c28cf.msp
+ 2010-02-05 01:11 . 2010-02-05 01:11 5526528 c:\windows\Installer\115dd4.msp
+ 2007-04-19 21:49 . 2007-04-19 21:49 1661280 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PPTVIEW.EXE
+ 2010-04-07 00:34 . 2009-03-08 12:34 1206784 c:\windows\ie8updates\KB980182-IE8\urlmon.dll
+ 2010-04-07 00:34 . 2009-03-08 12:41 5937152 c:\windows\ie8updates\KB980182-IE8\mshtml.dll
+ 2010-04-07 00:34 . 2009-03-08 12:32 1985024 c:\windows\ie8updates\KB980182-IE8\iertutil.dll
+ 2005-03-02 00:59 . 2009-12-08 18:55 2180352 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2005-03-02 00:59 . 2009-08-04 14:00 2180352 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2005-03-02 00:34 . 2009-12-08 18:19 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2005-03-02 00:34 . 2009-08-04 13:13 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2005-03-02 00:34 . 2009-12-08 18:19 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2005-03-02 00:34 . 2009-08-04 13:13 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2005-03-02 00:57 . 2009-08-04 13:58 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2005-03-02 00:57 . 2009-12-08 18:53 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-04-07 00:35 . 2010-03-02 04:30 31648712 c:\windows\system32\MRT.exe
+ 2009-03-08 12:39 . 2010-02-25 18:54 11070976 c:\windows\system32\ieframe.dll
+ 2010-02-25 18:54 . 2010-02-25 18:54 11070976 c:\windows\system32\dllcache\ieframe.dll
+ 2010-04-07 00:35 . 2009-03-08 12:39 11063808 c:\windows\ie8updates\KB980182-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"GoToMeeting"="c:\program files\Citrix\GoToMeeting\452\g2mstart.exe" [2010-02-13 39816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll" [2004-12-07 69632]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 57344]
"IPInSightMonitor 01"="c:\program files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [2003-07-14 98304]
"dlbxmon.exe"="c:\program files\Dell Photo AIO Printer 962\dlbxmon.exe" [2005-01-18 425984]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"LoadMSvcmm"="c:\program files\Blockbuster\BLOCKBUSTERMovielink\Movielink User.exe" [2009-03-27 455112]
"eFax 4.3"="c:\program files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 116224]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-08-16 271672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-11 148888]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-10-2 815104]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-8-6 69632]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\windows\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/4/2010 5:14 PM 162640]
R1 bcbf;bcbf;c:\windows\system32\bcbf.sys [2/13/2010 7:32 AM 73728]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 11:15 AM 66632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/4/2010 5:14 PM 19024]
R2 MSSEARCH;Microsoft Search;c:\program files\Common Files\System\MSSearch\Bin\mssearch.exe [8/6/2005 5:35 PM 73728]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\ICDUSB2.sys [11/28/2002 10:23 PM 39048]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 11:15 AM 12872]

--- Other Services/Drivers In Memory ---

*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder

2010-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 20:34]

2010-04-10 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: efax.com\www
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\wlqgx11x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/search?hl=en&q=yahoo.com&btnG=Google+Search
FF - plugin: c:\documents and settings\Admin\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Admin\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Yahoo!\BrowserPlus\2.6.0\Plugins\npybrowserplus_2.6.0.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npybrowserplus_2.4.17.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-09 21:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(660)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2010-04-09 21:19:07
ComboFix-quarantined-files.txt 2010-04-10 04:19
ComboFix2.txt 2010-04-07 00:27

Pre-Run: 49,549,692,928 bytes free
Post-Run: 49,628,860,416 bytes free

- - End Of File - - 1187E27208970B1AB9DF7AA24A22A3FF





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users