Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google Redirect


  • This topic is locked This topic is locked
16 replies to this topic

#1 Moyira

Moyira

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:23 PM

Posted 21 August 2010 - 12:09 AM

I use AVG, and Spybot S&D. I have continuously updated and I scan everyday. But I am finding NOTHING in any of my scans. My AVG also scans for rootkits, and has found nothing. But everytime I click a link in a Google Search (and so far, it just seems to be google), I get redirected to various ad sites.

Here is my DDS log.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Erica at 23:05:54.92 on Fri 08/20/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3070.1549 [GMT -6:00]

SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\lxdqcoms.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lexmark Z2400 Series\lxdqMsdMon.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Erica\Downloads\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Foxit Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: Foxit Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Logitech Vid] "c:\program files\logitech\logitech vid\vid.exe" -bootmode
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [lxdqmon.exe] "c:\program files\lexmark z2400 series\lxdqmon.exe"
mRun: [lxdqamon] "c:\program files\lexmark z2400 series\lxdqamon.exe"
mRun: [RivaTuner] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition\RivaTunerWrapper.exe" /T
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition\RivaTunerWrapper.exe" /S
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\erica\appdata\roaming\microsoft\windows\start menu\programs\startup\CurseClientStartup.ccip
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\avgrsstx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\erica\appdata\roaming\mozilla\firefox\profiles\g5m2g1l0.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - component: c:\users\erica\appdata\roaming\mozilla\firefox\profiles\g5m2g1l0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\erica\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.ytff.general.dontshowhpoffer, truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-4-19 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-4-19 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-4-19 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-4-19 243024]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-6-22 921952]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-22 308136]
R2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe -service --> c:\windows\system32\lxdqcoms.exe -service [?]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-8-19 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-4-3 240232]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-3-4 277536]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2010-1-24 16168]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-4-19 430152]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-19 1343400]

=============== Created Last 30 ================

2010-08-21 05:04:56 0 ----a-w- c:\users\erica\defogger_reenable
2010-08-21 04:09:09 0 d-s---w- C:\ComboFix
2010-08-21 03:43:00 361606126 ----a-w- c:\windows\MEMORY.DMP
2010-08-21 03:32:23 98816 ----a-w- c:\windows\sed.exe
2010-08-21 03:32:23 77312 ----a-w- c:\windows\MBR.exe
2010-08-21 03:32:23 256512 ----a-w- c:\windows\PEV.exe
2010-08-21 03:32:23 161792 ----a-w- c:\windows\SWREG.exe
2010-08-20 05:34:23 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-20 05:34:23 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-20 02:09:26 0 d-----w- c:\program files\The Witcher Enhanced Edition
2010-08-10 19:49:05 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-04 15:54:42 0 d-----w- c:\program files\iPod
2010-08-01 18:54:02 0 d-----w- c:\program files\MSECache
2010-07-27 13:50:08 0 d-----w- c:\program files\StarCraft II
2010-07-26 22:57:54 0 d-----w- c:\users\erica\Starcraft2
2010-07-23 20:15:49 0 d-----w- c:\program files\Mass Effect

==================== Find3M ====================

2010-08-20 03:02:08 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-08-20 03:02:08 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-16 01:28:27 580 ----a-w- C:\RegBackup.reg
2010-06-30 06:25:31 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-28 01:17:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSBW_01_00_00.Wdf
2010-06-28 01:17:40 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSQVGA_01_00_00.Wdf
2010-06-22 14:55:16 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 14:55:16 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 14:55:13 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-19 06:33:29 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07:18 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48:35 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-08 06:02:06 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-05-27 07:24:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49:37 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-26 16:30:55 411368 ----a-w- c:\windows\system32\deployJava1.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 23:06:23.71 ===============


BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:23 PM

Posted 26 August 2010 - 10:10 AM

Hi and welcome. smile.gif

My name is Extremeboy (or EB for short), and I will be helping you with your log. I apologize for the delay.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a GMER log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or GMER log please refer to this page and in step #6 and Step #7 and Step #8 for further instructions on downloading and running DDS & GMER. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-GMER log
-Description of any remaining problems you may still have.


With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 Moyira

Moyira
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:23 PM

Posted 26 August 2010 - 10:43 AM

Hi, and thanks!

I do still have the redirect problem. I cannot run GMER, it always bluescreens my computer.
I have attached the Attach log from DDS, and the DDS log is below.
Thanks for your help again!


DDS (Ver_10-03-17.01) - NTFSx86
Run by Erica at 9:39:50.15 on Thu 08/26/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3070.1767 [GMT -6:00]

SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\lxdqcoms.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lexmark Z2400 Series\lxdqMsdMon.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\AVG\AVG9\avgupd.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Erica\Desktop\bleepingcomputer\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [lxdqmon.exe] "c:\program files\lexmark z2400 series\lxdqmon.exe"
mRun: [lxdqamon] "c:\program files\lexmark z2400 series\lxdqamon.exe"
mRun: [RivaTuner] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition\RivaTunerWrapper.exe" /T
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition\RivaTunerWrapper.exe" /S
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\erica\appdata\roaming\mozilla\firefox\profiles\2co3t1dl.default\
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\erica\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-4-19 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-4-19 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-4-19 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-4-19 243024]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-6-22 921952]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-22 308136]
R2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe -service --> c:\windows\system32\lxdqcoms.exe -service [?]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-8-19 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-7-9 248936]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-3-4 277536]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2010-1-24 16168]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-4-19 430152]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-19 1343400]
S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\erica\desktop\real temp\WinRing0.sys [2008-7-26 14416]

=============== Created Last 30 ================

2010-08-25 17:39:54 0 d-----w- c:\programdata\NVIDIA Corporation
2010-08-25 17:38:59 56936 ----a-w- c:\windows\system32\OpenCL.dll
2010-08-25 17:38:59 11008040 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-08-25 17:38:59 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-08-25 17:38:57 4553832 ----a-w- c:\windows\system32\nvcuda.dll
2010-08-25 17:38:57 314984 ----a-w- c:\windows\system32\nvdecodemft.dll
2010-08-25 17:38:57 2892904 ----a-w- c:\windows\system32\nvcuvid.dll
2010-08-25 17:38:57 2506344 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-08-25 17:38:57 14092904 ----a-w- c:\windows\system32\nvoglv32.dll
2010-08-25 17:38:55 236136 ----a-w- c:\windows\system32\nvcod1922.dll
2010-08-25 17:38:55 236136 ----a-w- c:\windows\system32\nvcod.dll
2010-08-25 17:38:55 10267240 ----a-w- c:\windows\system32\nvcompiler.dll
2010-08-25 14:57:00 571904 ----a-w- c:\windows\system32\oleaut32.dll
2010-08-22 17:41:53 0 d-sh--w- C:\$RECYCLE.BIN
2010-08-22 16:58:01 423201774 ----a-w- c:\windows\MEMORY.DMP
2010-08-22 16:17:52 0 d-----w- c:\windows\system32\appmgmt
2010-08-21 03:32:23 98816 ----a-w- c:\windows\sed.exe
2010-08-21 03:32:23 77312 ----a-w- c:\windows\MBR.exe
2010-08-21 03:32:23 256512 ----a-w- c:\windows\PEV.exe
2010-08-21 03:32:23 161792 ----a-w- c:\windows\SWREG.exe
2010-08-20 05:34:23 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-20 05:34:23 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-20 02:09:26 0 d-----w- c:\program files\The Witcher Enhanced Edition
2010-08-10 19:49:05 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-04 15:54:42 0 d-----w- c:\program files\iPod
2010-08-01 18:54:02 0 d-----w- c:\program files\MSECache

==================== Find3M ====================

2010-08-20 03:02:08 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-08-20 03:02:08 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 11:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 01:28:27 580 ----a-w- C:\RegBackup.reg
2010-07-09 22:37:10 1469544 ----a-w- c:\windows\system32\nvsvc.dll
2010-07-09 22:37:10 13939816 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 22:37:10 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 22:37:10 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-09 22:37:00 9818728 ----a-w- c:\windows\system32\nvd3dum.dll
2010-07-09 22:37:00 5107816 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-07-09 22:37:00 1625192 ----a-w- c:\windows\system32\nvapi.dll
2010-06-30 06:25:31 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-28 01:17:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSBW_01_00_00.Wdf
2010-06-28 01:17:40 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSQVGA_01_00_00.Wdf
2010-06-22 14:55:16 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-19 06:33:29 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07:18 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48:35 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-08 06:02:06 1233920 ----a-w- c:\windows\system32\msxml3.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 9:40:25.58 ===============

Attached Files



#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:23 PM

Posted 26 August 2010 - 11:32 AM

Hello again,

Is the redirect just in FireFox/IE or both?

Let's begin with Combofix, I see that you have ran it before. Can you please check for me if there is a C:\Combofix.txt log file? If it is there, please post it in your next reply in addition to running Combofix again... Delete the current Combofix.exe file if you still have it.

Download and Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

Download Combofix from any of the links below, and save it to your desktop.
Link 1
Link 2

Please refer to this page for full instructions on how to run ComboFix.
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click ComboFix.exe to start the program. Agree to the prompts.
  • When ComboFix is finished, a log report (C:\ComboFix.txt) will open. Post back with it.
Leave your computer alone while ComboFix is running.

ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.



Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 Moyira

Moyira
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:23 PM

Posted 26 August 2010 - 11:47 AM

Below is the ComboFix log from my previous run.
The redirect is in both FireFox and IE. And it has moved to Yahoo searches as well.

I will run ComboFix again and post that log when it is done.


ComboFix 10-08-21.06 - Erica 08/22/2010 11:28:54.3.4 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3070.2076 [GMT -6:00]
Running from: c:\users\Erica\Desktop\bleepingcomputer\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\TEMP\logishrd\LVPrcInj01.dll

-- Previous Run --

Infected copy of c:\windows\System32\wininit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

-- Previous Run --

Infected copy of c:\windows\System32\wininit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

--------

Infected copy of c:\windows\System32\wininit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

--------

Infected copy of c:\windows\System32\wininit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

.
((((((((((((((((((((((((( Files Created from 2010-07-22 to 2010-08-22 )))))))))))))))))))))))))))))))
.

2010-08-22 17:36 . 2010-08-22 17:38 -------- d-----w- c:\users\Erica\AppData\Local\temp
2010-08-22 17:36 . 2010-08-22 17:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-22 16:14 . 2010-08-22 16:14 -------- d-----w- c:\program files\Common Files\Java
2010-08-20 05:34 . 2010-08-22 17:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-20 05:34 . 2010-08-20 05:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-08-20 03:07 . 2010-08-20 21:37 -------- d-----w- c:\users\Erica\AppData\Local\The Witcher
2010-08-20 02:09 . 2010-08-20 16:09 -------- d-----w- c:\program files\The Witcher Enhanced Edition
2010-08-10 19:49 . 2010-06-14 06:12 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-06 01:50 . 2010-08-06 01:50 47364 ----a-w- c:\programdata\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll
2010-08-04 15:54 . 2010-08-04 15:54 -------- d-----w- c:\program files\iPod
2010-08-04 15:51 . 2010-08-04 15:51 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-08-01 18:54 . 2010-08-01 18:54 -------- d-----w- c:\program files\MSECache
2010-07-27 13:50 . 2010-08-17 23:14 -------- d-----w- c:\program files\StarCraft II
2010-07-26 22:57 . 2010-07-26 22:58 -------- d-----w- c:\users\Erica\Starcraft2
2010-07-23 20:15 . 2010-07-23 20:28 -------- d-----w- c:\program files\Mass Effect
2010-07-23 20:12 . 2010-07-23 20:12 2723264 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\software\VisualCRT\vcredist_x86.exe
2010-07-23 20:12 . 2010-07-23 20:12 484632 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\DirectX\DXSETUP.exe
2010-07-23 20:12 . 2010-07-23 20:12 74520 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\DirectX\DSETUP.dll
2010-07-23 20:12 . 2010-07-23 20:12 2248984 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\DirectX\dsetup32.dll
2010-07-23 20:11 . 2010-07-23 20:11 312176 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\data\Mass Effect Uninstaller.exe
2010-07-23 20:11 . 2010-07-23 20:11 386312 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\data\Mass Effect ™_code.exe
2010-07-23 20:05 . 2010-07-23 20:05 105218 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\data\DataSetup.exe
2010-07-23 20:04 . 2010-07-23 20:04 1696296 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\Setup.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-22 17:37 . 2010-04-20 05:09 -------- d-----w- c:\programdata\NVIDIA
2010-08-22 17:00 . 2010-05-08 01:40 -------- d-----w- c:\users\Erica\AppData\Roaming\Skype
2010-08-22 16:57 . 2010-04-20 15:28 -------- d-----w- c:\program files\Yahoo!
2010-08-22 16:17 . 2010-05-08 01:34 -------- d-----r- c:\program files\Skype
2010-08-22 16:14 . 2010-05-26 16:30 -------- d-----w- c:\program files\Java
2010-08-22 15:53 . 2010-05-08 01:41 -------- d-----w- c:\users\Erica\AppData\Roaming\skypePM
2010-08-20 04:32 . 2010-04-21 15:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-20 03:02 . 2010-08-20 02:30 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-08-20 03:02 . 2010-08-20 02:30 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-08-16 18:47 . 2010-04-22 02:22 -------- d-----w- c:\program files\Common Files\BioWare
2010-08-06 01:48 . 2010-04-20 06:04 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-08-05 19:11 . 2010-04-22 02:22 -------- d-----w- c:\program files\Dragon Age
2010-08-05 19:09 . 2010-04-22 02:38 -------- d-----w- c:\program files\Electronic Arts
2010-08-04 15:54 . 2010-06-17 14:17 -------- d-----w- c:\program files\iTunes
2010-08-04 15:54 . 2010-04-20 05:47 -------- d-----w- c:\program files\Common Files\Apple
2010-07-29 06:30 . 2010-08-10 19:48 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-10 19:48 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-27 13:59 . 2010-05-07 21:53 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-07-25 02:17 . 2010-07-25 02:17 55994 ----a-w- c:\programdata\SPL7360.tmp
2010-07-23 20:27 . 2010-04-22 02:36 -------- d-----w- c:\programdata\Media Center Programs
2010-07-22 03:55 . 2010-05-05 23:30 -------- d-----w- c:\program files\Blizzard
2010-07-21 03:50 . 2010-07-12 22:18 -------- d-----w- c:\users\Erica\AppData\Roaming\DivX
2010-07-17 11:00 . 2010-05-26 16:31 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 01:28 . 2010-07-16 01:28 580 ----a-w- C:\RegBackup.reg
2010-07-16 00:23 . 2010-07-16 00:23 -------- d-----w- c:\program files\Activision
2010-07-12 22:38 . 2010-07-12 22:38 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-12 22:17 . 2010-07-12 22:17 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-07-12 22:17 . 2010-07-12 22:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-07-12 22:17 . 2010-07-12 22:17 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-07-12 22:13 . 2010-07-12 22:18 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-07-12 22:13 . 2010-07-12 22:18 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-07-09 20:16 . 2010-07-09 20:16 -------- d-----w- c:\program files\Microsoft Works
2010-07-02 17:57 . 2010-04-22 02:37 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-02 17:57 . 2010-07-02 17:57 53632 ----a-w- c:\users\Erica\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-07-02 17:57 . 2010-04-22 02:37 53632 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-30 06:25 . 2010-08-10 19:48 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-28 01:17 . 2010-06-28 01:17 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSBW_01_00_00.Wdf
2010-06-28 01:17 . 2010-06-28 01:17 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSQVGA_01_00_00.Wdf
2010-06-28 01:17 . 2010-06-28 01:17 -------- d-----w- c:\programdata\Logitech
2010-06-28 01:17 . 2010-05-07 23:24 -------- d-----w- c:\program files\Logitech
2010-06-26 09:01 . 2010-05-21 02:44 -------- d-----w- c:\program files\Microsoft.NET
2010-06-24 04:01 . 2010-05-25 17:45 -------- d-----w- c:\users\Erica\AppData\Roaming\WinFF
2010-06-22 14:55 . 2010-06-22 14:55 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 14:55 . 2010-04-20 05:31 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 14:55 . 2010-04-20 05:31 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-22 02:47 . 2010-08-10 19:48 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-22 02:47 . 2010-08-10 19:48 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-22 02:47 . 2010-08-10 19:48 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-19 06:33 . 2010-08-10 19:48 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33 . 2010-08-10 19:48 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23 . 2010-08-10 19:48 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07 . 2010-08-10 19:48 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-08-10 19:48 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-12 16:21 . 2010-06-12 15:09 6667344 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Support\EADM\eadm-installer.exe
2010-06-12 15:42 . 2010-06-12 15:08 2083600 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\Sims3EP02GDF.dll
2010-06-12 15:42 . 2010-06-12 15:08 365840 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\paul.dll
2010-06-12 15:42 . 2010-06-12 15:08 107792 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\S3Launcher.exe
2010-06-12 15:41 . 2010-06-12 15:08 3237136 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\EAWebkit.dll
2010-06-12 15:09 . 2010-06-12 15:08 319488 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\_Setup.dll
2010-06-12 15:09 . 2010-06-12 15:08 398608 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Sims3EP02Setup.exe
2010-06-12 15:09 . 2010-06-12 15:08 555520 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\ISSetup.dll
2010-06-12 15:09 . 2010-06-12 15:08 54544 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Autorun.exe
2010-06-08 06:02 . 2010-08-10 19:48 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-06-03 04:21 . 2010-05-19 04:05 4277016 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2010-06-03 04:21 . 2010-05-19 04:04 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2010-06-03 03:46 . 2010-06-03 02:37 65765088 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\patch\DragonAge1.03.exe
2010-06-03 02:37 . 2010-06-03 02:37 554214 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\data\DataSetup.exe
2010-06-03 02:37 . 2010-06-03 02:37 390416 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\data\Dragon Age Origins Awakening_code.exe
2010-06-03 02:37 . 2010-06-03 02:37 126528 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\data\DAO_UpdateAddinsXml.exe
2010-06-03 02:37 . 2010-06-03 02:37 1262768 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\Setup.exe
2010-06-03 02:37 . 2010-06-03 02:37 1246440 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\autorun.exe
2010-06-01 16:05 . 2010-04-20 05:31 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-27 07:24 . 2010-06-10 00:41 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49 . 2010-06-10 00:41 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-25 17:57 . 2010-05-25 17:57 311 ----a-w- c:\users\Erica\AppData\Roaming\WinFF\ff100525115753.bat
2010-05-25 17:48 . 2010-05-25 17:48 530 ----a-w- c:\users\Erica\AppData\Roaming\WinFF\ff100525114813.bat
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 16:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lxdqmon.exe"="c:\program files\Lexmark Z2400 Series\lxdqmon.exe" [2009-10-26 672424]
"lxdqamon"="c:\program files\Lexmark Z2400 Series\lxdqamon.exe" [2009-10-26 16040]
"RivaTuner"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" [2009-08-22 24576]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" [2009-08-22 24576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13683816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-01-19 8452640]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-11 1468256]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-02-18 357448]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-02-18 1573448]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-02-18 3203144]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Erica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]
path=c:\users\Erica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
backup=c:\windows\pss\CurseClientStartup.ccip.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Erica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\Erica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aim"="c:\program files\AIM\aim.exe" /d locale=en-US
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" -bootmode
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-04-19 430152]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-20 1343400]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Erica\Desktop\Real Temp\WinRing0.sys [2010-04-23 14416]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-04-20 52872]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-06-22 216400]
S1 AvgTdiX;AVG Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-06-22 243024]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe [2007-11-28 589824]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2009-11-11 22384]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-01-25 16168]

.
Contents of the 'Scheduled Tasks' folder

2010-08-22 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2010-08-20 21:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Erica\AppData\Roaming\Mozilla\Firefox\Profiles\2co3t1dl.default\
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Erica\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-MSSMSGS - winorf32.rom


.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2316427597-1100130316-3964573790-1001\Software\SecuROM\License information*]
"datasecu"=hex:62,16,5f,92,50,68,c4,54,8b,fb,10,f8,b6,ca,88,2b,2d,cc,e3,e9,b4,
ea,60,d2,3f,d7,e6,75,b1,82,28,5b,bc,18,6f,6b,d5,1e,01,8a,05,39,48,9f,8a,e1,\
"rkeysecu"=hex:42,12,4e,c5,4a,ac,a2,9d,83,fa,0d,9e,fd,5b,c0,43

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WUDFHost.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\windows\system32\taskhost.exe
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\conhost.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Lexmark Z2400 Series\lxdqMsdMon.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\Windows Media Player\WMPSideShowGadget.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe
c:\program files\Windows Media Player\wmplayer.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDPop3.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDMedia.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDRSS.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Completion time: 2010-08-22 11:42:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-22 17:42

Pre-Run: 292,025,593,856 bytes free
Post-Run: 291,923,755,008 bytes free

- - End Of File - - 820F6DB1D6D751374A19074DE64C20E0

Edited by extremeboy, 27 August 2010 - 11:32 AM.
Edited to Remove E-mail


#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:23 PM

Posted 26 August 2010 - 11:55 AM

Okay. Thanks for the update. I will hear from you soon then.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 Moyira

Moyira
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:23 PM

Posted 26 August 2010 - 09:52 PM

Here is the newest CF log


ComboFix 10-08-26.02 - Erica 08/26/2010 20:34:11.4.4 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3070.1947 [GMT -6:00]
Running from: c:\users\Erica\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Some 3rd party browsers were infected and had to be removed. Do not be alarmed.


c:\program files\mozilla Firefox\firefox.exe

Infected copy of c:\windows\system32\wininit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

Infected copy of c:\program files\internet explorer\iexplore.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe

.
((((((((((((((((((((((((( Files Created from 2010-07-27 to 2010-08-27 )))))))))))))))))))))))))))))))
.

2010-08-27 02:40 . 2010-08-27 02:43 -------- d-----w- c:\users\Erica\AppData\Local\temp
2010-08-27 02:40 . 2010-08-27 02:40 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-27 02:40 . 2010-08-27 02:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-27 02:32 . 2010-08-27 02:33 -------- d-----w- C:\32788R22FWJFW
2010-08-25 17:39 . 2010-08-25 17:39 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-08-25 17:38 . 2010-07-09 22:37 56936 ----a-w- c:\windows\system32\OpenCL.dll
2010-08-25 17:38 . 2010-07-09 22:37 11008040 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-08-25 17:38 . 2010-07-09 22:37 4553832 ----a-w- c:\windows\system32\nvcuda.dll
2010-08-25 17:38 . 2010-07-09 22:37 314984 ----a-w- c:\windows\system32\nvdecodemft.dll
2010-08-25 17:38 . 2010-07-09 22:37 2892904 ----a-w- c:\windows\system32\nvcuvid.dll
2010-08-25 17:38 . 2010-07-09 22:37 2506344 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-08-25 17:38 . 2010-07-09 22:37 14092904 ----a-w- c:\windows\system32\nvoglv32.dll
2010-08-25 17:38 . 2010-07-09 22:37 236136 ----a-w- c:\windows\system32\nvcod1922.dll
2010-08-25 17:38 . 2010-07-09 22:37 236136 ----a-w- c:\windows\system32\nvcod.dll
2010-08-25 17:38 . 2010-07-09 22:37 10267240 ----a-w- c:\windows\system32\nvcompiler.dll
2010-08-25 14:57 . 2010-04-07 07:10 571904 ----a-w- c:\windows\system32\oleaut32.dll
2010-08-22 16:14 . 2010-08-22 16:14 -------- d-----w- c:\program files\Common Files\Java
2010-08-20 05:34 . 2010-08-22 17:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-20 05:34 . 2010-08-20 05:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-08-20 03:07 . 2010-08-20 21:37 -------- d-----w- c:\users\Erica\AppData\Local\The Witcher
2010-08-20 02:09 . 2010-08-20 16:09 -------- d-----w- c:\program files\The Witcher Enhanced Edition
2010-08-10 19:49 . 2010-06-14 06:12 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-06 01:50 . 2010-08-06 01:50 47364 ----a-w- c:\programdata\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll
2010-08-04 15:54 . 2010-08-04 15:54 -------- d-----w- c:\program files\iPod
2010-08-04 15:51 . 2010-08-04 15:51 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-08-01 18:54 . 2010-08-01 18:54 -------- d-----w- c:\program files\MSECache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-27 02:43 . 2010-04-20 05:09 -------- d-----w- c:\programdata\NVIDIA
2010-08-25 17:40 . 2010-04-20 05:09 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-22 17:00 . 2010-05-08 01:40 -------- d-----w- c:\users\Erica\AppData\Roaming\Skype
2010-08-22 16:57 . 2010-04-20 15:28 -------- d-----w- c:\program files\Yahoo!
2010-08-22 16:17 . 2010-05-08 01:34 -------- d-----r- c:\program files\Skype
2010-08-22 16:14 . 2010-05-26 16:30 -------- d-----w- c:\program files\Java
2010-08-22 15:53 . 2010-05-08 01:41 -------- d-----w- c:\users\Erica\AppData\Roaming\skypePM
2010-08-20 04:32 . 2010-04-21 15:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-20 03:02 . 2010-08-20 02:30 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-08-20 03:02 . 2010-08-20 02:30 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-08-17 23:14 . 2010-07-27 13:50 -------- d-----w- c:\program files\StarCraft II
2010-08-16 18:47 . 2010-04-22 02:22 -------- d-----w- c:\program files\Common Files\BioWare
2010-08-06 01:48 . 2010-04-20 06:04 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-08-05 19:11 . 2010-04-22 02:22 -------- d-----w- c:\program files\Dragon Age
2010-08-05 19:09 . 2010-04-22 02:38 -------- d-----w- c:\program files\Electronic Arts
2010-08-04 15:54 . 2010-06-17 14:17 -------- d-----w- c:\program files\iTunes
2010-08-04 15:54 . 2010-04-20 05:47 -------- d-----w- c:\program files\Common Files\Apple
2010-07-29 06:30 . 2010-08-10 19:48 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-10 19:48 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-27 13:59 . 2010-05-07 21:53 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-07-25 02:17 . 2010-07-25 02:17 55994 ----a-w- c:\programdata\SPL7360.tmp
2010-07-23 20:28 . 2010-07-23 20:15 -------- d-----w- c:\program files\Mass Effect
2010-07-23 20:27 . 2010-04-22 02:36 -------- d-----w- c:\programdata\Media Center Programs
2010-07-23 20:12 . 2010-07-23 20:12 2723264 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\software\VisualCRT\vcredist_x86.exe
2010-07-23 20:12 . 2010-07-23 20:12 484632 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\DirectX\DXSETUP.exe
2010-07-23 20:12 . 2010-07-23 20:12 74520 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\DirectX\DSETUP.dll
2010-07-23 20:12 . 2010-07-23 20:12 2248984 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\DirectX\dsetup32.dll
2010-07-23 20:11 . 2010-07-23 20:11 312176 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\data\Mass Effect Uninstaller.exe
2010-07-23 20:11 . 2010-07-23 20:11 386312 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\data\Mass Effect ™_code.exe
2010-07-23 20:05 . 2010-07-23 20:05 105218 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\data\DataSetup.exe
2010-07-23 20:04 . 2010-07-23 20:04 1696296 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\mass_effect\Setup.exe
2010-07-22 03:55 . 2010-05-05 23:30 -------- d-----w- c:\program files\Blizzard
2010-07-21 03:50 . 2010-07-12 22:18 -------- d-----w- c:\users\Erica\AppData\Roaming\DivX
2010-07-17 11:00 . 2010-05-26 16:31 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 01:28 . 2010-07-16 01:28 580 ----a-w- C:\RegBackup.reg
2010-07-16 00:23 . 2010-07-16 00:23 -------- d-----w- c:\program files\Activision
2010-07-12 22:38 . 2010-07-12 22:38 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-12 22:17 . 2010-07-12 22:17 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-07-12 22:17 . 2010-07-12 22:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-07-12 22:17 . 2010-07-12 22:17 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-07-12 22:13 . 2010-07-12 22:18 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-07-12 22:13 . 2010-07-12 22:18 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-07-09 22:37 . 2010-07-09 22:37 1469544 ----a-w- c:\windows\system32\nvsvc.dll
2010-07-09 22:37 . 2010-07-09 22:37 13939816 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 22:37 . 2010-07-09 22:37 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 22:37 . 2010-07-09 22:37 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-09 22:37 . 2010-08-25 17:38 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-07-09 22:37 . 2010-04-20 05:33 9818728 ----a-w- c:\windows\system32\nvd3dum.dll
2010-07-09 22:37 . 2010-01-12 18:03 1625192 ----a-w- c:\windows\system32\nvapi.dll
2010-07-09 22:37 . 2009-07-13 22:09 5107816 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-07-09 20:16 . 2010-07-09 20:16 -------- d-----w- c:\program files\Microsoft Works
2010-07-02 17:57 . 2010-04-22 02:37 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-02 17:57 . 2010-07-02 17:57 53632 ----a-w- c:\users\Erica\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-07-02 17:57 . 2010-04-22 02:37 53632 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-30 06:25 . 2010-08-10 19:48 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-22 14:55 . 2010-06-22 14:55 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 14:55 . 2010-04-20 05:31 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 14:55 . 2010-04-20 05:31 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-22 02:47 . 2010-08-10 19:48 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-22 02:47 . 2010-08-10 19:48 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-22 02:47 . 2010-08-10 19:48 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-19 06:33 . 2010-08-10 19:48 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33 . 2010-08-10 19:48 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23 . 2010-08-10 19:48 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07 . 2010-08-10 19:48 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-08-10 19:48 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-12 16:21 . 2010-06-12 15:09 6667344 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Support\EADM\eadm-installer.exe
2010-06-12 15:42 . 2010-06-12 15:08 2083600 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\Sims3EP02GDF.dll
2010-06-12 15:42 . 2010-06-12 15:08 365840 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\paul.dll
2010-06-12 15:42 . 2010-06-12 15:08 107792 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\S3Launcher.exe
2010-06-12 15:41 . 2010-06-12 15:08 3237136 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Game\Bin\EAWebkit.dll
2010-06-12 15:09 . 2010-06-12 15:08 319488 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\_Setup.dll
2010-06-12 15:09 . 2010-06-12 15:08 398608 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Sims3EP02Setup.exe
2010-06-12 15:09 . 2010-06-12 15:08 555520 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\ISSetup.dll
2010-06-12 15:09 . 2010-06-12 15:08 54544 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\sims3_ep02_dd\Autorun.exe
2010-06-08 06:02 . 2010-08-10 19:48 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-06-03 04:21 . 2010-05-19 04:05 4277016 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2010-06-03 04:21 . 2010-05-19 04:04 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2010-06-03 03:46 . 2010-06-03 02:37 65765088 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\patch\DragonAge1.03.exe
2010-06-03 02:37 . 2010-06-03 02:37 554214 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\data\DataSetup.exe
2010-06-03 02:37 . 2010-06-03 02:37 390416 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\data\Dragon Age Origins Awakening_code.exe
2010-06-03 02:37 . 2010-06-03 02:37 126528 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\data\DAO_UpdateAddinsXml.exe
2010-06-03 02:37 . 2010-06-03 02:37 1262768 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\Setup.exe
2010-06-03 02:37 . 2010-06-03 02:37 1246440 ----a-w- c:\programdata\Electronic Arts\EA Core\cache\{ }\dragonage_ep1_eu1\autorun.exe
2010-06-01 16:05 . 2010-04-20 05:31 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-08-22_17.38.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:55 . 2010-08-22 17:39 28888 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-08-27 02:44 28888 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:50 . 2010-08-25 17:39 86016 c:\windows\System32\DriverStore\infpub.dat
- 2009-07-14 04:50 . 2010-06-28 01:18 86016 c:\windows\System32\DriverStore\infpub.dat
+ 2010-08-25 17:38 . 2010-07-09 22:37 56936 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\OpenCL.dll
- 2010-04-20 05:03 . 2010-08-21 02:05 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-20 05:03 . 2010-08-26 15:39 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-04-20 05:03 . 2010-08-21 02:05 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-20 05:03 . 2010-08-26 15:39 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2010-08-26 15:39 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2010-08-21 02:05 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-04-20 04:29 . 2010-08-27 02:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-04-20 04:29 . 2010-08-22 17:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:34 . 2010-08-25 17:48 83208 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2010-04-20 04:29 . 2010-08-27 02:44 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-20 04:29 . 2010-08-22 17:38 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-20 04:29 . 2010-08-27 02:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-04-20 04:29 . 2010-08-22 17:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-04-20 04:29 . 2010-08-27 02:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-04-20 04:29 . 2010-08-22 17:38 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-04-21 05:00 . 2010-08-22 17:01 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-21 05:00 . 2010-08-25 18:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-21 05:00 . 2010-08-25 18:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-04-21 05:00 . 2010-08-22 17:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-04-21 05:00 . 2010-08-22 17:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-04-21 05:00 . 2010-08-25 18:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2010-04-20 04:29 . 2010-08-22 17:38 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-20 04:29 . 2010-08-27 02:44 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-20 04:29 . 2010-08-22 17:38 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-04-20 04:29 . 2010-08-27 02:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-08-25 17:40 . 2010-08-25 17:40 10134 c:\windows\Installer\{DA97BDF9-BC72-46FD-8E76-427F2BB951EE}\ARPPRODUCTICON.exe
- 2010-04-20 05:35 . 2010-04-20 05:35 10134 c:\windows\Installer\{DA97BDF9-BC72-46FD-8E76-427F2BB951EE}\ARPPRODUCTICON.exe
+ 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.20749_none_0cb171a26c998e15\AcRes.dll
+ 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.16629_none_0c3d74af536bb669\AcRes.dll
+ 2010-04-20 04:30 . 2010-08-25 18:09 6476 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2316427597-1100130316-3964573790-1001_UserData.bin
- 2010-08-22 17:26 . 2010-08-22 17:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-08-25 17:46 . 2010-08-27 02:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-08-25 17:46 . 2010-08-27 02:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-08-22 17:26 . 2010-08-22 17:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-08-25 14:57 . 2010-04-07 07:33 571904 c:\windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.1.7600.20685_none_bd60214875eb62b1\oleaut32.dll
+ 2010-08-25 14:57 . 2010-04-07 07:10 571904 c:\windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.1.7600.16567_none_bcee24e95cbbbdb3\oleaut32.dll
+ 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20749_none_0cb572ca6c95f371\AcXtrnal.dll
+ 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20749_none_0cb572ca6c95f371\AcLayers.dll
+ 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16629_none_0c4175d753681bc5\AcXtrnal.dll
+ 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16629_none_0c4175d753681bc5\AcLayers.dll
+ 2010-08-27 02:43 . 2009-10-07 07:47 109080 c:\windows\temp\logishrd\LVPrcInj01.dll
- 2010-08-22 17:37 . 2010-08-22 17:38 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
+ 2010-04-20 15:15 . 2010-08-26 15:36 385952 c:\windows\System32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
- 2009-07-14 04:50 . 2010-06-28 01:18 143360 c:\windows\System32\DriverStore\infstrng.dat
+ 2009-07-14 04:50 . 2010-08-25 17:39 143360 c:\windows\System32\DriverStore\infstrng.dat
- 2009-07-14 04:50 . 2010-06-28 01:17 143360 c:\windows\System32\DriverStore\infstor.dat
+ 2009-07-14 04:50 . 2010-08-25 17:39 143360 c:\windows\System32\DriverStore\infstor.dat
+ 2010-08-25 17:39 . 2010-07-09 22:37 604776 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvudisp.exe
+ 2010-08-25 17:38 . 2010-07-09 22:37 261268 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvdrsdb.bin
+ 2010-08-25 17:38 . 2010-07-09 22:37 314984 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvdecodemft.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 236136 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvcod.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 795104 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\dpinst.exe
+ 2010-08-25 17:39 . 2010-07-09 22:37 156264 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\dbInstaller.exe
+ 2010-04-20 05:07 . 2010-08-25 18:07 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 02:03 . 2010-08-26 10:29 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:03 . 2010-08-22 17:18 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2010-08-25 17:38 . 2010-07-09 22:37 5107816 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvwgf2um.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 9818728 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvd3dum.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 2892904 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvcuvid.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 2506344 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvcuvenc.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 4553832 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvcuda.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 1625192 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvapi.dll
+ 2009-07-14 04:34 . 2010-08-25 17:48 3897560 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:34 . 2010-08-11 02:25 3897560 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 07:18 . 2010-08-25 14:56 23633541 c:\windows\winsxs\ManifestCache\e4e8be02b8fae2a7_blobs.bin
+ 2010-08-25 17:38 . 2010-07-09 22:37 14092904 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvoglv32.dll
+ 2010-08-25 17:38 . 2010-07-09 22:37 11008040 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvlddmkm.sys
+ 2010-08-25 17:39 . 2010-07-09 22:37 22792952 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\NvCplSetupEng.exe
+ 2010-08-25 17:38 . 2010-07-09 22:37 10267240 c:\windows\System32\DriverStore\FileRepository\nv_disp.inf_x86_neutral_c04de2a289110631\nvcompiler.dll
+ 2010-07-14 16:59 . 2010-07-14 16:59 27267072 c:\windows\Installer\f746f48.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 16:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lxdqmon.exe"="c:\program files\Lexmark Z2400 Series\lxdqmon.exe" [2009-10-26 672424]
"lxdqamon"="c:\program files\Lexmark Z2400 Series\lxdqamon.exe" [2009-10-26 16040]
"RivaTuner"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" [2009-08-22 24576]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" [2009-08-22 24576]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-01-19 8452640]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-11 1468256]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-02-18 357448]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-02-18 1573448]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-02-18 3203144]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Erica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]
path=c:\users\Erica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
backup=c:\windows\pss\CurseClientStartup.ccip.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Erica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\Erica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aim"="c:\program files\AIM\aim.exe" /d locale=en-US
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" -bootmode
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-04-19 430152]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-20 1343400]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Erica\Desktop\Real Temp\WinRing0.sys [2010-04-23 14416]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-04-20 52872]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-06-22 216400]
S1 AvgTdiX;AVG Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-06-22 243024]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe [2007-11-28 589824]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2009-11-11 22384]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-01-25 16168]

.
Contents of the 'Scheduled Tasks' folder

2010-08-26 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2010-08-20 21:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2316427597-1100130316-3964573790-1001\Software\SecuROM\License information*]
"datasecu"=hex:62,16,5f,92,50,68,c4,54,8b,fb,10,f8,b6,ca,88,2b,2d,cc,e3,e9,b4,
ea,60,d2,3f,d7,e6,75,b1,82,28,5b,bc,18,6f,6b,d5,1e,01,8a,05,39,48,9f,8a,e1,\
"rkeysecu"=hex:42,12,4e,c5,4a,ac,a2,9d,83,fa,0d,9e,fd,5b,c0,43

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\nvvsvc.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\conhost.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Lexmark Z2400 Series\lxdqMsdMon.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDPop3.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDMedia.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDRSS.exe
c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Windows Media Player\WMPSideShowGadget.exe
c:\windows\system32\taskhost.exe
c:\program files\Windows Media Player\wmplayer.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Completion time: 2010-08-26 20:47:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-27 02:47
ComboFix2.txt 2010-08-22 17:42

Pre-Run: 289,405,247,488 bytes free
Post-Run: 289,348,440,064 bytes free

- - End Of File - - D92ED56AE89AFAF495F49320D4E9B08C

Edited by extremeboy, 27 August 2010 - 11:33 AM.
remove e-mail


#8 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:23 PM

Posted 27 August 2010 - 11:24 AM

Hello again,

That looks better. Appears you were infected with one of the more newer browser infections.

Could you attach the C:\Qoobox\Combofix-quarantined-files.txt text file in your next reply.

Let me know if the redirects still occur in Internet Explorer. FireFox may not be working now, due to the firefox application being removed. We can re-install that afterwards if you don't mind.

Now, could you run a scan with Malwarebytes.

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#9 Moyira

Moyira
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:23 PM

Posted 27 August 2010 - 11:39 AM

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4489

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

8/27/2010 10:37:19 AM
mbam-log-2010-08-27 (10-37-19).txt

Scan type: Quick scan
Objects scanned: 139171
Time elapsed: 6 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Attached Files



#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:23 PM

Posted 27 August 2010 - 11:59 AM

Could you answer my question and I'll come up with another fix soon, once I come back home soon.

Thanks.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 Moyira

Moyira
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:23 PM

Posted 27 August 2010 - 12:01 PM

The redirects don't seem to be around anymore! I reinstalled Firefox, and I checked in both FF and IE.

Awesome! You rock!

#12 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:23 PM

Posted 27 August 2010 - 02:16 PM

You're welcome.

Before we end of though, I would like you to upload the following files to a submission channel.

Submit file sample
  • Open to the Submission Channel.
  • Under Link to topic where this file was requested, input:
    CODE
    http://www.bleepingcomputer.com/forums/topic341659.html
  • Click Browse and select the following files and upload each of them one at a time:
    1. C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\firefox.exe.vir
    2. C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\iexplore.exe.vir
    3. C:\Qoobox\Quarantine\C\Windows\System32\wininit.exe.vir
  • Under the comments section, say that Extremeboy asked for the submission.
  • Then select Send File to send it
  • After that you should get a confirmation if it was uploaded successfully.

  • Let me know once you have completed that.

    Then... Proceed with an online scan to confirm.

    Run ESET Online Scan
    1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
    2. Click the button.
    3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      1. Click on to download the ESET Smart Installer. Save it to your desktop.
      2. Double click on the icon on your desktop.
    4. Check
    5. Click the button.
    6. Accept any security warnings from your browser.
    7. Check
    8. Push the Start button.
    9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    10. When the scan completes, push
    11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    12. Push the button.
    13. Push
    You can refer to this animation by neomage if needed.

    Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

    Thanks.

    With Regards,
    Extremeboy
    Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

    If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

    The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

    #13 Moyira

    Moyira
    • Topic Starter

    • Members
    • 9 posts
    • OFFLINE
    •  
    • Local time:05:23 PM

    Posted 27 August 2010 - 03:40 PM

    Submitted those files. Running ESET right now.

    #14 Moyira

    Moyira
    • Topic Starter

    • Members
    • 9 posts
    • OFFLINE
    •  
    • Local time:05:23 PM

    Posted 27 August 2010 - 04:24 PM

    DDS Logs and Scan Logs below, Attach is attached



    DDS (Ver_10-03-17.01) - NTFSx86
    Run by Erica at 15:20:19.12 on Fri 08/27/2010
    Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
    Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3070.1651 [GMT -6:00]

    SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Windows\system32\lxdqcoms.exe
    C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Windows\system32\Dwm.exe
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgam.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\Lexmark Z2400 Series\lxdqMsdMon.exe
    C:\Program Files\AVG\AVG9\avgtray.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
    C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
    C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
    C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
    C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
    C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
    C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
    C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
    C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\Explorer.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\AIM\aim.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Users\Erica\Desktop\bleepingcomputer\dds.scr
    C:\Windows\system32\conhost.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
    BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [lxdqmon.exe] "c:\program files\lexmark z2400 series\lxdqmon.exe"
    mRun: [lxdqamon] "c:\program files\lexmark z2400 series\lxdqamon.exe"
    mRun: [RivaTuner] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition\RivaTunerWrapper.exe" /T
    mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
    mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition\RivaTunerWrapper.exe" /S
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
    mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
    mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
    mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
    mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
    mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    Trusted Zone: real.com\rhap-app-4-0
    Trusted Zone: real.com\rhapreg
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    AppInit_DLLs: c:\windows\system32\avgrsstx.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\erica\appdata\roaming\mozilla\firefox\profiles\2co3t1dl.default\
    FF - prefs.js: network.proxy.type - 4
    FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\erica\appdata\roaming\facebook\npfbplugin_1_0_3.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
    c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-4-19 52872]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-4-19 216400]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-4-19 29584]
    R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-4-19 243024]
    R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-6-22 921952]
    R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-22 308136]
    R2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe -service --> c:\windows\system32\lxdqcoms.exe -service [?]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-8-19 1153368]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-7-9 248936]
    R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
    R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-3-4 277536]
    R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2010-1-24 16168]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-4-19 430152]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
    S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
    S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-19 1343400]
    S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\erica\desktop\real temp\WinRing0.sys [2008-7-26 14416]

    =============== Created Last 30 ================

    2010-08-27 19:24:52 0 d-----w- c:\program files\ESET
    2010-08-27 16:30:00 0 d-----w- c:\users\erica\appdata\roaming\Malwarebytes
    2010-08-27 16:29:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-27 16:29:37 0 d-----w- c:\programdata\Malwarebytes
    2010-08-27 16:29:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-08-27 16:29:36 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-08-27 02:43:36 0 d-----w- C:\$RECYCLE.BIN
    2010-08-25 17:39:54 0 d-----w- c:\programdata\NVIDIA Corporation
    2010-08-25 17:38:59 56936 ----a-w- c:\windows\system32\OpenCL.dll
    2010-08-25 17:38:59 11008040 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
    2010-08-25 17:38:59 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
    2010-08-25 17:38:57 4553832 ----a-w- c:\windows\system32\nvcuda.dll
    2010-08-25 17:38:57 314984 ----a-w- c:\windows\system32\nvdecodemft.dll
    2010-08-25 17:38:57 2892904 ----a-w- c:\windows\system32\nvcuvid.dll
    2010-08-25 17:38:57 2506344 ----a-w- c:\windows\system32\nvcuvenc.dll
    2010-08-25 17:38:57 14092904 ----a-w- c:\windows\system32\nvoglv32.dll
    2010-08-25 17:38:55 236136 ----a-w- c:\windows\system32\nvcod1922.dll
    2010-08-25 17:38:55 236136 ----a-w- c:\windows\system32\nvcod.dll
    2010-08-25 17:38:55 10267240 ----a-w- c:\windows\system32\nvcompiler.dll
    2010-08-25 14:57:00 571904 ----a-w- c:\windows\system32\oleaut32.dll
    2010-08-22 16:58:01 423201774 ----a-w- c:\windows\MEMORY.DMP
    2010-08-22 16:17:52 0 d-----w- c:\windows\system32\appmgmt
    2010-08-21 03:32:23 98816 ----a-w- c:\windows\sed.exe
    2010-08-21 03:32:23 77312 ----a-w- c:\windows\MBR.exe
    2010-08-21 03:32:23 256512 ----a-w- c:\windows\PEV.exe
    2010-08-21 03:32:23 161792 ----a-w- c:\windows\SWREG.exe
    2010-08-20 05:34:23 0 d-----w- c:\programdata\Spybot - Search & Destroy
    2010-08-20 05:34:23 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-08-20 02:09:26 0 d-----w- c:\program files\The Witcher Enhanced Edition
    2010-08-10 19:49:05 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2010-08-04 15:54:42 0 d-----w- c:\program files\iPod
    2010-08-01 18:54:02 0 d-----w- c:\program files\MSECache

    ==================== Find3M ====================

    2010-08-20 03:02:08 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
    2010-08-20 03:02:08 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
    2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
    2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
    2010-07-17 11:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
    2010-07-16 01:28:27 580 ----a-w- C:\RegBackup.reg
    2010-07-09 22:37:10 1469544 ----a-w- c:\windows\system32\nvsvc.dll
    2010-07-09 22:37:10 13939816 ----a-w- c:\windows\system32\nvcpl.dll
    2010-07-09 22:37:10 129640 ----a-w- c:\windows\system32\nvvsvc.exe
    2010-07-09 22:37:10 110696 ----a-w- c:\windows\system32\nvmctray.dll
    2010-07-09 22:37:00 9818728 ----a-w- c:\windows\system32\nvd3dum.dll
    2010-07-09 22:37:00 5107816 ----a-w- c:\windows\system32\nvwgf2um.dll
    2010-07-09 22:37:00 1625192 ----a-w- c:\windows\system32\nvapi.dll
    2010-06-30 06:25:31 978432 ----a-w- c:\windows\system32\wininet.dll
    2010-06-22 14:55:16 12536 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-06-19 06:33:29 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2010-06-19 06:33:29 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
    2010-06-19 06:23:50 37376 ----a-w- c:\windows\system32\rtutils.dll
    2010-06-19 04:07:18 2326016 ----a-w- c:\windows\system32\win32k.sys
    2010-06-16 05:48:35 224256 ----a-w- c:\windows\system32\schannel.dll
    2010-06-08 06:02:06 1233920 ----a-w- c:\windows\system32\msxml3.dll
    2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
    2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
    2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

    ============= FINISH: 15:20:53.70 ===============

    ESETScan

    C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\iexplore.exe.vir Win32/Bamital.DX trojan deleted - quarantined
    C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\firefox.exe.vir Win32/Bamital.DX trojan deleted - quarantined
    C:\Qoobox\Quarantine\C\Windows\System32\wininit.exe.vir Win32/Bamital.DX trojan deleted - quarantined
    C:\Users\Erica\AppData\Local\VirtualStore\Windows\System32\winorf32.rom a variant of Win32/Nebuler.BD trojan cleaned by deleting - quarantined
    C:\Users\Erica\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\85b668d-54a5dffb multiple threats deleted - quarantined
    C:\Users\Erica\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\588e0139-2de56936 multiple threats deleted - quarantined

    Attached Files



    #15 extremeboy

    extremeboy

    • Malware Response Team
    • 12,975 posts
    • OFFLINE
    •  
    • Gender:Male
    • Local time:08:23 PM

    Posted 28 August 2010 - 12:57 PM

    Update Java to Version 6 Update 21

    Important Note: Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
    • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
    • Look for "JDK 6 Update 21 (JDK or JRE)".
    • Click the "Download JRE" button to the right.
    • Select your Platform: "Windows".
    • Select your Language: "Multi-language".
    • Read the License Agreement, and then check the box that says: "I agree to the Java SE...License Agreement".
    • Click Continue and the page will refresh.
    • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
    • Close any programs you may have running - especially your web browser.
    Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
    • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u21-windows-i586-s.exe to install the newest version.
    • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
    • When the Java Setup - Welcome window opens, click the Install > button.
    • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
    -- Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
    -- Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


    Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer.

    ---

    Please follow/read the steps below to remove the tools we used and for some more information. smile.gif


    Uninstall ComboFix

    Remove Combofix now that we're done with it.
    • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
    • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
    • Please follow the prompts to uninstall Combofix.
    • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
    This will uninstall Combofix and anything assoicated with it.

    Download and Run OTC

    We will now remove the tools we used during this fix using OTC.
    • Download OTC by OldTimer and save it to your desktop.
    • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
    • Then Click the big button.
    • You will get a prompt saying "Being Cleanup Process". Please select Yes.
    • Restart your computer when prompted.


    Congratulations! You now appear clean! specool.gif

    Now that you are clean, please follow and read some of the prevention tips >over here<. Is your system a bit slow? If so, try some of the points and things suggested here.



    If you have no more questions, comments or problems please tell us, so we can close off the topic.

    Thanks.

    With Regards,
    Extremeboy
    Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

    If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

    The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users