Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google redirect - the saga continues


  • This topic is locked This topic is locked
2 replies to this topic

#1 soundfreak

soundfreak

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:30 PM

Posted 13 July 2011 - 12:11 AM

Thank you, whoever you are, in advance.

Here's my DDS:

.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by W***** R******* at 23:02:42 on 2011-07-12
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8190.6383 [GMT -6:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\DU Meter\DUMeterSvc.exe
C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\ppped.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Subsonic\subsonic-service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\PROGRA~2\DUMETE~1\DUMeter.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Users\W***** R*******\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: DebugBar BHO: {69fc0024-10eb-480a-bbf2-3bf4e78e17b1} - C:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - C:\PROGRA~2\FlashFXP\IEFlash.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: DebugBar: {3e1201f4-1707-409f-bb45-a5f192381da0} - C:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.dll
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
uRun: [DU Meter] C:\Program Files (x86)\DU Meter\DUMeter.exe
StartupFolder: C:\Users\W*****~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORU~1\Dropbox.lnk - C:\Users\W***** R*******\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\W*****~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORU~1\Trillian.lnk - C:\Program Files (x86)\Trillian\trillian.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORU~1\Launchy.lnk - C:\Program Files (x86)\Launchy\Launchy.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORU~1\Subsonic.lnk - C:\Program Files (x86)\Subsonic\subsonic-agent.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{97DCF5E3-FCFD-48F1-8841-6205CE0AD175} : DhcpNameServer = 192.168.1.1
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO-X64: DebugBar BHO: {69FC0024-10EB-480A-BBF2-3BF4E78E17B1} - C:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.dll
BHO-X64: DebugBar BHO - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: FlashFXP Helper for Internet Explorer: {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~2\FlashFXP\IEFlash.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB-X64: DebugBar: {3E1201F4-1707-409F-BB45-A5F192381DA0} - C:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.dll
EB-X64: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - No File
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\W***** R*******\AppData\Roaming\Mozilla\Firefox\Profiles\pjfa0fri.default\
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Research\HD View\nphdview.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Photosynth\npPhotosynthMozilla.dll
FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\W***** R*******\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\W***** R*******\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Users\W***** R*******\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\W***** R*******\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);C:\Windows\system32\DRIVERS\tdrpm258.sys --> C:\Windows\system32\DRIVERS\tdrpm258.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-5-4 128384]
R2 DUMeterSvc;DU Meter Service;C:\Program Files (x86)\DU Meter\DUMeterSvc.exe [2010-4-10 1412488]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-7-12 366640]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [2011-4-1 428640]
R3 CompFilter64;UVCCompositeFilter;C:\Windows\system32\DRIVERS\lvbflt64.sys --> C:\Windows\system32\DRIVERS\lvbflt64.sys [?]
R3 HTCAND64;HTC Device Driver;C:\Windows\system32\Drivers\ANDROIDUSB.sys --> C:\Windows\system32\Drivers\ANDROIDUSB.sys [?]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\system32\DRIVERS\LEqdUsb.Sys --> C:\Windows\system32\DRIVERS\LEqdUsb.Sys [?]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\system32\DRIVERS\LHidEqd.Sys --> C:\Windows\system32\DRIVERS\LHidEqd.Sys [?]
R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
R3 LVUVC64;Logitech HD Pro Webcam C910(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 DroidExplorerService;DroidExplorer Service;C:\Program Files\Droid Explorer\DroidExplorer.Service.exe [2010-8-1 253440]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-18 136176]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-4-15 1153368]
S3 afcdp;afcdp;C:\Windows\system32\DRIVERS\afcdp.sys --> C:\Windows\system32\DRIVERS\afcdp.sys [?]
S3 cmvad;Linksys Wireless-G Music Bridge Interface;C:\Windows\system32\drivers\cmudaxv.sys --> C:\Windows\system32\drivers\cmudaxv.sys [?]
S3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;C:\Program Files (x86)\DU Meter\DUMetr64.sys [2011-1-31 19088]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2011-4-29 14216]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2011-4-29 8456]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-2-27 1038088]
S3 Fw1884;Driver for FW-1884;C:\Windows\system32\Drivers\Fw1884x64.sys --> C:\Windows\system32\Drivers\Fw1884x64.sys [?]
S3 Fw1884WdmService;%FdgWdmSvcDesc%;C:\Windows\system32\Drivers\FW1884Wdmx64.sys --> C:\Windows\system32\Drivers\FW1884Wdmx64.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-18 136176]
S3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 rspAux;rspAux;C:\Windows\system32\DRIVERS\rspAux64.sys --> C:\Windows\system32\DRIVERS\rspAux64.sys [?]
S3 Spyder2;ColorVision Spyder2;C:\Windows\system32\DRIVERS\Spyder2.sys --> C:\Windows\system32\DRIVERS\Spyder2.sys [?]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S4 afcdpsrv;Acronis Nonstop Backup service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-3-3 2480048]
.
=============== Created Last 30 ================
.
2011-07-13 03:58:32 -------- d-----w- C:\Users\W***** R*******\AppData\Local\Temp
2011-07-13 03:25:46 35712 ----a-w- C:\Windows\SysWow64\drivers\BlackBox.sys
2011-07-13 02:58:07 -------- d-sh--w- C:\$RECYCLE.BIN
2011-07-13 02:24:47 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2011-07-12 22:26:28 -------- d-----w- C:\Windows\System32\SPReview
2011-07-12 22:26:17 -------- d-----w- C:\Windows\System32\EventProviders
2011-07-12 22:22:59 753664 ----a-w- C:\Windows\System32\drivers\http.sys
2011-07-12 22:21:59 95232 ----a-w- C:\Windows\System32\regapi.dll
2011-07-12 22:19:08 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-07-12 21:35:59 2871808 ----a-w- C:\Windows\explorer.exe
2011-07-12 21:33:12 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-07-12 21:33:12 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-07-12 21:32:56 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-12 21:32:56 338944 ----a-w- C:\Windows\System32\conhost.exe
2011-07-12 21:32:56 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-12 21:32:56 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-12 21:32:56 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-07-12 21:32:55 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-12 21:32:55 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-12 21:32:55 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-12 21:32:55 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-12 21:32:55 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-12 21:32:55 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-12 20:12:23 -------- d-----w- C:\Program Files (x86)\ESET
2011-07-12 20:04:37 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-07-12 20:04:19 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2011-07-12 20:01:56 -------- d-----w- C:\Users\W***** R*******\AppData\Local\Microsoft Help
2011-07-12 19:52:54 289280 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-07-12 19:52:54 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-07-12 19:52:54 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-07-12 19:51:55 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-07-12 19:51:55 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-07-12 19:51:55 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-07-12 19:51:54 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-07-12 19:48:59 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-07-12 19:48:53 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-07-12 19:48:53 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-07-12 19:48:53 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-07-12 19:48:53 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2011-07-12 19:48:53 207872 ----a-w- C:\Windows\System32\cfgmgr32.dll
2011-07-12 19:48:53 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-07-12 19:25:30 691 ----a-w- C:\Users\W***** R*******\AppData\Roaming\GetValue.vbs
2011-07-12 19:25:30 35 ----a-w- C:\Users\W***** R*******\AppData\Roaming\SetValue.bat
2011-07-12 17:20:00 -------- d-----w- C:\Users\W***** R*******\AppData\Roaming\SUPERAntiSpyware.com
2011-07-12 17:20:00 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-07-12 17:19:51 -------- d-----w- C:\ProgramData\!SASCORE
2011-07-12 17:19:49 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-07-12 16:55:44 -------- d-----w- C:\Users\W***** R*******\AppData\Roaming\Malwarebytes
2011-07-12 16:55:41 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-12 16:55:40 -------- d-----w- C:\ProgramData\Malwarebytes
2011-07-12 16:55:37 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-07-12 16:55:37 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-07-12 16:49:43 55384 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys
2011-07-12 16:49:24 -------- d-----w- C:\Program Files (x86)\SpywareBlaster
2011-07-12 16:48:37 -------- d-----w- C:\Program Files (x86)\Lavasoft
2011-07-12 03:40:22 115712 --sha-r- C:\Windows\SysWow64\rpchttpb.dll
2011-07-12 02:02:34 -------- d-----w- C:\Users\W***** R*******\AppData\Roaming\Design-Lib.Com
2011-07-12 02:02:27 -------- d-----w- C:\Program Files (x86)\Design-Lib Creations
2011-07-11 23:42:28 8873296 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AB2C3A1E-7942-4788-82A7-7E41A16AED59}\mpengine.dll
2011-07-08 23:09:30 -------- d-----w- C:\Program Files\Common Files\EPSON
2011-07-08 23:09:06 88064 ----a-w- C:\Windows\System32\E_IBCBGXA.DLL
2011-07-08 23:09:06 118784 ----a-w- C:\Windows\System32\E_ILMGXA.DLL
2011-07-08 23:08:41 464384 ----a-w- C:\Windows\System32\esxw2ud.dll
2011-07-08 23:08:41 13824 ----a-w- C:\Windows\System32\esxcdev.dll
2011-07-08 23:08:41 132560 ----a-w- C:\Windows\System32\esdevapp.exe
2011-07-08 00:09:34 -------- d-----w- C:\Program Files (x86)\Mozilla Thunderbird 5.0 Beta 2
2011-07-07 17:33:16 53248 ----a-r- C:\Users\W***** R*******\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-07-07 17:32:30 -------- d-----w- C:\Program Files (x86)\Common Files\LWS
2011-07-05 23:31:57 -------- d-----w- C:\Users\W***** R*******\AppData\Roaming\Copernic
2011-07-05 23:31:57 -------- d-----w- C:\Users\W***** R*******\AppData\Local\Copernic
2011-07-04 20:13:02 -------- d-----w- C:\Program Files (x86)\Kolor
2011-07-04 20:08:36 -------- d-----w- C:\Users\W***** R*******\AppData\Local\Kolor
2011-07-04 20:08:01 -------- d-----w- C:\Program Files\Kolor
2011-07-04 19:55:20 -------- d-----w- C:\Program Files\KRPano
2011-07-04 19:23:58 -------- d-----w- C:\Program Files (x86)\Photosynth
2011-07-04 19:09:40 -------- d-----w- C:\Program Files (x86)\Microsoft Research
2011-07-01 02:52:19 -------- d-----w- C:\Users\W***** R*******\AppData\Roaming\ResourceCentral.E6E1B28A311BC518DB6C6883EA3757FDE0E90ADC.1
2011-06-23 23:32:20 -------- d-----w- C:\Users\W***** R*******\AppData\Local\{DE263065-C16A-4D22-8224-79CDAA5CFCBE}
2011-06-23 23:06:56 -------- d-----w- C:\Windows\en
2011-06-23 23:05:12 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-06-23 23:04:17 -------- d-----w- C:\Windows\PCHEALTH
2011-06-23 23:03:51 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-06-23 23:03:51 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-06-23 23:03:51 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-06-23 23:03:51 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-06-23 23:03:50 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d05fe8f41cc31f90a\DSETUP.dll
2011-06-23 23:03:50 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d05fe8f41cc31f90a\DXSETUP.exe
2011-06-23 23:03:50 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d05fe8f41cc31f90a\dsetup32.dll
2011-06-23 23:03:42 4398360 ----a-w- C:\Windows\System32\d3dx9_32.dll
2011-06-23 23:03:42 3426072 ----a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-06-23 23:03:41 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cacf6ba81cc31f909\DSETUP.dll
2011-06-23 23:03:41 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cacf6ba81cc31f909\DXSETUP.exe
2011-06-23 23:03:41 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cacf6ba81cc31f909\dsetup32.dll
2011-06-23 22:43:50 -------- d-----w- C:\Users\W***** R*******\AppData\Local\Windows Live
2011-06-23 22:43:49 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-06-23 04:22:27 -------- d-----w- C:\Program Files\Microsoft Research
2011-06-23 03:45:14 -------- d-----w- C:\Program Files\ArdfryImaging
2011-06-21 20:24:51 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-06-21 20:24:51 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll
.
==================== Find3M ====================
.
2011-07-12 22:29:25 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-07-12 22:29:25 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-07-12 16:44:17 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-01 20:08:09 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-06-26 06:45:56 256000 ----a-w- C:\Windows\PEV.exe
2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-06-08 03:51:50 368640 ----a-w- C:\Windows\SysWow64\ReWire.dll
2011-06-03 06:56:38 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-06-03 05:57:52 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-06-03 05:56:11 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-03 03:48:32 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-05-04 08:52:22 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-05-03 05:29:29 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-05-03 04:30:02 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-04-29 03:06:10 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-04-29 03:05:49 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-04-29 03:05:37 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-04-25 05:33:51 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-04-25 02:34:03 499200 ----a-w- C:\Windows\System32\drivers\afd.sys
2011-04-23 01:29:25 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-04-23 01:19:19 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-04-22 23:35:56 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-04-22 23:25:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-04-22 22:15:29 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-04-16 19:20:47 25640 ----a-w- C:\Windows\gdrv.sys
.
============= FINISH: 23:04:32.77 ===============

I just found out I'm not supposed to run ComboFix without first being told to do so.... Well I did it... shame on me. In any case I attached the log.

Bumpety bump bump....

EDIT: Please be patient. There are over 360 unanswered topics in this forum at present and the current average wait time to receive help is 11 days. ~Budapest

Attached Files


Edited by Budapest, 14 July 2011 - 04:52 PM.


BC AdBot (Login to Remove)

 


#2 soundfreak

soundfreak
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:30 PM

Posted 15 July 2011 - 01:56 AM

I found the solution. You can remove the thread. I apologize for not following the rules - I was under the influence of anxiety.

#3 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:11:30 PM

Posted 15 July 2011 - 05:03 PM

Thanks for posting back to inform us that the issue you were experiencing has been resolved. We greatly appreciate it.

This thread will now be closed.

Kindest Regards,
SweetTech.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users