Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Infected with TDSS & Google keeps redirecting

  • This topic is locked This topic is locked
2 replies to this topic

#1 patsel23


  • Members
  • 1 posts
  • Local time:10:18 PM

Posted 03 June 2014 - 09:32 PM

Attached File  attach.txt   16.16KB   2 downloadsAttached File  dds.txt   16.98KB   2 downloads


DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 1.6.0_03
Run by Tandrea Sellers at 22:23:33 on 2014-06-03
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.510.100 [GMT -4:00]
AV: AVG Premium Security 2014 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Internet Security 2012 *Enabled*
FW: avast! Antivirus *Disabled*
FW: AVG Firewall *Disabled*
============== Running Processes ================
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Documents and Settings\Tandrea Sellers\Application Data\DefaultTab\DefaultTab\DTUpdate.exe
C:\Program Files\pcmax\pcmax.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Lexmark Z2300 Series\lxdpMsdMon.exe
C:\Program Files\AVG SafeGuard toolbar\vprot.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Browsersafeguard\BrowserSafeguard.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc
============== Pseudo HJT Report ===============
uStart Page = hxxp://start.mysearchdial.com/?f=1&a=adk_14_18&cd=2XzuyEtN2Y1L1QzutDtDtD0DyDyCyD0DtByCtDzytAyBzz0AtN0D0Tzu0SzzzztCtN1L2XzutBtFtBtDtFtCzytFtCtN1L1Czu1T1Q1J1VtCyE1VtCzztN1L1G1B1V1N2Y1L1Qzu2StB0CyEyC0ByEtC0DtG0CyCyCtCtGzyyD0C0CtGyEzyyEzytGyByDtDtByEzyzz0ByEyC0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtD0FyByDtD0A0EtGzz0F0C0DtGzztA0AtBtG0E0A0CtDtGyEyD0FyByDyBzz0CtCyC0CtB2Q&cr=2032305528&ir=
uSearch Bar = hxxp://www.bing.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://start.mysearchdial.com/?f=1&a=adk_14_18&cd=2XzuyEtN2Y1L1QzutDtDtD0DyDyCyD0DtByCtDzytAyBzz0AtN0D0Tzu0SzzzztCtN1L2XzutBtFtBtDtFtCzytFtCtN1L1Czu1T1Q1J1VtCyE1VtCzztN1L1G1B1V1N2Y1L1Qzu2StB0CyEyC0ByEtC0DtG0CyCyCtCtGzyyD0C0CtGyEzyyEzytGyByDtDtByEzyzz0ByEyC0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtD0FyByDtD0A0EtGzz0F0C0DtGzztA0AtBtG0E0A0CtDtGyEyD0FyByDyBzz0CtCyC0CtB2Q&cr=2032305528&ir=
uInternet Connection Wizard,ShellNext = iexplore
uProxyServer = hxxp=;https=;
uProxyOverride = <-loopback>
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: AOLTBSearch Class: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - LocalServer32 - <no file>
dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
BHO: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - c:\program files\lexmark toolbar\toolband.dll
BHO: <No Name>: {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\program files\microsoft money\system\MNYSIDE.DLL
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - LocalServer32 - <no file>
BHO: DriveLetterAccess: {5CA3D70E-1895-11CF-8E15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Vafmusic2 Toolbar: {7f3f960e-a836-45ca-8911-0accb522246e} - c:\program files\vafmusic2\prxtbVafm.dll
BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} -
BHO: AVG SafeGuard toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg safeguard toolbar\\AVG SafeGuard toolbar_toolbar.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.9012.1008\swg.dll
TB: AIM Search: {40D41A8B-D79B-43D7-99A7-9EE0F344C385} - LocalServer32 - <no file>
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: AOL Toolbar: {DE9C389F-3316-41A7-809B-AA305ED9D922} - LocalServer32 - <no file>
TB: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - c:\program files\lexmark toolbar\toolband.dll
TB: <No Name>: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - <no file>
TB: Vafmusic2 Toolbar: {7F3F960E-A836-45CA-8911-0ACCB522246E} - c:\program files\vafmusic2\prxtbVafm.dll
TB: AOL Toolbar: {DE9C389F-3316-41A7-809B-AA305ED9D922} - LocalServer32 - <no file>
TB: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - c:\program files\lexmark toolbar\toolband.dll
TB: Vafmusic2 Toolbar: {7f3f960e-a836-45ca-8911-0accb522246e} - c:\program files\vafmusic2\prxtbVafm.dll
TB: AVG SafeGuard toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg safeguard toolbar\\AVG SafeGuard toolbar_toolbar.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: &Yahoo! Messenger: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
EB: &Yahoo! Messenger: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [pcreg] c:\program files\pcmax\service.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_13_0_0_206_Plugin.exe -update plugin
uRunServices: [Windows Services] scmsg.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [lxdpmon.exe] "c:\program files\lexmark z2300 series\lxdpmon.exe"
mRun: [lxdpamon] "c:\program files\lexmark z2300 series\lxdpamon.exe"
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [vProt] "c:\program files\avg safeguard toolbar\vprot.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [BrowserSafeguard] "c:\program files\browsersafeguard\BrowserSafeguard.exe"
mRun: [pcreg] c:\program files\pcmax\service.exe
mRunOnce: [SpUninstallCleanUp] REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f
StartupFolder: c:\docume~1\tandre~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
uPolicies-Explorer: HideSCAHealth = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: HideSCAHealth = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\MNYSIDE.DLL
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - hxxp://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119925405750
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132761026021
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://download.shockwave.com/pub/otoy/OTOYAX.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.shockwave.com/content/heavyweapon/popcaploader_v6.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4519/mcfscan.cab
TCP: NameServer =
TCP: Interfaces\{19D55CEA-9A72-479A-8A21-D7D5D1597636} : DHCPNameServer =
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\18.1.7\ViProtocol.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\program files\windows defender\MpShHook.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = Error!
================= FIREFOX ===================
FF - ProfilePath - c:\documents and settings\tandrea sellers\application data\mozilla\firefox\profiles\pdurpwpv.default\
FF - prefs.js: browser.search.selectedEngine - Mysearchdial
FF - prefs.js: browser.startup.homepage - hxxp://start.mysearchdial.com/?f=1&a=adk_14_18&cd=2XzuyEtN2Y1L1QzutDtDtD0DyDyCyD0DtByCtDzytAyBzz0AtN0D0Tzu0SzzzztCtN1L2XzutBtFtBtDtFtCzytFtCtN1L1Czu1T1Q1J1VtCyE1VtCzztN1L1G1B1V1N2Y1L1Qzu2StB0CyEyC0ByEtC0DtG0CyCyCtCtGzyyD0C0CtGyEzyyEzytGyByDtDtByEzyzz0ByEyC0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtD0FyByDtD0A0EtGzz0F0C0DtGzztA0AtBtG0E0A0CtDtGyEyD0FyByDyBzz0CtCyC0CtB2Q&cr=2032305528&ir=
FF - component: c:\program files\mozilla firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_13_0_0_206.dll
FF - user.js: extensions.irmysearch.aflt - adk_14_18
FF - user.js: extensions.irmysearch.instlRef - adk_14_18
FF - user.js: extensions.irmysearch.cr - 2032305528
FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1QzutDtDtD0DyDyCyD0DtByCtDzytAyBzz0AtN0D0Tzu0SzzzztCtN1L2XzutBtFtBtDtFtCzytFtCtN1L1Czu1T1Q1J1VtCyE1VtCzztN1L1G1B1V1N2Y1L1Qzu2StB0CyEyC0ByEtC0DtG0CyCyCtCtGzyyD0C0CtGyEzyyEzytGyByDtDtByEzyzz0ByEyC0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtD0FyByDtD0A0EtGzz0F0C0DtGzztA0AtBtG0E0A0CtDtGyEyD0FyByDyBzz0CtCyC0CtB2Q
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2014-3-17 573968]
R1 {42e50651-9669-456e-9081-d5a836274274}t;{42e50651-9669-456e-9081-d5a836274274}t;c:\windows\system32\drivers\{42e50651-9669-456e-9081-d5a836274274}t.sys [2014-5-22 55224]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-9-18 42784]
R2 DefaultTabUpdate;DefaultTabUpdate;c:\documents and settings\tandrea sellers\application data\defaulttab\defaulttab\DTUpdate.exe [2013-9-18 107520]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service --> c:\windows\system32\lxdpcoms.exe -service [?]
R2 lxdpCATSCustConnectService;lxdpCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdpserv.exe [2008-12-27 98984]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2014-5-31 175480]
R2 pcmaxservice;pcmaxservice Service;c:\program files\pcmax\pcmax.exe [2014-5-29 241344]
R2 vToolbarUpdater18.1.7;vToolbarUpdater18.1.7;c:\program files\common files\avg secure search\vtoolbarupdater\18.1.7\ToolbarUpdater.exe [2014-6-2 1808408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 HitmanPro37CrusaderBoot;HitmanPro 3.7 Crusader (Boot);"e:\hitmanpro.exe" /crusader:boot --> e:\HitmanPro.exe [?]
S2 NAVAPEL;NAVAPEL;\??\c:\program files\navnt\navapel.sys --> c:\program files\navnt\NAVAPEL.SYS [?]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-1-27 1025352]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys --> c:\windows\system32\vsdatant.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 WinDefend;Windows Defender Service;c:\program files\windows defender\MsMpEng.exe [2006-4-3 14032]
=============== File Associations ===============
ShellExec: EasyShare.exe: Preview="c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe"
=============== Created Last 30 ================
2014-06-01 23:03:51    --------    d-----w-    C:\temp
2014-05-31 05:15:17    175480    ----a-w-    c:\windows\system32\mfevtps.exe
2014-05-31 04:30:30    --------    d-----w-    c:\program files\stinger
2014-05-31 04:28:14    --------    d-----w-    c:\program files\common files\McAfee
2014-05-31 04:26:35    --------    d-----w-    c:\program files\pcmax
2014-05-31 04:26:20    --------    d-----w-    c:\program files\PC Speed Maximizer
2014-05-31 04:25:07    --------    d-----w-    c:\program files\Browsersafeguard
2014-05-22 19:36:27    55224    ----a-w-    c:\windows\system32\drivers\{42e50651-9669-456e-9081-d5a836274274}t.sys
2014-05-13 05:34:26    46704    ----a-w-    c:\program files\mozilla firefox\browser\components\browsercomps.dll
2014-05-13 05:29:05    --------    d-----w-    c:\program files\Mozilla Maintenance Service
2014-05-08 13:48:42    227704    ----a-w-    c:\program files\mozilla firefox\plugins\nppdf32.dll
2014-05-08 13:48:42    227704    ----a-w-    c:\program files\internet explorer\plugins\nppdf32.dll
==================== Find3M  ====================
2014-06-02 14:30:42    42784    ----a-w-    c:\windows\system32\drivers\avgtpx86.sys
2014-05-13 07:09:46    70832    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2014-05-13 07:09:46    692400    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2014-03-17 23:31:40    573968    ----a-w-    c:\windows\system32\drivers\mfehidk.sys
2014-03-17 23:26:14    134600    ----a-w-    c:\windows\system32\drivers\mfeapfk.sys
2007-09-19 23:29:33    41412496    ----a-w-    c:\program files\zlsSetup_70_408_000_en.exe
2005-10-01 02:40:17    9346664    ----a-w-    c:\program files\zlsSetup_60_667_000.exe
============= FINISH: 22:25:31.17 ===============

Edited by Noviciate, 05 June 2014 - 12:43 PM.
Log added frtom attachment.

BC AdBot (Login to Remove)


#2 fireman4it


    Bleepin' Fireman

  • Malware Response Team
  • 13,512 posts
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:09:18 PM

Posted 05 June 2014 - 07:37 PM

Hello patsel23,

  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Follow This Topic.I suggest you click it and select Immediate E-Mail notification and click on Follow This Topic. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

  • Finally, please reply using the Post  button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.




Please delete your copy of TDSSKiller and download the latest version from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

  • Click the Start Scan button.

  • If a suspicious object is detected, the default action will be Skip, click on Continue.

  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.


    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.




Install Recovery Console and Run ComboFix

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

Download Combofix from any of the links below, and save it to your desktop

Link 1
Link 2

  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • If you did not have it installed, you will see the prompt below. Choose YES.
  • RcAuto1.gif
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running.
ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.


Things to include in your next reply::

TdssKiller log


How is your machine running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.



If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif

#3 fireman4it


    Bleepin' Fireman

  • Malware Response Team
  • 13,512 posts
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:09:18 PM

Posted 08 June 2014 - 05:07 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.



If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users