1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved redirect/ fake virus scanner problem..

Discussion in 'Malware and Virus Removal Archive' started by gideon01, 2010/03/26.

  1. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    [Resolved] redirect/ fake virus scanner problem..

    so i got the bingzugo thing fixed , now this is happening. if i google something and click the link to open the result page i get redirected to a add site. the add is totaly random never the same. it seems to only happen in google at this point. also a fake virus scanner starts, scans my system and says i got hundreds of spy/malware and bogs my pc down big time. i had to reboot after the fake scan started just to be able to post this.
    i also get browser memory can not be read click ok to close errors since i installed zone alarm not sure if thats related or what

    this may have been a hidden trojan cause i downloaded and
    installed most of the tools in this thread http://www.windowsbbs.com/malware-virus-removal/67958-ounce-prevention-worth-pound-cure.html and what ever is causing it went undetected


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 3/20/2010 11:49:48 PM
    System Uptime: 3/26/2010 5:15:36 PM (0 hours ago)

    Motherboard: Dell Inc. | | 0J3492
    Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz | Microprocessor | 3192/800mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 149 GiB total, 128.221 GiB free.
    D: is CDROM (UDF)
    E: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1: 3/24/2010 5:00:39 PM - System Checkpoint
    RP2: 3/25/2010 6:28:52 PM - System Checkpoint

    ==== Installed Programs ======================


    ==== Event Viewer Messages From Past Week ========


    ==== End Of File ===========================
     
    Last edited: 2010/03/26
  2. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    logs

    DDS (Ver_10-03-17.01) - NTFSx86
    Run by home at 17:21:14.01 on Fri 03/26/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1193 [GMT -4:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

    ============== Running Processes ===============

    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    svchost.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\home\My Documents\addware malware tools\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.whtm.com/
    uInternet Settings,ProxyOverride = *.local
    BHO: {25526b16-f633-481c-8891-b9f8903112a4} - vimoveta.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
    BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: ZoneAlarm Toolbar Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
    mRun: [IAAnotif] c:\program files\intel\intel application accelerator\iaanotif.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe "
    mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon= "hidden "
    mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
    StartupFolder: c:\docume~1\home\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: NameServer = 93.188.162.32,93.188.166.159
    TCP: {7076810B-EFD8-4D07-9781-31A5C01D8A1A} = 217.23.14.75,4.2.2.1,192.168.2.1
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    AppInit_DLLs: zibuyubo.dll c:\windows\system32\
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
    SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
    LSA: Notification Packages = scecli zibuyubo.dll pacoli.dll
    IFEO: MpCmdRun.exe - c:\windows\system32\svchost.exe
    IFEO: MsMpEng.exe - c:\windows\system32\svchost.exe
    IFEO: msseces.exe - c:\windows\system32\svchost.exe

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\home\applic~1\mozilla\firefox\profiles\lkk0n11m.default\
    FF - prefs.js: browser.search.selectedEngine - Bing
    FF - prefs.js: browser.startup.homepage - www.msn.com
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: XULRunner: {31942E39-7CFE-435E-B223-E1FBE5769585} - c:\documents and settings\home\local settings\application data\{31942E39-7CFE-435E-B223-E1FBE5769585}
    FF - HiddenExtension: LoudMo Contextual Ad Assistant: No Registry Reference - c:\program files\mozilla firefox\extensions\{b213b800-b50c-14f4-a353-7f58602f49f1}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: google.toolbar.linkdoctor.enabled - false
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);

    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================


    ==================== Find3M ====================

    1601-01-01 00:03:28 94208 --sha-w- c:\windows\system32\naluwota.exe

    ============= FINISH: 17:25:46.31 ===============
     

  3. to hide this advert.

  4. 2010/03/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!


    Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Installer under Version 2.0.2
    [DO NOT download version 2.0.3 (beta)]
    Install, and run it.
    Post HijackTHis log.
    Do NOT attempt to fix anything!

    NOTE. If you're using Vista, or 7, right click on HijackThis, and click Run as Administrator
     
  5. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:27:51 PM, on 3/26/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\ComboFix\CF21534.cfxxe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\ComboFix\pv.cfxxe
    C:\ComboFix\CF21534.cfxxe
    C:\ComboFix\CSCRIPT.cfxxe
    C:\ComboFix\sed.cfxxe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.whtm.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {25526b16-f633-481c-8891-b9f8903112a4} - vimoveta.dll (file missing)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon= "hidden "
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7076810B-EFD8-4D07-9781-31A5C01D8A1A}: NameServer = 217.23.14.75,4.2.2.1,192.168.2.1
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: COMServer - Unknown owner - C:\WINDOWS\system32\msapps\comsrvr.exe (file missing)
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 7529 bytes
     
  6. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    ComboFix 10-03-26.02 - home 03/26/2010 18:09:17.2.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1362 [GMT -4:00]
    Running from: c:\documents and settings\home\My Documents\Downloads\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\documents and settings\home\Local Settings\Application Data\{31942E39-7CFE-435E-B223-E1FBE5769585}
    c:\documents and settings\home\Local Settings\Application Data\{31942E39-7CFE-435E-B223-E1FBE5769585}\chrome.manifest
    c:\documents and settings\home\Local Settings\Application Data\{31942E39-7CFE-435E-B223-E1FBE5769585}\chrome\content\_cfg.js
    c:\documents and settings\home\Local Settings\Application Data\{31942E39-7CFE-435E-B223-E1FBE5769585}\chrome\content\overlay.xul
    c:\documents and settings\home\Local Settings\Application Data\{31942E39-7CFE-435E-B223-E1FBE5769585}\install.rdf
    c:\windows\system32\naluwota.exe

    ----- BITS: Possible infected sites -----

    hxxp://77.74.48.118
    Infected copy of c:\windows\system32\DRIVERS\iaStor.sys was found and disinfected
    Restored copy from - Kitty ate it :p
    .
    ((((((((((((((((((((((((( Files Created from 2010-02-26 to 2010-03-26 )))))))))))))))))))))))))))))))
    .

    2010-03-26 21:44 . 2010-03-26 21:51 -------- d-----w- c:\documents and settings\home\Application Data\LimeWire
    2010-03-26 21:44 . 2010-03-26 21:44 -------- d-----w- c:\program files\LimeWire
    2010-03-26 12:22 . 2010-03-26 11:49 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-03-26 11:50 . 2010-02-04 15:53 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-03-26 11:49 . 2010-03-26 11:49 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-03-26 11:47 . 2010-03-26 11:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
    2010-03-26 11:47 . 2010-03-26 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-03-26 11:47 . 2010-03-26 11:48 -------- d-----w- c:\program files\Lavasoft
    2010-03-26 11:43 . 2010-03-26 11:44 -------- d-----w- c:\program files\SpywareGuard
    2010-03-26 11:30 . 2010-03-26 11:30 -------- d-----w- c:\documents and settings\home\Application Data\WinPatrol
    2010-03-26 11:30 . 2010-03-26 11:30 -------- d-----w- c:\program files\BillP Studios
    2010-03-26 11:13 . 2010-03-26 22:17 -------- d-----w- c:\windows\Internet Logs
    2010-03-26 11:10 . 2010-03-26 11:10 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
    2010-03-26 11:10 . 2005-08-25 23:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
    2010-03-26 11:10 . 2010-03-26 11:12 -------- d-----w- c:\program files\SpywareBlaster
    2010-03-26 10:59 . 2010-03-26 12:00 -------- d-----w- c:\documents and settings\home\Application Data\QuickScan
    2010-03-25 22:21 . 2010-03-25 22:21 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
    2010-03-24 22:54 . 2010-01-07 20:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-03-24 22:54 . 2010-01-07 20:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-03-24 20:06 . 2010-03-26 21:26 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-03-24 20:05 . 2010-03-24 22:53 120 ----a-w- c:\windows\Fnudukeq.dat
    2010-03-24 20:05 . 2010-03-24 20:05 0 ----a-w- c:\windows\Mlinevix.bin
    2010-03-24 20:05 . 2010-03-24 20:05 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
    2010-03-24 19:58 . 2010-03-26 12:22 -------- d-sh--w- c:\documents and settings\home\.COMMgr
    2010-03-24 19:58 . 2010-03-24 19:57 167936 ----a-w- c:\windows\Nmanaa.exe
    2010-03-24 19:57 . 2010-03-26 12:04 -------- d-----w- c:\windows\system32\msapps
    2010-03-24 19:57 . 2010-03-24 20:26 -------- d-----w- c:\documents and settings\home\Application Data\D8585968FC18271731C4ED43D7D5AD4E
    2010-03-23 22:26 . 2010-03-23 22:26 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
    2010-03-23 22:26 . 2010-03-23 22:26 -------- d-----w- c:\program files\DVDVideoSoft
    2010-03-23 22:19 . 2010-03-23 22:19 -------- d-----w- c:\documents and settings\home\Application Data\OxelonMC
    2010-03-23 22:19 . 2010-03-23 22:20 -------- d-----w- c:\program files\OxelonMedia
    2010-03-23 20:03 . 2010-03-23 20:03 -------- d-----w- c:\program files\Sun
    2010-03-23 20:00 . 2010-03-23 20:01 -------- d-----w- c:\documents and settings\home\.SunDownloadManager
    2010-03-22 10:35 . 2010-03-22 10:36 -------- d-----w- c:\documents and settings\home\Application Data\ProfitUI Reborn Updater
    2010-03-22 10:08 . 2010-03-22 10:08 -------- d-----w- c:\program files\Ventrilo
    2010-03-22 10:08 . 2010-03-22 10:08 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2010-03-22 09:51 . 2010-03-22 09:51 -------- d-----w- C:\_OTM
    2010-03-22 01:26 . 2010-03-22 01:26 -------- d-----w- c:\program files\Trend Micro
    2010-03-21 23:00 . 2010-03-21 23:00 -------- d-----w- c:\windows\Sun
    2010-03-21 18:41 . 2010-03-21 18:41 -------- d-----w- c:\documents and settings\home\Application Data\Malwarebytes
    2010-03-21 18:41 . 2010-03-21 18:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-03-21 18:41 . 2010-03-25 10:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-03-21 12:37 . 2010-03-21 12:37 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-03-21 07:06 . 2010-03-21 07:06 0 ----a-w- c:\windows\nsreg.dat
    2010-03-21 07:05 . 2010-03-21 07:05 -------- d-----w- c:\documents and settings\home\Local Settings\Application Data\Mozilla
    2010-03-21 07:02 . 2010-03-21 07:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Toolbar4
    2010-03-21 06:38 . 2008-04-13 17:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
    2010-03-21 06:38 . 2008-04-13 17:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
    2010-03-21 06:38 . 2001-08-18 02:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
    2010-03-21 06:38 . 2008-04-13 23:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
    2010-03-21 06:25 . 2010-03-21 06:25 -------- d-----w- c:\program files\WinSCP
    2010-03-21 06:21 . 2010-03-21 06:21 -------- d-----w- c:\documents and settings\home\Application Data\Windows Search
    2010-03-21 06:16 . 2009-12-17 21:14 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-03-21 05:22 . 2010-03-21 05:22 -------- d-----w- c:\program files\Sony
    2010-03-21 05:22 . 2010-03-21 05:22 -------- d-----w- c:\program files\Common Files\SWF Studio
    2010-03-21 05:20 . 2010-03-21 05:20 13104 ----a-w- c:\documents and settings\home\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-03-21 05:19 . 2010-03-21 06:39 -------- d-----w- c:\documents and settings\home\Application Data\Apple Computer
    2010-03-21 05:19 . 2009-05-18 18:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-03-21 05:19 . 2008-04-17 17:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
    2010-03-21 05:17 . 2010-03-21 05:20 -------- d-----w- c:\documents and settings\home\Local Settings\Application Data\Apple Computer
    2010-03-21 04:09 . 2010-03-22 09:46 -------- d-----w- c:\documents and settings\home\Local Settings\Application Data\ApplicationHistory
    2010-03-21 04:04 . 2010-03-21 04:04 -------- d-----w- c:\documents and settings\home\Application Data\Yahoo!
    2010-03-21 04:04 . 2010-03-21 07:17 -------- d-----w- c:\program files\Yahoo!
    2010-03-21 04:04 . 2010-03-21 04:04 -------- d-----w- c:\program files\CCleaner

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-03-26 18:33 . 2010-03-26 21:18 668648 ----a-w- c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    2010-03-26 18:33 . 2010-03-26 21:18 830864 ----a-w- c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    2010-03-26 11:14 . 2010-03-26 11:14 -------- d-----w- c:\documents and settings\home\Application Data\CheckPoint
    2010-03-26 11:14 . 2010-03-26 11:14 -------- d-----w- c:\program files\CheckPoint
    2010-03-26 11:14 . 2010-03-26 11:14 4212 ---ha-w- c:\windows\system32\zllictbl.dat
    2010-03-26 11:14 . 2010-03-26 11:14 -------- d-----w- c:\program files\Zone Labs
    2010-03-25 20:31 . 2010-03-21 03:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-03-25 01:08 . 2004-08-12 14:11 477952 ----a-w- c:\windows\system32\drivers\iaStor.sys
    2010-03-24 20:30 . 2010-03-21 03:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-03-23 20:03 . 2010-03-21 02:59 -------- d-----w- c:\program files\Java
    2010-03-21 22:09 . 2010-03-21 02:59 -------- d-----w- c:\program files\Common Files\Java
    2010-03-21 22:09 . 2010-03-21 22:09 348160 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bdbf744-n\msvcr71.dll
    2010-03-21 22:09 . 2010-03-21 22:09 61440 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-63ad000f-n\decora-sse.dll
    2010-03-21 22:09 . 2010-03-21 22:09 503808 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bdbf744-n\msvcp71.dll
    2010-03-21 22:09 . 2010-03-21 22:09 499712 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bdbf744-n\jmc.dll
    2010-03-21 22:09 . 2010-03-21 22:09 12800 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-63ad000f-n\decora-d3d.dll
    2010-03-21 12:37 . 2010-03-21 03:58 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2010-03-21 12:37 . 2010-03-21 03:58 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2010-03-21 12:37 . 2010-03-21 03:58 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2010-03-21 06:38 . 2010-03-21 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
    2010-03-21 05:22 . 2010-03-21 03:55 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-03-21 05:19 . 2010-03-21 05:19 -------- d-----w- c:\program files\iTunes
    2010-03-21 05:19 . 2010-03-21 05:19 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2010-03-21 05:19 . 2010-03-21 05:19 -------- d-----w- c:\program files\iPod
    2010-03-21 05:19 . 2010-03-21 05:17 -------- d-----w- c:\program files\Common Files\Apple
    2010-03-21 05:19 . 2010-03-21 05:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2010-03-21 05:18 . 2010-03-21 05:18 -------- d-----w- c:\program files\Bonjour
    2010-03-21 05:18 . 2010-03-21 05:18 -------- d-----w- c:\program files\QuickTime
    2010-03-21 05:18 . 2010-03-21 05:18 -------- d-----w- c:\program files\Apple Software Update
    2010-03-21 04:20 . 2010-03-21 03:35 -------- d-----w- c:\program files\Windows Desktop Search
    2010-03-21 03:58 . 2010-03-21 03:58 -------- d-----w- c:\program files\AVG
    2010-03-21 03:58 . 2010-03-21 03:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
    2010-03-21 03:58 . 2010-03-21 03:58 -------- d-----w- c:\program files\Broadcom
    2010-03-21 03:58 . 2010-03-21 03:55 -------- d-----w- c:\program files\Common Files\InstallShield
    2010-03-21 03:57 . 2010-03-21 03:57 -------- d-----w- c:\program files\Intel
    2010-03-21 03:56 . 2010-03-21 03:56 -------- d-----w- c:\program files\Analog Devices
    2010-03-21 03:48 . 2010-03-21 03:48 -------- d-----w- c:\program files\microsoft frontpage
    2010-03-21 03:48 . 2010-03-26 11:30 0 ----a-w- c:\documents and settings\home\Application Data\WinPatrol\Config.sys
    2010-03-21 03:48 . 2010-03-26 11:30 0 ----a-w- c:\documents and settings\home\Application Data\WinPatrol\Autoexec.bat
    2010-03-21 03:46 . 2010-03-21 03:46 -------- d-----w- c:\program files\NVIDIA Corporation
    2010-03-21 03:46 . 2010-03-21 03:46 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
    2010-03-21 03:45 . 2010-03-21 03:45 21640 ----a-w- c:\windows\system32\emptyregdb.dat
    2010-03-21 03:39 . 2010-03-21 03:39 -------- d-----w- c:\program files\MSBuild
    2010-03-21 03:39 . 2010-03-21 03:39 -------- d-----w- c:\program files\Reference Assemblies
    2010-03-21 03:36 . 2010-03-21 03:36 -------- d-----w- c:\documents and settings\home\Application Data\Windows Desktop Search
    2010-03-21 03:35 . 2010-03-21 03:35 -------- d-----w- c:\program files\Windows Media Connect 2
    2010-02-18 09:34 . 2010-02-18 09:34 1273856 ----a-w- c:\windows\system32\A7xidBuk_-0UPM.dll
    2010-02-15 22:41 . 2010-02-15 22:41 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
    2010-02-04 15:53 . 2010-03-26 11:47 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
    2010-01-27 02:04 . 2010-03-21 07:02 60592 ----a-w- c:\documents and settings\All Users\Application Data\Toolbar4\{0C8413C1-FAD1-446C-8584-BE50576F863E}\update.exe
    2010-01-27 02:04 . 2010-03-21 07:02 46256 ----a-w- c:\documents and settings\All Users\Application Data\Toolbar4\{0C8413C1-FAD1-446C-8584-BE50576F863E}\uninstall.exe
    2010-01-12 17:03 . 2010-03-21 03:12 10276768 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
    2010-01-12 17:03 . 2010-01-12 17:03 61440 ----a-w- c:\windows\system32\OpenCL.dll
    2010-01-12 17:03 . 2010-01-12 17:03 4104192 ----a-w- c:\windows\system32\nvcuda.dll
    2010-01-12 17:03 . 2010-01-12 17:03 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
    2010-01-12 17:03 . 2010-01-12 17:03 2283526 ----a-w- c:\windows\system32\nvdata.bin
    2010-01-12 17:03 . 2010-01-12 17:03 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
    2010-01-12 17:03 . 2010-01-12 17:03 182888 ----a-w- c:\windows\system32\nvcodins.dll
    2010-01-12 17:03 . 2010-01-12 17:03 182888 ----a-w- c:\windows\system32\nvcod.dll
    2010-01-12 17:03 . 2010-01-12 17:03 14458880 ----a-w- c:\windows\system32\nvoglnt.dll
    2010-01-12 17:03 . 2010-01-12 17:03 11632640 ----a-w- c:\windows\system32\nvcompiler.dll
    2010-01-12 17:03 . 2010-01-12 17:03 1081344 ----a-w- c:\windows\system32\nvapi.dll
    2010-01-12 17:03 . 2008-04-14 00:12 6359168 ----a-w- c:\windows\system32\nv4_disp.dll
    2010-01-12 03:17 . 2010-01-12 03:17 278120 ----a-w- c:\windows\system32\nvmccs.dll
    2010-01-12 03:17 . 2010-01-12 03:17 154216 ----a-w- c:\windows\system32\nvsvc32.exe
    2010-01-12 03:17 . 2010-01-12 03:17 145000 ----a-w- c:\windows\system32\nvcolor.exe
    2010-01-12 03:17 . 2010-01-12 03:17 13666408 ----a-w- c:\windows\system32\nvcpl.dll
    2010-01-12 03:17 . 2010-01-12 03:17 110696 ----a-w- c:\windows\system32\nvmctray.dll
    2010-01-12 03:17 . 2010-01-12 03:17 81920 ----a-w- c:\windows\system32\nvwddi.dll
    2009-12-31 16:50 . 2004-08-12 14:06 353792 ----a-w- c:\windows\system32\drivers\srv.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP "= "c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 1388544]
    "IAAnotif "= "c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
    "ZoneAlarm Client "= "c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-11-22 1037192]
    "ISW "= "c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2009-10-14 730480]
    "WinPatrol "= "c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]

    c:\documents and settings\home\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-3-23 503808]
    SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5} "= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2010-03-21 12:37 12464 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @= "Service "

    [HKLM\~\startupfolder\C:^Documents and Settings^home^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\documents and settings\home\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
    2010-01-07 20:07 429392 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)
    "DisableNotifications "= 1 (0x1)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\AVG\\AVG9\\avgemc.exe "=
    "c:\\Program Files\\AVG\\AVG9\\avgupd.exe "=
    "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Program Files\\Sony\\Station\\Launchpad\\LaunchPad.exe "=
    "c:\\Program Files\\Ventrilo\\Ventrilo.exe "=
    "c:\\Program Files\\Sony\\EverQuest II\\EQ2VoiceService.exe "=
    "c:\\WINDOWS\\system32\\spoolsv.exe "=
    "c:\\Program Files\\LimeWire\\LimeWire.exe "=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/26/2010 7:50 AM 64288]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/20/2010 11:58 PM 216200]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/20/2010 11:58 PM 242696]
    R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3/21/2010 8:37 AM 916760]
    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/21/2010 8:37 AM 308064]
    R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [10/14/2009 9:30 AM 25208]
    R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [10/14/2009 9:30 AM 476528]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1263728]
    S2 COMServer;COMServer; "c:\windows\system32\msapps\comsrvr.exe" s --> c:\windows\system32\msapps\comsrvr.exe [?]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-03-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 11:49]

    2010-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.whtm.com/
    uInternet Settings,ProxyOverride = *.local
    TCP: {7076810B-EFD8-4D07-9781-31A5C01D8A1A} = 217.23.14.75,4.2.2.1,192.168.2.1
    FF - ProfilePath - c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\
    FF - prefs.js: browser.search.selectedEngine - Bing
    FF - prefs.js: browser.startup.homepage - www.msn.com
    FF - component: c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
    FF - plugin: c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{25526b16-f633-481c-8891-b9f8903112a4} - vimoveta.dll
    MSConfigStartUp-deweritoz - c:\windows\system32\tizuluke.dll
    MSConfigStartUp-lodogayapa - webomeru.dll



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-03-26 18:19
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(668)
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

    - - - - - - - > 'lsass.exe'(724)
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

    - - - - - - - > 'explorer.exe'(2284)
    c:\windows\system32\WININET.dll
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
    c:\program files\Windows Desktop Search\deskbar.dll
    c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
    c:\program files\Windows Desktop Search\dbres.dll
    c:\program files\Windows Desktop Search\wordwheel.dll
    c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
    c:\program files\Windows Desktop Search\msnlExtRes.dll
    c:\windows\system32\ieframe.dll
    c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
    c:\program files\WinRAR\rarext.dll
    c:\program files\OxelonMedia\menuext.dll
    c:\program files\Lavasoft\Ad-Aware\ShellExt.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\WinSCP\DragExt.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
    c:\program files\SpywareGuard\spywareguard.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\nvsvc32.exe
    c:\program files\AVG\AVG9\avgchsvx.exe
    c:\program files\AVG\AVG9\avgrsx.exe
    c:\program files\AVG\AVG9\avgcsrvx.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Intel\Intel Application Accelerator\iaantmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\SearchIndexer.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\AVG\AVG9\avgnsx.exe
    c:\program files\AVG\AVG9\avgcsrvx.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\program files\SpywareGuard\sgbhp.exe
    c:\windows\system32\SearchProtocolHost.exe
    c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
    c:\windows\system32\SearchFilterHost.exe
    c:\windows\system32\NOTEPAD.EXE
    c:\program files\AVG\AVG9\avgui.exe
    c:\program files\Mozilla Firefox\firefox.exe
    .
    **************************************************************************
    .
    Completion time: 2010-03-26 18:29:42 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-03-26 22:29
    ComboFix2.txt 2010-03-21 19:46

    Pre-Run: 137,403,588,608 bytes free
    Post-Run: 137,533,341,696 bytes free

    - - End Of File - - 120CA31C8704E957C5D520704CA8C632
     
  7. 2010/03/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    How is redirection issue?


    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\Fnudukeq.dat
    c:\windows\Mlinevix.bin
    c:\windows\Nmanaa.exe
    c:\windows\system32\A7xidBuk_-0UPM.dll
    c:\windows\system32\msapps\comsrvr.exe
    
    
    Folder::
    
    Driver::
    COMServer
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
     "DisableMonitoring "=dword:00000000
    
    
    RegLockDel::
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.
     
  8. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    ComboFix 10-03-26.02 - home 03/26/2010 19:07:56.3.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1261 [GMT -4:00]
    Running from: c:\documents and settings\home\My Documents\Downloads\ComboFix.exe
    Command switches used :: c:\documents and settings\home\Desktop\CFScript.txt.txt
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

    FILE ::
    "c:\windows\Fnudukeq.dat "
    "c:\windows\Mlinevix.bin "
    "c:\windows\Nmanaa.exe "
    "c:\windows\system32\A7xidBuk_-0UPM.dll "
    "c:\windows\system32\msapps\comsrvr.exe "
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\Fnudukeq.dat
    c:\windows\Mlinevix.bin
    c:\windows\Nmanaa.exe
    c:\windows\system32\A7xidBuk_-0UPM.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_COMSERVER
    -------\Service_COMServer


    ((((((((((((((((((((((((( Files Created from 2010-02-26 to 2010-03-26 )))))))))))))))))))))))))))))))
    .

    2010-03-26 21:44 . 2010-03-26 23:18 -------- d-----w- c:\documents and settings\home\Application Data\LimeWire
    2010-03-26 21:44 . 2010-03-26 21:44 -------- d-----w- c:\program files\LimeWire
    2010-03-26 12:22 . 2010-03-26 11:49 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-03-26 11:50 . 2010-02-04 15:53 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-03-26 11:49 . 2010-03-26 11:49 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-03-26 11:47 . 2010-03-26 11:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
    2010-03-26 11:47 . 2010-03-26 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-03-26 11:47 . 2010-03-26 11:48 -------- d-----w- c:\program files\Lavasoft
    2010-03-26 11:43 . 2010-03-26 11:44 -------- d-----w- c:\program files\SpywareGuard
    2010-03-26 11:30 . 2010-03-26 11:30 -------- d-----w- c:\documents and settings\home\Application Data\WinPatrol
    2010-03-26 11:30 . 2010-03-26 11:30 -------- d-----w- c:\program files\BillP Studios
    2010-03-26 11:13 . 2010-03-26 23:15 -------- d-----w- c:\windows\Internet Logs
    2010-03-26 11:10 . 2010-03-26 11:10 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
    2010-03-26 11:10 . 2005-08-25 23:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
    2010-03-26 11:10 . 2010-03-26 11:12 -------- d-----w- c:\program files\SpywareBlaster
    2010-03-26 10:59 . 2010-03-26 12:00 -------- d-----w- c:\documents and settings\home\Application Data\QuickScan
    2010-03-25 22:21 . 2010-03-25 22:21 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
    2010-03-24 22:54 . 2010-01-07 20:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-03-24 22:54 . 2010-01-07 20:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-03-24 20:06 . 2010-03-26 21:26 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-03-24 20:05 . 2010-03-24 20:05 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
    2010-03-24 19:58 . 2010-03-26 12:22 -------- d-sh--w- c:\documents and settings\home\.COMMgr
    2010-03-24 19:57 . 2010-03-26 12:04 -------- d-----w- c:\windows\system32\msapps
    2010-03-24 19:57 . 2010-03-24 20:26 -------- d-----w- c:\documents and settings\home\Application Data\D8585968FC18271731C4ED43D7D5AD4E
    2010-03-23 22:26 . 2010-03-23 22:26 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
    2010-03-23 22:26 . 2010-03-23 22:26 -------- d-----w- c:\program files\DVDVideoSoft
    2010-03-23 22:19 . 2010-03-23 22:19 -------- d-----w- c:\documents and settings\home\Application Data\OxelonMC
    2010-03-23 22:19 . 2010-03-23 22:20 -------- d-----w- c:\program files\OxelonMedia
    2010-03-23 20:03 . 2010-03-23 20:03 -------- d-----w- c:\program files\Sun
    2010-03-23 20:00 . 2010-03-23 20:01 -------- d-----w- c:\documents and settings\home\.SunDownloadManager
    2010-03-22 10:35 . 2010-03-22 10:36 -------- d-----w- c:\documents and settings\home\Application Data\ProfitUI Reborn Updater
    2010-03-22 10:08 . 2010-03-22 10:08 -------- d-----w- c:\program files\Ventrilo
    2010-03-22 10:08 . 2010-03-22 10:08 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2010-03-22 09:51 . 2010-03-22 09:51 -------- d-----w- C:\_OTM
    2010-03-22 01:26 . 2010-03-22 01:26 -------- d-----w- c:\program files\Trend Micro
    2010-03-21 23:00 . 2010-03-21 23:00 -------- d-----w- c:\windows\Sun
    2010-03-21 18:41 . 2010-03-21 18:41 -------- d-----w- c:\documents and settings\home\Application Data\Malwarebytes
    2010-03-21 18:41 . 2010-03-21 18:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-03-21 18:41 . 2010-03-25 10:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-03-21 12:37 . 2010-03-21 12:37 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-03-21 07:06 . 2010-03-21 07:06 0 ----a-w- c:\windows\nsreg.dat
    2010-03-21 07:05 . 2010-03-21 07:05 -------- d-----w- c:\documents and settings\home\Local Settings\Application Data\Mozilla
    2010-03-21 07:02 . 2010-03-21 07:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Toolbar4
    2010-03-21 06:38 . 2008-04-13 17:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
    2010-03-21 06:38 . 2008-04-13 17:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
    2010-03-21 06:38 . 2001-08-18 02:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
    2010-03-21 06:38 . 2008-04-13 23:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
    2010-03-21 06:25 . 2010-03-21 06:25 -------- d-----w- c:\program files\WinSCP
    2010-03-21 06:21 . 2010-03-21 06:21 -------- d-----w- c:\documents and settings\home\Application Data\Windows Search
    2010-03-21 06:16 . 2009-12-17 21:14 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-03-21 05:22 . 2010-03-21 05:22 -------- d-----w- c:\program files\Sony
    2010-03-21 05:22 . 2010-03-21 05:22 -------- d-----w- c:\program files\Common Files\SWF Studio
    2010-03-21 05:20 . 2010-03-21 05:20 13104 ----a-w- c:\documents and settings\home\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-03-21 05:19 . 2010-03-21 06:39 -------- d-----w- c:\documents and settings\home\Application Data\Apple Computer
    2010-03-21 05:19 . 2009-05-18 18:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-03-21 05:19 . 2008-04-17 17:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
    2010-03-21 05:17 . 2010-03-21 05:20 -------- d-----w- c:\documents and settings\home\Local Settings\Application Data\Apple Computer
    2010-03-21 04:09 . 2010-03-22 09:46 -------- d-----w- c:\documents and settings\home\Local Settings\Application Data\ApplicationHistory
    2010-03-21 04:04 . 2010-03-21 04:04 -------- d-----w- c:\documents and settings\home\Application Data\Yahoo!
    2010-03-21 04:04 . 2010-03-21 07:17 -------- d-----w- c:\program files\Yahoo!
    2010-03-21 04:04 . 2010-03-21 04:04 -------- d-----w- c:\program files\CCleaner

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-03-26 23:14 . 2010-03-26 11:40 8279191 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
    2010-03-26 22:27 . 2010-03-21 03:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-03-26 18:33 . 2010-03-26 21:18 668648 ----a-w- c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    2010-03-26 18:33 . 2010-03-26 21:18 830864 ----a-w- c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    2010-03-26 11:14 . 2010-03-26 11:14 -------- d-----w- c:\documents and settings\home\Application Data\CheckPoint
    2010-03-26 11:14 . 2010-03-26 11:14 -------- d-----w- c:\program files\CheckPoint
    2010-03-26 11:14 . 2010-03-26 11:14 4212 ---ha-w- c:\windows\system32\zllictbl.dat
    2010-03-26 11:14 . 2010-03-26 11:14 -------- d-----w- c:\program files\Zone Labs
    2010-03-25 01:08 . 2004-08-12 14:11 477952 ----a-w- c:\windows\system32\drivers\iaStor.sys
    2010-03-24 20:30 . 2010-03-21 03:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-03-23 20:03 . 2010-03-21 02:59 -------- d-----w- c:\program files\Java
    2010-03-21 22:09 . 2010-03-21 02:59 -------- d-----w- c:\program files\Common Files\Java
    2010-03-21 22:09 . 2010-03-21 22:09 348160 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bdbf744-n\msvcr71.dll
    2010-03-21 22:09 . 2010-03-21 22:09 61440 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-63ad000f-n\decora-sse.dll
    2010-03-21 22:09 . 2010-03-21 22:09 503808 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bdbf744-n\msvcp71.dll
    2010-03-21 22:09 . 2010-03-21 22:09 499712 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bdbf744-n\jmc.dll
    2010-03-21 22:09 . 2010-03-21 22:09 12800 ----a-w- c:\documents and settings\home\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-63ad000f-n\decora-d3d.dll
    2010-03-21 12:37 . 2010-03-21 03:58 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2010-03-21 12:37 . 2010-03-21 03:58 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2010-03-21 12:37 . 2010-03-21 03:58 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2010-03-21 06:38 . 2010-03-21 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
    2010-03-21 05:22 . 2010-03-21 03:55 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-03-21 05:19 . 2010-03-21 05:19 -------- d-----w- c:\program files\iTunes
    2010-03-21 05:19 . 2010-03-21 05:19 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2010-03-21 05:19 . 2010-03-21 05:19 -------- d-----w- c:\program files\iPod
    2010-03-21 05:19 . 2010-03-21 05:17 -------- d-----w- c:\program files\Common Files\Apple
    2010-03-21 05:19 . 2010-03-21 05:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2010-03-21 05:18 . 2010-03-21 05:18 -------- d-----w- c:\program files\Bonjour
    2010-03-21 05:18 . 2010-03-21 05:18 -------- d-----w- c:\program files\QuickTime
    2010-03-21 05:18 . 2010-03-21 05:18 -------- d-----w- c:\program files\Apple Software Update
    2010-03-21 04:20 . 2010-03-21 03:35 -------- d-----w- c:\program files\Windows Desktop Search
    2010-03-21 03:58 . 2010-03-21 03:58 -------- d-----w- c:\program files\AVG
    2010-03-21 03:58 . 2010-03-21 03:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
    2010-03-21 03:58 . 2010-03-21 03:58 -------- d-----w- c:\program files\Broadcom
    2010-03-21 03:58 . 2010-03-21 03:55 -------- d-----w- c:\program files\Common Files\InstallShield
    2010-03-21 03:57 . 2010-03-21 03:57 -------- d-----w- c:\program files\Intel
    2010-03-21 03:56 . 2010-03-21 03:56 -------- d-----w- c:\program files\Analog Devices
    2010-03-21 03:48 . 2010-03-21 03:48 -------- d-----w- c:\program files\microsoft frontpage
    2010-03-21 03:48 . 2010-03-26 11:30 0 ----a-w- c:\documents and settings\home\Application Data\WinPatrol\Config.sys
    2010-03-21 03:48 . 2010-03-26 11:30 0 ----a-w- c:\documents and settings\home\Application Data\WinPatrol\Autoexec.bat
    2010-03-21 03:46 . 2010-03-21 03:46 -------- d-----w- c:\program files\NVIDIA Corporation
    2010-03-21 03:46 . 2010-03-21 03:46 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
    2010-03-21 03:45 . 2010-03-21 03:45 21640 ----a-w- c:\windows\system32\emptyregdb.dat
    2010-03-21 03:39 . 2010-03-21 03:39 -------- d-----w- c:\program files\MSBuild
    2010-03-21 03:39 . 2010-03-21 03:39 -------- d-----w- c:\program files\Reference Assemblies
    2010-03-21 03:36 . 2010-03-21 03:36 -------- d-----w- c:\documents and settings\home\Application Data\Windows Desktop Search
    2010-03-21 03:35 . 2010-03-21 03:35 -------- d-----w- c:\program files\Windows Media Connect 2
    2010-03-21 03:23 . 2010-03-21 03:47 77423 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2010-02-15 22:41 . 2010-02-15 22:41 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
    2010-02-04 15:53 . 2010-03-26 11:47 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
    2010-01-27 02:04 . 2010-03-21 07:02 60592 ----a-w- c:\documents and settings\All Users\Application Data\Toolbar4\{0C8413C1-FAD1-446C-8584-BE50576F863E}\update.exe
    2010-01-27 02:04 . 2010-03-21 07:02 46256 ----a-w- c:\documents and settings\All Users\Application Data\Toolbar4\{0C8413C1-FAD1-446C-8584-BE50576F863E}\uninstall.exe
    2010-01-12 17:03 . 2010-03-21 03:12 10276768 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
    2010-01-12 17:03 . 2010-01-12 17:03 61440 ----a-w- c:\windows\system32\OpenCL.dll
    2010-01-12 17:03 . 2010-01-12 17:03 4104192 ----a-w- c:\windows\system32\nvcuda.dll
    2010-01-12 17:03 . 2010-01-12 17:03 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
    2010-01-12 17:03 . 2010-01-12 17:03 2283526 ----a-w- c:\windows\system32\nvdata.bin
    2010-01-12 17:03 . 2010-01-12 17:03 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
    2010-01-12 17:03 . 2010-01-12 17:03 182888 ----a-w- c:\windows\system32\nvcodins.dll
    2010-01-12 17:03 . 2010-01-12 17:03 182888 ----a-w- c:\windows\system32\nvcod.dll
    2010-01-12 17:03 . 2010-01-12 17:03 14458880 ----a-w- c:\windows\system32\nvoglnt.dll
    2010-01-12 17:03 . 2010-01-12 17:03 11632640 ----a-w- c:\windows\system32\nvcompiler.dll
    2010-01-12 17:03 . 2010-01-12 17:03 1081344 ----a-w- c:\windows\system32\nvapi.dll
    2010-01-12 17:03 . 2008-04-14 00:12 6359168 ----a-w- c:\windows\system32\nv4_disp.dll
    2010-01-12 03:17 . 2010-01-12 03:17 278120 ----a-w- c:\windows\system32\nvmccs.dll
    2010-01-12 03:17 . 2010-01-12 03:17 154216 ----a-w- c:\windows\system32\nvsvc32.exe
    2010-01-12 03:17 . 2010-01-12 03:17 145000 ----a-w- c:\windows\system32\nvcolor.exe
    2010-01-12 03:17 . 2010-01-12 03:17 13666408 ----a-w- c:\windows\system32\nvcpl.dll
    2010-01-12 03:17 . 2010-01-12 03:17 110696 ----a-w- c:\windows\system32\nvmctray.dll
    2010-01-12 03:17 . 2010-01-12 03:17 81920 ----a-w- c:\windows\system32\nvwddi.dll
    2009-12-31 16:50 . 2004-08-12 14:06 353792 ----a-w- c:\windows\system32\drivers\srv.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP "= "c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 1388544]
    "IAAnotif "= "c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
    "ZoneAlarm Client "= "c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-11-22 1037192]
    "ISW "= "c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2009-10-14 730480]
    "WinPatrol "= "c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]

    c:\documents and settings\home\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-3-23 503808]
    SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5} "= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2010-03-21 12:37 12464 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @= "Service "

    [HKLM\~\startupfolder\C:^Documents and Settings^home^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\documents and settings\home\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
    2010-01-07 20:07 429392 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)
    "DisableNotifications "= 1 (0x1)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\AVG\\AVG9\\avgemc.exe "=
    "c:\\Program Files\\AVG\\AVG9\\avgupd.exe "=
    "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Program Files\\Sony\\Station\\Launchpad\\LaunchPad.exe "=
    "c:\\Program Files\\Ventrilo\\Ventrilo.exe "=
    "c:\\Program Files\\Sony\\EverQuest II\\EQ2VoiceService.exe "=
    "c:\\WINDOWS\\system32\\spoolsv.exe "=
    "c:\\Program Files\\LimeWire\\LimeWire.exe "=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/26/2010 7:50 AM 64288]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/20/2010 11:58 PM 216200]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/20/2010 11:58 PM 242696]
    R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3/21/2010 8:37 AM 916760]
    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/21/2010 8:37 AM 308064]
    R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [10/14/2009 9:30 AM 25208]
    R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [10/14/2009 9:30 AM 476528]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1263728]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-03-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 11:49]

    2010-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.whtm.com/
    uInternet Settings,ProxyOverride = *.local
    TCP: {7076810B-EFD8-4D07-9781-31A5C01D8A1A} = 217.23.14.75,4.2.2.1,192.168.2.1
    FF - ProfilePath - c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\
    FF - prefs.js: browser.search.selectedEngine - Bing
    FF - prefs.js: browser.startup.homepage - www.msn.com
    FF - component: c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
    FF - plugin: c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\lkk0n11m.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{25526b16-f633-481c-8891-b9f8903112a4} - (no file)



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-03-26 19:16
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(672)
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

    - - - - - - - > 'lsass.exe'(728)
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

    - - - - - - - > 'explorer.exe'(2464)
    c:\windows\system32\WININET.dll
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
    c:\program files\Windows Desktop Search\deskbar.dll
    c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
    c:\program files\Windows Desktop Search\dbres.dll
    c:\program files\Windows Desktop Search\wordwheel.dll
    c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
    c:\program files\Windows Desktop Search\msnlExtRes.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\WinSCP\DragExt.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
    c:\program files\SpywareGuard\spywareguard.dll
    c:\program files\SpywareGuard\dlprotect.dll
    c:\program files\Spybot - Search & Destroy\SDHelper.dll
    c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    c:\windows\system32\nvcpl.dll
    c:\windows\system32\nvapi.dll
    c:\program files\NVIDIA Corporation\nView\nvshell.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\nvsvc32.exe
    c:\program files\AVG\AVG9\avgchsvx.exe
    c:\program files\AVG\AVG9\avgrsx.exe
    c:\program files\AVG\AVG9\avgcsrvx.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Intel\Intel Application Accelerator\iaantmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\SearchIndexer.exe
    c:\program files\AVG\AVG9\avgnsx.exe
    c:\program files\AVG\AVG9\avgcsrvx.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
    c:\program files\SpywareGuard\sgbhp.exe
    .
    **************************************************************************
    .
    Completion time: 2010-03-26 19:22:52 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-03-26 23:22
    ComboFix2.txt 2010-03-26 22:29
    ComboFix3.txt 2010-03-21 19:46

    Pre-Run: 137,463,320,576 bytes free
    Post-Run: 137,482,784,768 bytes free

    - - End Of File - - AC2132D2DA43AE08C3A5FED1B41EA064
     
  9. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:24:54 PM, on 3/26/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.whtm.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon= "hidden "
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7076810B-EFD8-4D07-9781-31A5C01D8A1A}: NameServer = 217.23.14.75,4.2.2.1,192.168.2.1
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 7131 bytes
     
  10. 2010/03/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall Combofix:
    Go Start > Run [Vista users, go Start> "Start search"]
    Type in:
    Combofix /Uninstall
    Note the space between the "Combofix" and the "/Uninstall "
    Click OK (Vista users - press Enter).
    Restart computer.

    ================================================================

    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Malwarebytes before running the scans.***


    STEP 1. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform Quick Scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 2.
    Post fresh HijackThis log.
    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  11. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    cant uninstall combo fix , after running the script from your last post.
    i try to uninstall it witht he command you posted and it says cant fin combofix ,make sure its spelled corectly , or click start search to find it.
    running a malwarebytes quick scan now
     
  12. 2010/03/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Delete Combofix manually....
    Delete Combofix, Qoobox folders,and Combofix.txt file from C:
    Delete Combofix from your desktop
     
  13. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    redirection issue seems to be fixed
     
  14. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    Malwarebytes' Anti-Malware 1.44
    Database version: 3510
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    3/26/2010 7:39:42 PM
    mbam-log-2010-03-26 (19-39-42).txt

    Scan type: Quick Scan
    Objects scanned: 102199
    Time elapsed: 3 minute(s), 42 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    quick scan found nothing, but it didnt find anything before i started the topic when the problems were there .
     
  15. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:47:20 PM, on 3/26/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.whtm.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {25526b16-f633-481c-8891-b9f8903112a4} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon= "hidden "
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7076810B-EFD8-4D07-9781-31A5C01D8A1A}: NameServer = 217.23.14.75,4.2.2.1,192.168.2.1
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 7264 bytes
     
  16. 2010/03/26
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    time to go to work, ill check thread in the morning when i get home =)
     
  17. 2010/03/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very good :)

    1. Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.


    2. Go to Kaspersky website and perform an online antivirus scan.

    1. Disable your active antivirus program.
    2. Read through the requirements and privacy statement and click on Accept button.
    3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    4. When the downloads have finished, click on Settings.
    5. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

    • Spyware, Adware, Dialers, and other potentially dangerous programs
      [*] Archives
      [*] Mail databases
    6. Click on My Computer under Scan.
    7. Once the scan is complete, it will display the results. Click on View Scan Report.
    8. You will see a list of infected items there. Click on Save Report As....
    9. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

    Post fresh HijackThis log as well.
     
  18. 2010/03/27
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:39:25 PM, on 3/27/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.whtm.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {25526b16-f633-481c-8891-b9f8903112a4} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon= "hidden "
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7076810B-EFD8-4D07-9781-31A5C01D8A1A}: NameServer = 217.23.14.75,4.2.2.1,192.168.2.1
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 6985 bytes
     
  19. 2010/03/27
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Saturday, March 27, 2010
    Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Saturday, March 27, 2010 06:06:02
    Records in database: 3880125
    Scan settings
    scan using the following database extended
    Scan archives yes
    Scan e-mail databases yes
    Scan area My Computer
    A:\
    C:\
    D:\
    E:\
    Scan statistics
    Objects scanned 47254
    Threats found 4
    Infected objects found 5
    Suspicious objects found 0
    Scan duration 01:24:21

    File name Threat Threats count
    C:\Qoobox\Quarantine\C\WINDOWS\Nmanaa.exe.vir Infected: Backdoor.Win32.Agent.aqzv 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\iaStor.sys.vir Infected: Rootkit.Win32.Tdss.ai 1
    C:\System Volume Information\_restore{68414456-E059-4322-8DE2-002DF6625E69}\RP2\A0001381.exe Infected: Trojan.Win32.Scar.bueu 1
    C:\System Volume Information\_restore{68414456-E059-4322-8DE2-002DF6625E69}\RP2\A0003731.exe Infected: Backdoor.Win32.Agent.aqzv 1
    C:\_OTM\MovedFiles\03232010_150042\C_Program Files\Mozilla Firefox\extensions\{b213b800-b50c-14f4-a353-7f58602f49f1}\components\--_4f_71L.dll Infected: not-a-virus:AdWare.Win32.EZula.alm 1
    Selected area has been scanned.
     
  20. 2010/03/27
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    redirect problem still there =(
    seems to only happen on google tho
     
  21. 2010/03/27
    gideon01

    gideon01 Inactive Thread Starter

    Joined:
    2010/03/21
    Messages:
    67
    Likes Received:
    0
    here is a full malwarebytes scan log , has a few things the quick scan didnt find

    Malwarebytes' Anti-Malware 1.44
    Database version: 3510
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    3/27/2010 4:39:16 PM
    mbam-log-2010-03-27 (16-39-11).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 148790
    Time elapsed: 41 minute(s), 53 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\System Volume Information\_restore{68414456-E059-4322-8DE2-002DF6625E69}\RP2\A0003647.sys (Malware.Trace) -> No action taken.
    C:\System Volume Information\_restore{68414456-E059-4322-8DE2-002DF6625E69}\RP2\A0003832.sys (Malware.Trace) -> No action taken.
     
    Last edited: 2010/03/27

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.