![]() |
|
|||||||
| [Fixed] Hijackthis! Logs - Google redirect virus help!! posted in the Security & Safety forums; I am having a crapload of trouble getting this off of my computer i have been scanning, downloading, and deleting for days now and I have come to the mercy ... |
|
|
|
#1 |
|
Bronze Member
![]() Join Date: Oct 2009
Posts: 11 PC Experience: Very Experienced
|
I am having a crapload of trouble getting this off of my computer i have been scanning, downloading, and deleting for days now and I have come to the mercy of this forum for help i am a semi experienced computer user and i can't run safe mode it gives me a error but normal mode is perfectly fine it's just that when i click on something on google it takes me to z with a bunch of random numbers and says the page is invaild or it takes me to a stupid video on youtube i have mcafee, windows defender, hijack this, superantispyware, malware bytes, combofix, spyware doctor, and drwebcure it i have tried it all i have never had this much trouble with anything computer related and when i scan on mcafee, win def, malware bytes, it finds nothing,but spyware doctor finds a couple low risk cookies, and adware but they keep coming back so if you can help me that would be greatly appreciated
|
|
|
|
| Advertisement - Register to Remove | |
|
|
|
#2 |
|
Moderator
![]() ![]() Join Date: May 2009
Location: Illinois
Posts: 361 PC Experience: Some Experience
|
Hello and Welcome to PCHF
If you would please follow my prework link below and post your logs in this thread. A Senior Security staff member will be with you soon. I will move your thread to the HJT logs(new). Thank You Skindred |
|
|
|
|
|
#3 |
|
Bronze Member
![]() Join Date: Oct 2009
Posts: 11 PC Experience: Very Experienced
|
here they are
ComboFix 09-10-27.08 - Alan 10/28/2009 16:42.1.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.421 [GMT -5:00] Running from: c:\documents and settings\Alan\Desktop\Combo-fix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Alan\Application Data\gyboz.inf c:\documents and settings\Alan\Application Data\iniasd.txt c:\documents and settings\Alan\Application Data\yluhuleguf.inf c:\documents and settings\Alan\Local Settings\Application Data\rucic.pif c:\documents and settings\All Users\Application Data\akit.com c:\documents and settings\All Users\Application Data\aridu.lib c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat c:\documents and settings\All Users\Application Data\otak.dll c:\documents and settings\All Users\Application Data\rury.sys c:\documents and settings\All Users\Application Data\ymiz.sys c:\documents and settings\All Users\Documents\ixomy.pif c:\documents and settings\All Users\Documents\loqeva.bin c:\documents and settings\All Users\Documents\pibohapy.sys c:\program files\Common Files\inisuwa.sys c:\program files\Common Files\viqefany.pif c:\program files\WinPCap c:\program files\WinPCap\rpcapd.exe c:\temp\DIV55 c:\temp\DIV55\xDb.log c:\temp\tn3 c:\windows\etufijos.dl c:\windows\mozaq.exe c:\windows\subo.inf c:\windows\system32\bin c:\windows\system32\drivers\npf.sys c:\windows\system32\ki3 c:\windows\system32\kuwopo._sy c:\windows\system32\Packet.dll c:\windows\system32\pthreadVC.dll c:\windows\system32\tmp.reg c:\windows\system32\uv9 c:\windows\system32\VC c:\windows\system32\WanPacket.dll c:\windows\system32\wpcap.dll c:\windows\system32\yfazovih.pif c:\windows\uwulep.bat ----- BITS: Possible infected sites ----- hxxp://dna65.fastaccess.com Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected Restored copy from - Kitty ate it . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_NPF ((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 ))))))))))))))))))))))))))))))) . 2009-10-28 17:28 . 2009-10-28 17:28 -------- d-----w- c:\documents and settings\Alan\Local Settings\Application Data\Threat Expert 2009-10-28 17:19 . 2009-10-08 16:31 767952 ----a-w- c:\windows\BDTSupport.dll 2009-10-28 17:19 . 2009-10-08 16:31 149456 ----a-w- c:\windows\SGDetectionTool.dll 2009-10-28 17:19 . 2009-10-08 16:31 165840 ----a-w- c:\windows\PCTBDRes.dll 2009-10-28 17:19 . 2009-10-08 16:31 1636304 ----a-w- c:\windows\PCTBDCore.dll 2009-10-28 17:19 . 2009-10-02 19:19 1152470 ----a-w- c:\windows\UDB.zip 2009-10-28 17:19 . 2008-11-26 17:08 131 ----a-w- c:\windows\IDB.zip 2009-10-28 17:16 . 2009-09-24 13:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2009-10-28 17:16 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2009-10-28 17:16 . 2009-09-23 21:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2009-10-28 17:16 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2009-10-28 17:16 . 2009-10-28 22:05 -------- d-----w- c:\program files\Spyware Doctor 2009-10-28 17:16 . 2009-10-28 17:20 -------- d-----w- c:\program files\Common Files\PC Tools 2009-10-28 17:16 . 2009-10-28 17:16 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2009-10-28 17:16 . 2009-10-28 17:16 -------- d-----w- c:\documents and settings\Alan\Application Data\PC Tools 2009-10-28 17:04 . 2009-10-28 17:04 -------- d-----w- C:\Combo-fix 2009-10-27 22:57 . 2009-10-27 23:01 111197 ----a-w- C:\MGlogs.zip 2009-10-27 22:57 . 2009-10-27 23:02 -------- d-----w- C:\MGtools 2009-10-27 21:41 . 2009-10-27 22:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-10-27 21:41 . 2009-10-27 21:45 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-10-27 02:52 . 2009-10-27 22:17 16750112 ----a-w- c:\documents and settings\Alan\ATT_SST_Installer.exe 2009-10-27 02:27 . 2009-10-27 02:27 -------- d-----w- c:\documents and settings\Alan\Application Data\AVG8 2009-10-27 01:19 . 2009-10-27 01:19 -------- d-----w- c:\program files\AxBx 2009-10-26 23:14 . 2009-10-26 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-10-26 23:14 . 2009-10-26 23:14 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-10-26 23:14 . 2009-10-26 23:14 -------- d-----w- c:\documents and settings\Alan\Application Data\SUPERAntiSpyware.com 2009-10-26 23:13 . 2009-10-26 23:13 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-10-26 01:47 . 2009-10-27 02:06 -------- d-----w- c:\program files\Eusing Free Registry Cleaner 2009-10-25 23:17 . 2009-10-25 23:17 -------- d-----w- c:\documents and settings\Alan\Application Data\Malwarebytes 2009-10-25 23:17 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-25 23:16 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-22 21:25 . 2009-10-22 21:25 19 ----a-w- c:\documents and settings\Alan\killbat.bat 2009-10-14 21:34 . 2009-10-14 21:34 -------- d-----w- c:\documents and settings\Alan\Application Data\WebCam Recorder 2009-10-14 21:34 . 2009-10-14 21:34 -------- d-----w- c:\program files\Solent 2009-10-14 21:18 . 2009-10-14 21:18 -------- d-----w- c:\program files\LEDSET 2009-10-14 21:08 . 2007-08-13 19:51 446464 ----a-w- c:\windows\system32\wmvdmoe.dll 2009-10-14 21:08 . 2009-10-14 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\PY_Software 2009-10-14 20:32 . 2008-04-13 17:39 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys 2009-10-14 20:32 . 2008-04-13 17:39 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys 2009-10-14 20:32 . 2008-04-13 17:46 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys 2009-10-14 20:32 . 2008-04-13 17:46 10880 ----a-w- c:\windows\system32\dllcache\ndisip.sys 2009-10-14 20:32 . 2008-04-13 17:46 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys 2009-10-14 20:32 . 2008-04-13 17:46 15232 ----a-w- c:\windows\system32\dllcache\streamip.sys 2009-10-14 20:31 . 2008-04-13 17:46 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys 2009-10-14 20:31 . 2008-04-13 17:46 11136 ----a-w- c:\windows\system32\dllcache\slip.sys 2009-10-14 20:31 . 2008-04-13 17:46 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS 2009-10-14 20:31 . 2008-04-13 17:46 19200 ----a-w- c:\windows\system32\dllcache\wstcodec.sys 2009-10-14 20:31 . 2008-04-13 17:46 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys 2009-10-14 20:31 . 2008-04-13 17:46 85248 ----a-w- c:\windows\system32\dllcache\nabtsfec.sys 2009-10-14 20:31 . 2008-04-13 17:46 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys 2009-10-14 20:31 . 2008-04-13 17:46 17024 ----a-w- c:\windows\system32\dllcache\ccdecode.sys 2009-10-14 20:30 . 2008-04-13 23:12 53760 ----a-w- c:\windows\system32\vfwwdm32.dll 2009-10-14 20:30 . 2008-04-13 23:12 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll 2009-10-14 00:47 . 2009-10-14 00:47 -------- d-----w- c:\documents and settings\Alan\Application Data\Publish Providers 2009-10-14 00:47 . 2009-10-14 00:47 -------- d-----w- c:\documents and settings\Alan\Local Settings\Application Data\Sony 2009-10-14 00:37 . 2009-10-14 00:47 -------- d-----w- c:\documents and settings\Alan\Application Data\Sony 2009-10-14 00:35 . 2009-10-20 16:29 -------- d-----w- c:\program files\Sony 2009-10-14 00:34 . 2009-10-14 00:34 -------- d-----w- c:\program files\Sony Setup 2009-10-12 22:01 . 2009-10-12 22:15 -------- d-----w- c:\program files\PVPXX 2009-10-12 13:12 . 2009-09-23 15:41 26176 ---ha-w- c:\windows\system32\hamachi.sys 2009-10-05 23:20 . 2009-10-05 23:20 -------- d-----w- C:\Sun 2009-10-05 23:04 . 2009-10-05 23:16 -------- d-----w- c:\documents and settings\Alan\.SunDownloadManager 2009-10-04 20:52 . 2009-10-04 20:52 11933 ----a-w- c:\windows\begofyn.com 2009-10-03 18:03 . 2009-10-01 15:29 195440 ------w- c:\windows\system32\MpSigStub.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2009-10-28 22:05 . 2008-12-07 03:01 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-28 20:06 . 2008-12-10 00:38 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore 2009-10-28 03:15 . 2008-12-06 03:30 -------- d-----w- c:\program files\Unlocker 2009-10-28 03:01 . 2008-12-10 00:21 -------- d-----w- c:\program files\McAfee 2009-10-28 00:01 . 2007-08-02 03:24 -------- d-----w- c:\program files\Windows Live Safety Center 2009-10-27 22:26 . 2006-08-25 23:36 -------- d-----w- c:\program files\Common Files\Motive 2009-10-27 22:17 . 2006-08-25 23:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive 2009-10-27 02:54 . 2006-08-11 03:32 -------- d-----w- c:\program files\Common Files\Jasc Software Inc 2009-10-27 02:51 . 2006-08-11 03:32 -------- d-----w- c:\documents and settings\Alan\Application Data\Jasc Software Inc 2009-10-27 02:33 . 2008-12-06 04:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8 2009-10-27 00:17 . 2007-12-21 19:00 -------- d-----w- c:\program files\Bellsouth 2009-10-26 23:07 . 2006-08-08 07:13 -------- d-----w- c:\program files\WildTangent 2009-10-26 23:06 . 2006-08-08 07:08 -------- d-----w- c:\program files\Dell 2009-10-25 23:17 . 2008-12-06 03:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-24 23:12 . 2008-12-08 22:23 21870 ----a-w- c:\documents and settings\Everybody\Application Data\wklnhst.dat 2009-10-22 21:53 . 2006-08-29 00:43 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent 2009-10-22 21:53 . 2006-08-29 00:44 -------- d-----w- c:\program files\Dell Games 2009-10-22 21:24 . 2008-11-02 02:28 -------- d-----w- c:\program files\Sun 2009-10-22 21:20 . 2006-08-08 07:04 -------- d-----w- c:\program files\Java 2009-10-21 00:55 . 2006-08-22 22:51 29390 ----a-w- c:\documents and settings\Alan\Application Data\wklnhst.dat 2009-10-20 16:25 . 2009-08-17 22:55 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2009-10-15 03:32 . 2006-08-08 07:17 -------- d-----w- c:\program files\Microsoft Works 2009-10-09 13:29 . 2006-08-08 07:18 -------- d-----w- c:\program files\Microsoft Money 2006 2009-10-04 13:04 . 2006-08-11 03:30 -------- d-----w- c:\program files\Dl_cats 2009-09-23 21:57 . 2009-03-01 17:36 58600 ----a-w- c:\documents and settings\Connor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-16 15:22 . 2008-12-10 00:22 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-09-16 15:22 . 2008-12-10 00:22 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys 2009-09-16 15:22 . 2008-12-10 00:22 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2009-09-16 15:22 . 2008-06-27 12:08 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2009-09-16 15:22 . 2008-12-10 00:20 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys 2009-09-16 08:20 . 2009-10-28 17:16 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat 2009-09-15 11:20 . 2009-10-28 17:16 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat 2009-09-15 07:12 . 2009-10-28 17:16 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat 2009-09-15 06:01 . 2009-10-28 17:16 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat 2009-09-11 14:18 . 2008-10-25 00:03 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-09 23:49 . 2009-09-09 21:46 540 ----a-w- c:\windows\system32\drivers\sthdae.log 2009-09-09 22:26 . 2009-09-09 22:26 -------- d-----w- c:\documents and settings\Alan\Application Data\Blitware 2009-09-09 21:44 . 2006-08-08 07:08 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-09-04 21:03 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-09-04 00:29 . 2009-09-04 00:29 -------- d-----w- c:\documents and settings\Alan\Application Data\Mael 2009-09-02 12:52 . 2009-09-02 12:52 -------- d-----w- c:\documents and settings\Everybody\Application Data\Datel 2009-09-02 01:00 . 2008-12-14 00:17 58600 ----a-w- c:\documents and settings\Everybody\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-02 00:27 . 2006-08-11 01:50 58600 ----a-w- c:\documents and settings\Alan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-02 00:22 . 2009-09-02 00:22 -------- d-----w- c:\program files\MSBuild 2009-09-02 00:22 . 2009-09-02 00:22 -------- d-----w- c:\program files\Reference Assemblies 2009-09-01 23:47 . 2009-09-01 23:47 -------- d-----w- c:\documents and settings\Alan\Application Data\Datel 2009-08-29 07:36 . 2004-08-10 17:51 832512 ----a-w- c:\windows\system32\wininet.dll 2009-08-29 07:36 . 2004-08-10 17:51 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-08-29 07:36 . 2004-08-10 17:50 17408 ----a-w- c:\windows\system32\corpol.dll 2009-08-27 21:05 . 2009-08-27 21:04 34 ----a-w- c:\documents and settings\Connor\jagex_runescape_preferences.dat 2009-08-26 08:00 . 2004-08-10 17:51 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-20 20:09 . 2009-08-20 20:09 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-19 01:01 . 2008-12-10 21:28 34 ----a-w- c:\documents and settings\Everybody\jagex_runescape_preferences.dat 2009-08-07 01:10 . 2009-05-30 19:18 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-08-07 01:10 . 2009-05-30 19:18 88 --sh--r- c:\windows\system32\3F285D0D6D.sys 2009-08-05 09:01 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 15:13 . 2008-10-25 00:03 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20 . 2008-10-25 00:03 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe 2004-08-04 10:00 . 2004-08-10 17:51 94784 --sh--w- c:\windows\twain.dll 2008-04-14 00:12 . 2008-10-25 00:03 551936 --sha-w- c:\windows\system32\oleaut32.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{472734EA-242A-422B-ADF8-83D1E48CC825}"= "c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll" [2009-10-08 395216] [HKEY_CLASSES_ROOT\clsid\{472734ea-242a-422b-adf8-83d1e48cc825}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{175B7885-28AB-4D18-8773-7A13A99980A4}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{472734EA-242A-422B-ADF8-83D1E48CC825}"= "c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll" [2009-10-08 395216] [HKEY_CLASSES_ROOT\clsid\{472734ea-242a-422b-adf8-83d1e48cc825}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{175B7885-28AB-4D18-8773-7A13A99980A4}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-28 68856] "DellSupport-"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-10-13 2000112] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X 86\3\DLCCtime.dll" [2005-09-14 73728] "lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-08 74672] "FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 295856] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736] "HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-04-13 198184] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208] "dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940] "CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2000-08-14 32768] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696] "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-09-22 1243088] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-02-26 437160] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce] "RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2008-12-06 03:18 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^Alan^Start Menu^Programs^Startup^Camio Viewer.lnk] backup=c:\windows\pss\Camio Viewer.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Auto Detect.lnk] backup=c:\windows\pss\Auto Detect.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk] backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "tmproxy"=2 (0x2) "TmPfw"=2 (0x2) "Tmntsrv"=2 (0x2) "PcCtlCom"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"= "c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\lxczcoms.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\McAfee\\VirusScan\\mcods.exe"= "c:\\Program Files\\Windows Defender\\MsMpEng.exe"= R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/28/2009 12:16 PM 207280] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 9:24 PM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 9:24 PM 74480] R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [10/28/2009 12:19 PM 112592] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/9/2008 7:25 PM 210216] R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/28/2009 12:16 PM 358600] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 9:24 PM 7408] S1 Hdaudioo;Hdaudioo; [x] S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] --- Other Services/Drivers In Memory --- *Deregistered* - mbr *Deregistered* - PCTSDInjDriver32 . Contents of the 'Scheduled Tasks' folder 2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34] 2009-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1258719614-4290492059-3762695196-1011Core.job - c:\documents and settings\Everybody\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-10 00:37] 2009-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1258719614-4290492059-3762695196-1011UA.job - c:\documents and settings\Everybody\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-10 00:37] 2009-06-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-10 17:22] 2009-08-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-10 17:22] . . ------- Supplementary Scan ------- . uStart Page = hxxp://my.att.net/ uInternet Settings,ProxyOverride = *.local Trusted Zone: musicmatch.com\online DPF: {EA7F451B-94DD-4009-A8BF-8F977B0B2696} - hxxp://pbells.broadjump.com/wizlet/StandardInstall/static/controls/WebflowActiveXInstaller_4-2-0.cab . - - - - ORPHANS REMOVED - - - - BHO-{C2875410-9359-471E-8CAE-3DEBC361F14A} - (no file) WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) SharedTaskScheduler-{55e21788-a65f-416c-b71d-8a24db927486} - (no file) ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file) SSODL-yetawasok-{55e21788-a65f-416c-b71d-8a24db927486} - (no file) ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-28 17:03 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtim e.dll,_RunDLLEntry@16????????????????????????????? ?????????????????????????????????????????????????? ?????????????????????????????????????????????????? ?????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************** ************************ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(644) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll - - - - - - - > 'explorer.exe'(2132) c:\windows\system32\WININET.dll c:\program files\Spyware Doctor\pctgmhk.dll c:\program files\McAfee\SiteAdvisor\saHook.dll c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\lxczcoms.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\program files\McAfee\MPF\MPFSrv.exe c:\program files\McAfee\MSK\MskSrver.exe c:\program files\Spyware Doctor\pctsSvc.exe c:\progra~1\mcafee.com\agent\mcagent.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\combo-fix6337c\CF30780.exe c:\program files\Lexmark 1200 Series\lxczbmon.exe c:\program files\Microsoft IntelliPoint\dpupdchk.exe c:\program files\iPod\bin\iPodService.exe c:\windows\system32\dlcccoms.exe c:\progra~1\McAfee\VIRUSS~1\mcshield.exe c:\combo-fix6337c\PEV.cfxxe . ************************************************** ************************ . Completion time: 2009-10-28 17:11 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-28 22:11 Pre-Run: 53,365,575,680 bytes free Post-Run: 54,220,865,536 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /fastdetect /NoExecute=OptIn - - End Of File - - 287EF021CA53A9C92F49E108FF7B9959 Last edited by Pancake; 3 Weeks Ago at 12:30 AM. Reason: Copied and pasted for better viewing.... |
|
|
|
|
|
#4 |
|
Senior Security Analyst
![]() Join Date: Jun 2006
Location: Victoria, Australia
Posts: 6,863 PC Experience: Elite PC Guru
|
You should never run Combofix unless asked to do so.It is a powerful tool...I will look at you log.In the meantime please run this..
Please download Malwarebytes' Anti-Malware from one of these places: |MG| Malwarebytes Anti-Malware 1.41 Download http://www.besttechie.net/tools/mbam-setup.exe Double Click mbam-setup.exe to install the application. If it will not run make a copy of the MBAM.exe and rename MBAM.exe to xxx.exe and run that.Keep the genuine MBAM.exe as we may need to run that later as is. * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select "Perform Quick Scan", then click Scan. * The scan may take some time to finish,so please be patient. * When the scan is complete, click OK, then Show Results to view the results. * Make sure that everything is checked, and click Remove Selected. * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. * Copy&Paste the entire report in your next reply along with a fresh HijackThis log. PLEASE NOTE: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you after scanning with MBAM. Please temporarily disable such programs or permit them to allow the changes. Once that Malwarebytes' Anti-Malware is done removing the malware and you have rebooted the computer, browse around and see if you are still having that problem.
__________________
My real name is Eddy
|
|
|
|
|
|
#5 |
|
Bronze Member
![]() Join Date: Oct 2009
Posts: 11 PC Experience: Very Experienced
|
i am very familiar with combo-fix.exe sorry though i will run malwarebytes right now
|
|
|
|
|
|
#6 |
|
Bronze Member
![]() Join Date: Oct 2009
Posts: 11 PC Experience: Very Experienced
|
heres the malwarebytes log:
Malwarebytes' Anti-Malware 1.41 Database version: 3033 Windows 5.1.2600 Service Pack 3 10/28/2009 6:43:29 PM mbam-log-2009-10-28 (18-43-29).txt Scan type: Quick Scan Objects scanned: 117227 Time elapsed: 9 minute(s), 24 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
|
|
#7 |
|
Bronze Member
![]() Join Date: Oct 2009
Posts: 11 PC Experience: Very Experienced
|
heres the fresh hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:48:43 PM, on 10/28/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16915) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe C:\WINDOWS\system32\lxczcoms.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe C:\Program Files\Lexmark 1200 Series\lxczbmon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\stsystra.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\dlcccoms.exe C:\WINDOWS\System32\alg.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\WINDOWS\explorer.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\internet explorer\iexplore.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = AT&T - Home Page R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\s wg.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtim e.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1 O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" O4 - HKCU\..\Run: [DellSupport-] "C:\Program Files\DellSupport\DSAgnt.exe" /startup O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user') O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.7.109.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase8942.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1186022855750 O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {EA7F451B-94DD-4009-A8BF-8F977B0B2696} - http://pbells.broadjump.com/wizlet/S...ller_4-2-0.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe -- End of file - 12826 bytes |
|
|
|
![]() |
| Bookmarks |
| Tags |
| google, google redirect virus, redirect, virus |
Similar discussions...
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Pending: Google Redirect | vegaman | Spyware / AdWare | 1 | 09-17-2009 04:23 PM |
| Pending: Google Redirect Virus | WJennings | [Pending] HJT Logs | 5 | 09-09-2009 05:49 AM |
| Fixed: The Google Redirect Virus | korsondo | [Fixed] Hijackthis! Logs | 31 | 09-04-2009 12:13 AM |
| Fixed: Google redirect | tenlarn | [Fixed] Hijackthis! Logs | 10 | 10-10-2008 10:38 PM |
| Google Redirect??????????? | sbuxman | Windows XP/2000 | 2 | 02-11-2008 12:36 PM |
| Thread Tools | |
| Display Modes | |
|
|






























Linear Mode

