Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 24

Thread: IE and Firefox search results hijacked - redirects to adware/alternate search sites

  1. #11
    Junior Member
    Join Date
    Jun 2009
    Posts
    12

    Default

    I think Combofix has frozen the computer. It finished up to Stage 50, found the SKYNET malware, then went to restart the machine. The screen has been holding at the "Windows is shutting down..." XP shutdown screen for about 30 mins.

    How do I proceed? Manual shutdown and re-run combofix or just post HijackThis log?

  2. #12
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Yes please do manual shutdown and rerun combofix
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #13
    Junior Member
    Join Date
    Jun 2009
    Posts
    12

    Default

    ComboFix 09-06-26.02 - Kris 06/28/2009 14:53.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3294.2877 [GMT -4:00]
    Running from: c:\documents and settings\Kris\Desktop\ComboFix.exe

    AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
    FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    c:\documents and settings\Kris\autorun.inf
    c:\documents and settings\Kris\Kris.exe
    c:\windows\system32\drivers\SKYNETbqodotnb.sys
    c:\windows\system32\SKYNETebiqtgow.dll
    c:\windows\system32\SKYNETgoxujcvn.dll
    c:\windows\system32\SKYNETkmttjxdq.dat
    c:\windows\system32\SKYNETvymxuevr.dat

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_SKYNETuyrulvbo


    ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 )))))))))))))))))))))))))))))))
    .

    2009-06-28 18:52 . 2009-06-28 18:52 -------- dc----w- c:\windows\system32\dllcache\cache
    2009-06-27 17:18 . 2009-06-27 17:18 -------- d-----w- C:\rsit
    2009-06-25 16:04 . 2009-06-25 16:05 -------- d-----w- c:\program files\ERUNT
    2009-06-25 02:54 . 2009-06-25 02:54 -------- d-----w- c:\documents and settings\Kris\Application Data\Windows Search
    2009-06-24 23:48 . 2009-06-25 16:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-24 23:48 . 2009-06-25 02:45 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-06-24 23:33 . 2009-06-24 23:33 -------- d-----w- c:\program files\Trend Micro
    2009-06-24 21:08 . 2009-06-24 21:08 -------- d-----w- c:\documents and settings\Kris\Application Data\Malwarebytes
    2009-06-24 21:08 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-06-24 21:08 . 2009-06-24 21:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-06-24 21:08 . 2009-06-24 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-06-24 21:08 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-06-24 11:32 . 2009-06-24 11:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
    2009-06-23 05:55 . 2009-06-23 05:55 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
    2009-06-22 14:26 . 2009-06-22 14:26 -------- d-----w- c:\program files\Pidgin
    2009-06-19 21:34 . 2009-06-19 21:34 -------- d-----w- c:\program files\Common Files\SourceTec
    2009-06-19 21:34 . 2009-06-19 21:34 -------- d-----w- c:\program files\SourceTec
    2009-06-19 21:21 . 2005-07-25 15:59 28672 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}\components\mintray-9178506d-2005072516-trunk.dll
    2009-06-19 20:37 . 2009-06-16 07:07 892928 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\ipod@songbirdnest.com\libraries\iconv.dll
    2009-06-19 20:37 . 2009-06-16 07:07 45056 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\ipod@songbirdnest.com\libraries\intl.dll
    2009-06-19 20:37 . 2009-06-16 07:07 417792 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\ipod@songbirdnest.com\libraries\libgpod.dll
    2009-06-19 20:37 . 2009-06-16 07:07 344064 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\ipod@songbirdnest.com\libraries\sbIPDDevice.dll
    2009-06-19 20:37 . 2009-06-16 07:07 1004081 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\ipod@songbirdnest.com\libraries\libglib-2.0-0.dll
    2009-06-19 20:37 . 2009-06-16 07:07 8192 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\ipod@songbirdnest.com\components\ComponentLoader.dll
    2009-06-19 20:37 . 2009-06-16 07:07 292108 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\ipod@songbirdnest.com\libraries\libgobject-2.0-0.dll
    2009-06-19 20:00 . 2009-06-16 07:08 569344 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\mtp@songbirdnest.com\components\sbMTPWin32.dll
    2009-06-19 20:00 . 2009-06-16 07:08 270336 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\windowsmedia@songbirdnest.com\platform\WINNT_x86-msvc\components\sbWindowsMediacore.dll
    2009-06-19 20:00 . 2009-06-16 07:08 106496 ----a-w- c:\documents and settings\Kris\Application Data\Songbird2\Profiles\vrzwksck.default\extensions\quicktime@songbirdnest.com\platform\WINNT_x86-msvc\components\sbQuickTimeMediacore.dll
    2009-06-19 19:57 . 2009-06-27 18:04 -------- d-----w- c:\documents and settings\Kris\Application Data\Songbird2
    2009-06-19 19:57 . 2009-06-19 19:58 -------- d-----w- c:\documents and settings\Kris\Local Settings\Application Data\Songbird2
    2009-06-19 19:56 . 2009-06-27 20:57 -------- d-----w- c:\program files\Songbird
    2009-06-19 17:21 . 2009-06-23 01:56 -------- d-----w- c:\documents and settings\Kris\Application Data\AccurateRip
    2009-06-19 15:37 . 2009-06-19 15:37 -------- d-----w- c:\program files\TweetDeck
    2009-06-19 04:52 . 2009-06-19 04:52 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
    2009-06-19 04:52 . 2009-06-21 09:31 -------- d-----w- c:\program files\World of Warcraft Trial
    2009-06-18 17:23 . 2009-06-19 17:21 -------- d-----w- c:\program files\Exact Audio Copy
    2009-06-18 16:49 . 2009-06-18 16:49 -------- d-----w- c:\program files\IrfanView
    2009-06-18 13:57 . 2009-06-18 13:57 -------- d-----w- c:\program files\MSECache
    2009-06-10 13:53 . 2009-06-10 13:53 -------- d-----w- c:\documents and settings\Kris\Application Data\JGsoft
    2009-06-10 13:51 . 2009-06-10 13:51 -------- d-----w- c:\program files\JGsoft
    2009-06-10 13:51 . 2008-08-05 07:01 67208 ----a-w- c:\windows\UnDeploy.exe
    2009-06-10 13:23 . 2009-06-10 13:23 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
    2009-06-10 05:23 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
    2009-06-10 05:23 . 2009-04-30 21:22 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
    2009-06-10 05:23 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
    2009-06-10 05:23 . 2009-04-30 21:22 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
    2009-06-09 10:00 . 2009-06-09 10:00 -------- d-----w- c:\program files\SonicWallES
    2009-06-08 21:59 . 2009-06-09 10:00 -------- d-----w- c:\documents and settings\Kris\Application Data\MailFrontier
    2009-06-08 21:54 . 2009-06-22 16:19 41470496 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2009-06-08 21:51 . 2009-06-25 14:58 4212 ---ha-w- c:\windows\system32\zllictbl.dat
    2009-06-08 21:51 . 2009-05-29 00:25 72584 ----a-w- c:\windows\zllsputility.exe
    2009-06-08 21:51 . 2009-05-29 00:25 69000 ----a-w- c:\windows\system32\zlcomm.dll
    2009-06-08 21:51 . 2009-05-29 00:25 103816 ----a-w- c:\windows\system32\zlcommdb.dll
    2009-06-08 21:50 . 2009-05-29 00:25 1221512 ----a-w- c:\windows\system32\zpeng25.dll
    2009-06-08 21:50 . 2009-06-25 22:36 -------- d-----w- c:\windows\system32\ZoneLabs
    2009-06-08 21:50 . 2009-06-08 21:50 -------- d-----w- c:\program files\Zone Labs
    2009-06-08 21:10 . 2009-06-28 17:08 -------- d-----w- c:\windows\Internet Logs
    2009-06-08 17:50 . 2009-04-14 02:10 264704 ------w- c:\documents and settings\Kris\Application Data\OfficeUpdate12\oudetect.dll
    2009-06-08 17:50 . 2009-06-10 03:49 -------- d-----w- c:\documents and settings\Kris\Application Data\OfficeUpdate12
    2009-06-08 00:18 . 2009-06-08 00:18 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2009-06-06 05:07 . 2009-06-06 05:07 -------- d-----w- c:\program files\Common Files\AnswerWorks 5.0
    2009-06-06 05:07 . 2008-08-19 13:46 1848608 ----a-w- c:\windows\system32\acXMLParser.dll
    2009-06-06 05:07 . 2008-08-19 13:46 3523872 ----a-w- c:\windows\system32\cdintf300.dll
    2009-06-06 05:07 . 2008-08-19 13:44 25888 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\HaB\Custom\billmind.exe
    2009-06-06 05:07 . 2008-08-19 13:44 25888 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Deluxe\Custom\billmind.exe
    2009-06-06 05:07 . 2008-08-19 13:44 25888 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\RPM\Custom\billmind.exe
    2009-06-06 05:07 . 2008-08-19 13:44 25888 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Premier\Custom\billmind.exe
    2009-06-06 05:07 . 2009-06-06 05:07 -------- d-----w- c:\documents and settings\Kris\Application Data\Intuit
    2009-06-06 05:07 . 2009-06-06 05:07 -------- d-----w- c:\program files\Common Files\Intuit
    2009-06-06 05:07 . 2009-06-06 05:07 -------- d-----w- c:\program files\Quicken
    2009-06-06 05:06 . 2009-06-06 05:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
    2009-06-04 04:14 . 2009-06-04 04:14 -------- d-----w- c:\program files\iPod
    2009-06-04 04:12 . 2009-06-04 04:13 -------- d-----w- c:\program files\QuickTime
    2009-06-04 04:05 . 2009-06-04 04:05 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-27 17:35 . 2009-05-21 20:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-06-26 23:46 . 2009-05-26 03:48 -------- d-----w- c:\documents and settings\Kris\Application Data\.purple
    2009-06-21 16:38 . 2009-06-22 19:54 8704 ----a-w- c:\windows\Internet Logs\xDB2.tmp
    2009-06-21 10:15 . 2009-06-08 21:54 522896 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2009-06-21 10:14 . 2009-06-21 16:38 553984 ----a-w- c:\windows\Internet Logs\xDB1.tmp
    2009-06-19 04:43 . 2009-05-21 23:45 -------- d-----w- c:\program files\Steam
    2009-06-18 15:09 . 2009-05-22 04:36 23376 ----a-w- c:\documents and settings\Kris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-06-10 13:22 . 2009-05-17 19:18 -------- d-----w- c:\program files\Windows Desktop Search
    2009-06-08 18:04 . 2009-05-25 17:30 -------- d-----w- c:\program files\Microsoft Works
    2009-06-08 02:14 . 2009-05-17 18:57 -------- d-----w- c:\program files\Google
    2009-06-08 01:44 . 2009-05-21 20:58 -------- d-----w- c:\documents and settings\Kris\Application Data\Apple Computer
    2009-06-06 05:07 . 2009-05-17 17:22 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-06-04 04:14 . 2009-05-21 20:57 -------- d-----w- c:\program files\iTunes
    2009-06-04 04:14 . 2009-05-21 20:56 -------- d-----w- c:\program files\Common Files\Apple
    2009-05-27 00:57 . 2009-05-27 00:57 184 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\uninst2.bat
    2009-05-27 00:57 . 2009-05-27 00:57 683801 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\UninstWMP\unins000.exe
    2009-05-27 00:57 . 2009-05-27 00:57 683801 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\UninstITW\unins000.exe
    2009-05-27 00:57 . 2009-05-27 00:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Last.fm
    2009-05-27 00:51 . 2009-05-27 00:51 -------- d-----w- c:\program files\Last.fm
    2009-05-26 04:40 . 2009-05-26 04:40 -------- d-----w- c:\documents and settings\Kris\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
    2009-05-26 04:40 . 2009-05-17 18:55 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2009-05-26 04:28 . 2009-05-26 04:40 38208 ----a-w- c:\documents and settings\Kris\Application Data\Macromedia\Flash Player\http://www.macromedia.com\bin\airapp...pinstaller.exe
    2009-05-26 03:46 . 2009-05-26 03:46 -------- d-----w- c:\program files\Common Files\GTK
    2009-05-25 17:30 . 2009-05-25 17:30 -------- d-----w- c:\program files\Common Files\L&H
    2009-05-25 17:30 . 2009-05-25 17:30 -------- d-----w- c:\program files\Microsoft ActiveSync
    2009-05-25 17:29 . 2009-05-25 17:29 -------- d-----w- c:\program files\Microsoft.NET
    2009-05-25 04:24 . 2008-05-27 02:18 350208 ----a-w- c:\windows\system32\mssph.dll
    2009-05-25 01:25 . 2009-05-25 01:25 -------- d-----w- c:\program files\CPUID
    2009-05-22 00:16 . 2009-05-22 00:16 -------- d-----w- c:\program files\Infogrames Interactive
    2009-05-22 00:15 . 2009-05-22 00:15 -------- d-----w- c:\program files\Elaborate Bytes
    2009-05-21 20:57 . 2009-05-21 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    2009-05-21 20:57 . 2009-05-21 20:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2009-05-21 20:57 . 2009-05-21 20:57 -------- d-----w- c:\program files\Bonjour
    2009-05-21 20:56 . 2009-05-21 20:56 -------- d-----w- c:\program files\Apple Software Update
    2009-05-21 20:56 . 2009-05-21 20:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
    2009-05-21 20:44 . 2009-05-21 20:44 -------- d-----w- c:\program files\HttpWatch
    2009-05-21 20:31 . 2009-05-21 20:31 0 ----a-w- c:\windows\nsreg.dat
    2009-05-17 19:21 . 2009-05-17 19:21 -------- d-----w- c:\program files\MSBuild
    2009-05-17 19:21 . 2009-05-17 19:21 -------- d-----w- c:\program files\Reference Assemblies
    2009-05-17 19:19 . 2009-05-17 19:19 -------- d-----w- c:\documents and settings\Kris\Application Data\Windows Desktop Search
    2009-05-17 19:17 . 2009-05-17 19:17 -------- d-----w- c:\program files\Windows Media Connect 2
    2009-05-17 18:57 . 2009-05-17 18:57 1915520 ----a-w- c:\documents and settings\Kris\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
    2009-05-17 18:54 . 2009-05-17 18:54 -------- d-----w- c:\program files\Common Files\Adobe
    2009-05-17 18:32 . 2009-05-17 18:32 -------- d-----w- c:\program files\Analog Devices
    2009-05-17 18:00 . 2009-05-17 16:07 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-05-17 17:25 . 2009-05-17 17:22 -------- d-----w- c:\program files\Common Files\InstallShield
    2009-05-17 17:22 . 2009-05-17 17:22 -------- d-----w- c:\program files\ATI Technologies
    2009-05-17 17:11 . 2009-05-17 17:11 -------- d-----w- c:\program files\Broadcom
    2009-05-17 16:09 . 2009-05-17 16:09 -------- d-----w- c:\program files\microsoft frontpage
    2009-05-17 16:04 . 2009-05-17 16:04 21640 ----a-w- c:\windows\system32\emptyregdb.dat
    2009-05-13 05:15 . 2006-03-04 03:33 915456 ----a-w- c:\windows\system32\wininet.dll
    2009-05-12 19:12 . 2009-05-17 17:26 26144 ----a-w- c:\windows\system32\spupdsvc.exe
    2009-05-07 15:32 . 2004-08-04 10:00 345600 ----a-w- c:\windows\system32\localspl.dll
    2009-04-17 12:26 . 2004-08-04 10:00 1847168 ----a-w- c:\windows\system32\win32k.sys
    2009-04-15 14:51 . 2004-08-04 10:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
    2009-04-14 02:10 . 2009-04-14 02:10 524288 ----a-w- c:\windows\opuc.dll
    2009-06-08 02:14 . 2009-06-08 02:14 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-06-28_18.51.09 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-06-28 18:52 . 2008-10-16 18:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
    + 2009-06-28 18:52 . 2008-04-14 00:12 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
    + 2009-06-28 18:52 . 2008-04-14 00:12 26112 c:\windows\system32\dllcache\cache\userinit.exe
    + 2009-06-28 18:52 . 2008-04-14 00:12 14336 c:\windows\system32\dllcache\cache\svchost.exe
    + 2009-06-28 18:52 . 2008-04-14 00:12 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
    + 2009-06-28 18:52 . 2008-04-14 00:12 17408 c:\windows\system32\dllcache\cache\powrprof.dll
    + 2009-06-28 18:52 . 2008-04-14 00:12 13312 c:\windows\system32\dllcache\cache\lsass.exe
    + 2009-06-28 18:52 . 2008-04-13 18:39 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
    + 2009-06-28 18:52 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
    + 2009-06-28 18:52 . 2008-04-14 00:12 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
    + 2009-06-08 21:55 . 2009-06-28 18:52 381288 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
    + 2009-06-28 18:52 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\cache\winlogon.exe
    + 2009-06-28 18:52 . 2009-05-13 05:15 915456 c:\windows\system32\dllcache\cache\wininet.dll
    + 2009-06-28 18:52 . 2008-04-14 00:12 578560 c:\windows\system32\dllcache\cache\user32.dll
    + 2009-06-28 18:52 . 2008-04-14 00:12 295424 c:\windows\system32\dllcache\cache\termsrv.dll
    + 2009-06-28 18:52 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\cache\tcpip.sys
    + 2009-06-28 18:52 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\cache\services.exe
    + 2009-06-28 18:52 . 2008-04-13 19:20 182656 c:\windows\system32\dllcache\cache\ndis.sys
    + 2009-06-28 18:52 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\cache\kernel32.dll
    + 2009-06-28 18:52 . 2008-04-14 00:11 110080 c:\windows\system32\dllcache\cache\imm32.dll
    + 2009-06-28 18:52 . 2008-04-14 00:11 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
    + 2009-06-28 18:52 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\cache\sfcfiles.dll
    + 2009-06-28 18:52 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\cache\ntoskrnl.exe
    + 2009-06-28 18:52 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
    + 2009-06-28 18:52 . 2008-04-14 00:12 1033728 c:\windows\system32\dllcache\cache\explorer.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "sbitunesagent"="c:\program files\Songbird\songbirditunesagent.exe" [2009-06-16 229376]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-06-08 30192]
    "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-05-29 1005960]

    c:\documents and settings\Kris\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Steam\\steamapps\\kizzer505\\counter-strike\\hl.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

    R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [5/17/2009 1:25 PM 3456]
    R3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\system32\drivers\RTL8187B.sys [5/21/2009 4:02 PM 264576]
    S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [5/24/2009 9:25 PM 12672]
    S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/7/2009 10:14 PM 30192]

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://webmail.mwcorporate.com/
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    FF - ProfilePath - c:\documents and settings\Kris\Application Data\Mozilla\Firefox\Profiles\9l4w8bel.default\
    FF - component: c:\program files\HttpWatch\Firefox\components\httpwatchproff.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-28 14:56
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(832)
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(740)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2009-06-28 14:57
    ComboFix-quarantined-files.txt 2009-06-28 18:57

    Pre-Run: 56,062,742,528 bytes free
    Post-Run: 56,052,887,552 bytes free

    271 --- E O F --- 2009-06-24 06:56

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:58:49 PM, on 6/28/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal


    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Songbird\songbirditunesagent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.mwcorporate.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: HttpWatch Professional - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchscpro.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [sbitunesagent] C:\Program Files\Songbird\songbirditunesagent.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: HttpWatch Professional - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatchpro.dll
    O9 - Extra 'Tools' menuitem: HttpWatch Professional - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatchpro.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 6785 bytes

  4. #14
    Junior Member
    Join Date
    Jun 2009
    Posts
    12

    Default

    Does it look like ComboFix cleaned out the malware?

    Let me know if this issue is fixed. I tested out the browser and have not experienced a redirect of any sort which is good. I'd just like to be sure that all known traces of the malware have been removed.

  5. #15
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Before judging that, let's run one scan:

    Please go to Kaspersky website and perform an online antivirus scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #16
    Junior Member
    Join Date
    Jun 2009
    Posts
    12

    Default

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0 REPORT
    Monday, June 29, 2009
    Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Program database last update: Monday, June 29, 2009 06:36:52
    Records in database: 2400340
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: no

    Scan area - My Computer:
    C:\
    D:\
    E:\

    Scan statistics:
    Files scanned: 49256
    Threat name: 1
    Infected objects: 1
    Suspicious objects: 0
    Duration of the scan: 00:58:32


    File name / Threat name / Threats count
    C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETgoxujcvn.dll.vir Infected: Trojan.Win32.Small.bzc 1

    The selected area was scanned.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:57:49 AM, on 6/29/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal


    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Songbird\songbirditunesagent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Java\jre6\bin\java.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.mwcorporate.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HttpWatch Professional - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchscpro.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [sbitunesagent] C:\Program Files\Songbird\songbirditunesagent.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: HttpWatch Professional - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatchpro.dll
    O9 - Extra 'Tools' menuitem: HttpWatch Professional - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatchpro.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 7354 bytes

  7. #17
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Empty this folder:

    C:\Qoobox\Quarantine

    Empty Recycle Bin.

    Still problems?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #18
    Junior Member
    Join Date
    Jun 2009
    Posts
    12

    Default

    Looks like I own my search results again.

    Thanks a lot for your help. I really appreciate it. Should we close this thread and delete my information from it?

  9. #19
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Do you mean your windows username by information?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  10. #20
    Junior Member
    Join Date
    Jun 2009
    Posts
    12

    Default

    Yes. Also these hijackthis reports detail the structure of my system. Could that be a security breach if left online?

    I'm not an expert on what can or can't be used, just trying to be cautious.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •