I know there is something wrong but it's beyond my knowledge to resolve. So I come to the best.
When you open Chrome or Firefox they crash, IE is fine. It won't let windows update and hijacks the website when you try to go to it. I've run Spybot and Malware Bytes, and the problems persist.
Thanks in advance.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by Carolynrsl at 0:30:16 on 2014-01-31
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.562 [GMT -6:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxcfcoms.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uProxyOverride = <local>
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} -
BHO: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} -
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: <No Name>: - LocalServer32 - <no file>
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} -
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Search - http://tbedits.totalrecipesearch.com/one-toolbaredits/menusearch.jhtml?s=100000459&p2=^YK^xdm003^S01928^us&si=CNPIzNHP1rACFSWFQAod_SUl1w&a=AA671E39-85F4-4F91-910B-20756E3DA426&n=2012072914&cv=1
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} -
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{6734B78D-2D91-44C2-BCF6-A3BA4F73FD04} : DHCPNameServer = 192.168.2.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\32.0.1700.76\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\carolynrsl\application data\mozilla\firefox\profiles\y0ciztnn.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=AA671E39-85F4-4F91-910B-20756E3DA426&n=77eda07a&ind=2012061818&p2=^YK^xdm003^S01928^us&si=CNPIzNHP1rACFSWFQAod_SUl1w&searchfor=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_170.dll
FF - ExtSQL: !HIDDEN! 2009-12-28 19:29; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2012-06-17 20:22; 14ffxtbr@TotalRecipeSearch_14.com; c:\program files\totalrecipesearch_14\bar\1.bin
.
============= SERVICES / DRIVERS ===============
.
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-11 55152]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2009-4-27 38912]
R3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [2009-4-27 39040]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-8-11 1684736]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\amustor.sys --> c:\windows\system32\drivers\AmUStor.SYS [?]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2009-8-20 1015424]
.
=============== Created Last 30 ================
.
2014-01-27 08:40:54 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\Google
2014-01-27 08:02:08 -------- d-----w- c:\windows\SxsCaPendDel
2014-01-12 20:31:09 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\genienext
2014-01-06 22:51:07 75376 ----a-w- c:\program files\mozilla firefox\breakpadinjector.dll
2014-01-06 22:51:07 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2014-01-06 22:51:01 3449456 ----a-w- c:\program files\mozilla firefox\gkmedias.dll
2014-01-06 22:51:01 194552 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2014-01-06 22:51:01 130672 ----a-w- c:\program files\mozilla firefox\mozglue.dll
2014-01-06 22:51:01 119408 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2014-01-06 22:50:59 770384 ----a-w- c:\program files\mozilla firefox\msvcr100.dll
2014-01-06 22:50:59 421200 ----a-w- c:\program files\mozilla firefox\msvcp100.dll
2014-01-06 22:50:59 3559024 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2014-01-06 22:50:53 28272 ----a-w- c:\program files\mozilla firefox\plugin-hang-ui.exe
2014-01-06 22:50:52 170960 ----a-w- c:\program files\mozilla firefox\webapp-uninstaller.exe
2014-01-06 22:50:52 108144 ----a-w- c:\program files\mozilla firefox\webapprt-stub.exe
2014-01-06 22:39:55 -------- d-----w- c:\documents and settings\carolynrsl\application data\WeatherBug
2014-01-06 22:39:50 -------- d-----w- c:\program files\AWS
2014-01-06 22:39:02 -------- d-----w- c:\documents and settings\carolynrsl\.android
2014-01-06 22:38:58 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\cache
2014-01-06 22:38:48 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\Mobogenie
.
==================== Find3M ====================
.
2013-12-12 22:36:02 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-12 22:36:02 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Hitachi_ rev.FB2O -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x864CCEC5]<<
_asm { PUSH EBP; MOV EBP, ESP; SUB ESP, 0x1c; PUSH EBX; PUSH ESI; MOV DWORD [EBP-0x4], 0x84aeb872; SUB DWORD [EBP-0x4], 0x84aeb12e; PUSH EDI; CALL 0xffffffffffffdf33; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8657B030]
3 CLASSPNP[0xF75C8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\0000005f[0x8653A8D8]
5 ACPI[0xF745F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x8657C028]
[0x8657AA38] -> IRP_MJ_CREATE -> 0x864CCEC5
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskHitachi_HTS543216L9SA00_________________FB2OC40C#4&44f0d94&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\iaStor DriverStartIo -> 0x864CCAEA
user & kernel MBR OK
sectors 312581806 (+255): user != kernel
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 0:31:37.14 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-31 00:33:09
-----------------------------
00:33:09.015 OS Version: Windows 5.1.2600 Service Pack 3
00:33:09.015 Number of processors: 2 586 0x1C02
00:33:09.015 ComputerName: ROSIELAPPY UserName: Carolynrsl
00:33:09.984 Initialize success
00:55:33.203 AVAST engine defs: 14013001
01:06:11.312 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\iaStor0
01:06:11.328 Disk 0 Vendor: Hitachi_ FB2O Size: 152627MB BusType: 3
01:06:11.328 Device \Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskHitachi_HTS543216L9SA00_________________FB2OC40C#4&44f0d94&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
01:06:11.343 Device \Driver\iaStor -> DriverStartIo 864ccaea
01:06:11.515 Disk 0 MBR read successfully
01:06:11.531 Disk 0 MBR scan
01:06:11.609 Disk 0 Windows XP default MBR code
01:06:11.625 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 147581 MB offset 63
01:06:11.671 Disk 0 Partition 2 00 1C Hidd FAT32 LBA MSDOS5.0 5004 MB offset 302246910
01:06:11.703 Disk 0 Partition 3 00 EF EFI FAT A1311 39 MB offset 312496380
01:06:11.734 Disk 0 scanning sectors +312576705
01:06:11.921 Disk 0 scanning C:\WINDOWS\system32\drivers
01:06:16.203 File: C:\WINDOWS\system32\drivers\atapi.sys **INFECTED** Win32:Alureon-FZ
01:06:29.468 Scan finished successfully
01:07:12.843 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Carolynrsl\Desktop\spybotstools\MBR.dat"
01:07:12.875 The log file has been saved successfully to "C:\Documents and Settings\Carolynrsl\Desktop\spybotstools\aswMBR.txt"
View attachment attach.zip
When you open Chrome or Firefox they crash, IE is fine. It won't let windows update and hijacks the website when you try to go to it. I've run Spybot and Malware Bytes, and the problems persist.
Thanks in advance.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by Carolynrsl at 0:30:16 on 2014-01-31
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.562 [GMT -6:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxcfcoms.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uProxyOverride = <local>
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} -
BHO: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} -
TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: <No Name>: - LocalServer32 - <no file>
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} -
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Search - http://tbedits.totalrecipesearch.com/one-toolbaredits/menusearch.jhtml?s=100000459&p2=^YK^xdm003^S01928^us&si=CNPIzNHP1rACFSWFQAod_SUl1w&a=AA671E39-85F4-4F91-910B-20756E3DA426&n=2012072914&cv=1
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} -
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{6734B78D-2D91-44C2-BCF6-A3BA4F73FD04} : DHCPNameServer = 192.168.2.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\32.0.1700.76\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\carolynrsl\application data\mozilla\firefox\profiles\y0ciztnn.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=AA671E39-85F4-4F91-910B-20756E3DA426&n=77eda07a&ind=2012061818&p2=^YK^xdm003^S01928^us&si=CNPIzNHP1rACFSWFQAod_SUl1w&searchfor=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_170.dll
FF - ExtSQL: !HIDDEN! 2009-12-28 19:29; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2012-06-17 20:22; 14ffxtbr@TotalRecipeSearch_14.com; c:\program files\totalrecipesearch_14\bar\1.bin
.
============= SERVICES / DRIVERS ===============
.
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-11 55152]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2009-4-27 38912]
R3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [2009-4-27 39040]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-8-11 1684736]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\amustor.sys --> c:\windows\system32\drivers\AmUStor.SYS [?]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2009-8-20 1015424]
.
=============== Created Last 30 ================
.
2014-01-27 08:40:54 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\Google
2014-01-27 08:02:08 -------- d-----w- c:\windows\SxsCaPendDel
2014-01-12 20:31:09 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\genienext
2014-01-06 22:51:07 75376 ----a-w- c:\program files\mozilla firefox\breakpadinjector.dll
2014-01-06 22:51:07 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2014-01-06 22:51:01 3449456 ----a-w- c:\program files\mozilla firefox\gkmedias.dll
2014-01-06 22:51:01 194552 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2014-01-06 22:51:01 130672 ----a-w- c:\program files\mozilla firefox\mozglue.dll
2014-01-06 22:51:01 119408 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2014-01-06 22:50:59 770384 ----a-w- c:\program files\mozilla firefox\msvcr100.dll
2014-01-06 22:50:59 421200 ----a-w- c:\program files\mozilla firefox\msvcp100.dll
2014-01-06 22:50:59 3559024 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2014-01-06 22:50:53 28272 ----a-w- c:\program files\mozilla firefox\plugin-hang-ui.exe
2014-01-06 22:50:52 170960 ----a-w- c:\program files\mozilla firefox\webapp-uninstaller.exe
2014-01-06 22:50:52 108144 ----a-w- c:\program files\mozilla firefox\webapprt-stub.exe
2014-01-06 22:39:55 -------- d-----w- c:\documents and settings\carolynrsl\application data\WeatherBug
2014-01-06 22:39:50 -------- d-----w- c:\program files\AWS
2014-01-06 22:39:02 -------- d-----w- c:\documents and settings\carolynrsl\.android
2014-01-06 22:38:58 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\cache
2014-01-06 22:38:48 -------- d-----w- c:\documents and settings\carolynrsl\local settings\application data\Mobogenie
.
==================== Find3M ====================
.
2013-12-12 22:36:02 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-12 22:36:02 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Hitachi_ rev.FB2O -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x864CCEC5]<<
_asm { PUSH EBP; MOV EBP, ESP; SUB ESP, 0x1c; PUSH EBX; PUSH ESI; MOV DWORD [EBP-0x4], 0x84aeb872; SUB DWORD [EBP-0x4], 0x84aeb12e; PUSH EDI; CALL 0xffffffffffffdf33; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8657B030]
3 CLASSPNP[0xF75C8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\0000005f[0x8653A8D8]
5 ACPI[0xF745F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x8657C028]
[0x8657AA38] -> IRP_MJ_CREATE -> 0x864CCEC5
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskHitachi_HTS543216L9SA00_________________FB2OC40C#4&44f0d94&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\iaStor DriverStartIo -> 0x864CCAEA
user & kernel MBR OK
sectors 312581806 (+255): user != kernel
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 0:31:37.14 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-31 00:33:09
-----------------------------
00:33:09.015 OS Version: Windows 5.1.2600 Service Pack 3
00:33:09.015 Number of processors: 2 586 0x1C02
00:33:09.015 ComputerName: ROSIELAPPY UserName: Carolynrsl
00:33:09.984 Initialize success
00:55:33.203 AVAST engine defs: 14013001
01:06:11.312 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\iaStor0
01:06:11.328 Disk 0 Vendor: Hitachi_ FB2O Size: 152627MB BusType: 3
01:06:11.328 Device \Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskHitachi_HTS543216L9SA00_________________FB2OC40C#4&44f0d94&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
01:06:11.343 Device \Driver\iaStor -> DriverStartIo 864ccaea
01:06:11.515 Disk 0 MBR read successfully
01:06:11.531 Disk 0 MBR scan
01:06:11.609 Disk 0 Windows XP default MBR code
01:06:11.625 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 147581 MB offset 63
01:06:11.671 Disk 0 Partition 2 00 1C Hidd FAT32 LBA MSDOS5.0 5004 MB offset 302246910
01:06:11.703 Disk 0 Partition 3 00 EF EFI FAT A1311 39 MB offset 312496380
01:06:11.734 Disk 0 scanning sectors +312576705
01:06:11.921 Disk 0 scanning C:\WINDOWS\system32\drivers
01:06:16.203 File: C:\WINDOWS\system32\drivers\atapi.sys **INFECTED** Win32:Alureon-FZ
01:06:29.468 Scan finished successfully
01:07:12.843 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Carolynrsl\Desktop\spybotstools\MBR.dat"
01:07:12.875 The log file has been saved successfully to "C:\Documents and Settings\Carolynrsl\Desktop\spybotstools\aswMBR.txt"
View attachment attach.zip