reznik1012
New member
Hello, I've tried to help a friend with a malware issue. Pop-ups called disk repair, slow computer, and google redirect are some of the symptoms. the disk repair stuff is not showing up anymore but im still getting redirected in google searches, the computer is slow, and when i go to update windows it says the page cannot be displayed. Also I've tried posting this from the computer that was infected and it also said that the page could not be displayed. I'm posting from another computer.
Here's a list of everything I've run so far:
-Ran ATF File cleaner
-Ran RKill.exe
-installed external wifi adapter (for compatibility with my network)
-Updated and ran Spybot S&D
-Updated and ran Malwarebytes
-Updated and ran Symantec Corparate
-installed and updated superantispyware
(at this point the Disk repair pop-ups stopped)
-Attempted windows update (failed)
-manually updated to Windows XP sp3
-Updated Firefox
-Updated to IE8
-Updated to Java 6 update 23
-Updated Adobe flash player
-Uninstalled multiple toolbars and older versions of java
-edited start-up entries for faster startup
-attempted to use Secunia OSI (failed)
-Ran ERUNT
-ran DDS
still getting google redirect and cannot access windows updates, slow moving computer, getting "virtual memory low" warnings from running a single scan.
here is my DDS Log:
DDS (Ver_10-12-12.02) - NTFSx86
Run by admin at 2:30:02.23 on Wed 12/29/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.47 [GMT -5:00]
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Documents and Settings\admin.DELL260\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://m.www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\f6d4050\v2\Belkinwcui.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Open with WordPerfect - c:\program files\wordperfect office x3\programs\WPLauncher.hta
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
Trusted Zone: iu.edu
Trusted Zone: iupui.edu
Trusted Zone: ius.edu
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190985335421
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admin~1.del\applic~1\mozilla\firefox\profiles\i0iu2s3z.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-6-2 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-6-2 161392]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-6-23 124608]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-6-23 1715904]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20101227.002\naveng.sys [2010-12-28 86008]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20101227.002\navex15.sys [2010-12-28 1360760]
R3 rt2870;Belkin 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2008-10-29 644096]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-6-2 83568]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-21 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-21 8320]
=============== Created Last 30 ================
2010-12-28 09:19:58 81920 ------w- c:\windows\system32\ieencode.dll
2010-12-28 09:06:15 144384 ------w- c:\windows\system32\drivers\hdaudbus.sys
2010-12-28 09:06:13 10240 ------w- c:\windows\system32\drivers\sffp_mmc.sys
2010-12-28 09:02:14 19569 ----a-w- c:\windows\005921_.tmp
2010-12-28 06:59:42 -------- dc-h--w- c:\windows\ie8
2010-12-28 04:07:00 21361 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-12-28 04:04:56 -------- d-----w- c:\program files\Belkin
2010-12-27 20:55:53 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\SUPERAntiSpyware.com
2010-12-27 20:55:52 -------- d-----w- c:\docume~1\admin~1.del\applic~1\SUPERAntiSpyware.com
2010-12-27 20:55:33 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-12-27 17:55:12 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2010-12-27 17:55:11 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-27 17:43:50 -------- d-----w- c:\program files\SpywareBlaster
2010-12-27 08:04:03 553696 ----a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2010-12-27 08:03:56 25048 ----a-w- c:\program files\mozilla firefox\components\browserdirprovider.dll
2010-12-27 08:03:56 140248 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2010-12-27 08:03:51 89048 ----a-w- c:\program files\mozilla firefox\nssutil3.dll
2010-12-27 08:03:51 492504 ----a-w- c:\program files\mozilla firefox\sqlite3.dll
2010-12-27 08:03:51 16856 ----a-w- c:\program files\mozilla firefox\plugin-container.exe
2010-12-27 08:03:51 11775448 ----a-w- c:\program files\mozilla firefox\xul.dll
2010-12-27 08:03:50 98304 ----a-w- c:\program files\mozilla firefox\nssdbm3.dll
2010-12-27 08:03:50 719832 ----a-w- c:\program files\mozilla firefox\mozcrt19.dll
2010-12-27 08:03:50 719832 ----a-w- c:\program files\mozilla firefox\mozcpp19.dll
2010-12-27 08:03:49 107480 ----a-w- c:\program files\mozilla firefox\crashreporter.exe
2010-12-27 05:55:04 -------- d-----w- c:\program files\Defraggler
2010-12-27 05:15:31 -------- d-----w- c:\windows\pss
2010-12-27 02:04:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-26 19:27:27 -------- d-----w- c:\docume~1\admin~1.del\applic~1\GetRightToGo
2010-12-26 02:50:20 -------- d-----w- c:\docume~1\admin~1.del\applic~1\Malwarebytes
2010-12-26 02:50:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-26 02:50:06 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-26 02:50:06 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2010-12-26 02:50:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-26 02:39:35 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Spybot - Search & Destroy
2010-12-26 02:34:58 -------- d-----w- c:\windows\{0D59735E-1DA7-4E6D-B1CC-44A4F59FD0FD}
2010-12-21 06:54:08 6273872 ----a-w- c:\docume~1\alluse~1.win\applic~1\microsoft\windows defender\definition updates\{45700c28-b3d0-445f-b054-c70be0a9d5ba}\mpengine.dll
2010-12-17 20:03:39 -------- d-----w- c:\program files\iPod
2010-12-17 20:03:16 -------- d-----w- c:\program files\iTunes
2010-12-12 22:24:58 -------- d-sh--w- c:\documents and settings\admin.dell260\IECompatCache
2010-12-12 22:22:17 -------- d-sh--w- c:\documents and settings\admin.dell260\PrivacIE
2010-12-12 21:55:09 -------- d-sh--w- c:\documents and settings\admin.dell260\IETldCache
2010-12-12 06:00:50 -------- d-----w- c:\windows\ie8updates
2010-12-12 05:41:19 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-12 05:41:17 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-12 05:41:17 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-08 01:33:23 -------- d-----w- c:\program files\Windows Media Connect 2
2010-11-29 22:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 22:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-29 13:51:02 -------- d-----w- c:\windows\system32\LogFiles
==================== Find3M ====================
2010-12-27 17:54:03 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-19 15:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-08 22:31:11 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD200BB-00GFA0 rev.09.01B09 -> Harddisk1\DR1 -> \Device\Ide\IdePort0 P0T1L0-c
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82F53555]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x82f597b0]; MOV EAX, [0x82f5982c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37C5] -> \Device\Harddisk1\DR1[0x82F99AB8]
3 CLASSPNP[0xF8578FD7] -> nt!IofCallDriver[0x804E37C5] -> [0x82EE3B18]
\Driver\atapi[0x82FA7498] -> IRP_MJ_CREATE -> 0x82F53555
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP0T1L0-c -> \??\IDE#DiskWDC_WD200BB-00GFA0______________________09.01B09#4457572d414d414b323138333436_033_0_0_0_0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x82F5339B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
============= FINISH: 2:34:16.12 ===============
I'm sorry if I've caused any trouble by running these scans prior to coming here for advice. I was honestly hoping they would clear out most of it.
Thanks in advance.
Here's a list of everything I've run so far:
-Ran ATF File cleaner
-Ran RKill.exe
-installed external wifi adapter (for compatibility with my network)
-Updated and ran Spybot S&D
-Updated and ran Malwarebytes
-Updated and ran Symantec Corparate
-installed and updated superantispyware
(at this point the Disk repair pop-ups stopped)
-Attempted windows update (failed)
-manually updated to Windows XP sp3
-Updated Firefox
-Updated to IE8
-Updated to Java 6 update 23
-Updated Adobe flash player
-Uninstalled multiple toolbars and older versions of java
-edited start-up entries for faster startup
-attempted to use Secunia OSI (failed)
-Ran ERUNT
-ran DDS
still getting google redirect and cannot access windows updates, slow moving computer, getting "virtual memory low" warnings from running a single scan.
here is my DDS Log:
DDS (Ver_10-12-12.02) - NTFSx86
Run by admin at 2:30:02.23 on Wed 12/29/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.47 [GMT -5:00]
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Documents and Settings\admin.DELL260\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://m.www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\f6d4050\v2\Belkinwcui.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Open with WordPerfect - c:\program files\wordperfect office x3\programs\WPLauncher.hta
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
Trusted Zone: iu.edu
Trusted Zone: iupui.edu
Trusted Zone: ius.edu
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190985335421
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admin~1.del\applic~1\mozilla\firefox\profiles\i0iu2s3z.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-6-2 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-6-2 161392]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-6-23 124608]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-6-23 1715904]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20101227.002\naveng.sys [2010-12-28 86008]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20101227.002\navex15.sys [2010-12-28 1360760]
R3 rt2870;Belkin 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2008-10-29 644096]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-6-2 83568]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-21 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-21 8320]
=============== Created Last 30 ================
2010-12-28 09:19:58 81920 ------w- c:\windows\system32\ieencode.dll
2010-12-28 09:06:15 144384 ------w- c:\windows\system32\drivers\hdaudbus.sys
2010-12-28 09:06:13 10240 ------w- c:\windows\system32\drivers\sffp_mmc.sys
2010-12-28 09:02:14 19569 ----a-w- c:\windows\005921_.tmp
2010-12-28 06:59:42 -------- dc-h--w- c:\windows\ie8
2010-12-28 04:07:00 21361 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-12-28 04:04:56 -------- d-----w- c:\program files\Belkin
2010-12-27 20:55:53 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\SUPERAntiSpyware.com
2010-12-27 20:55:52 -------- d-----w- c:\docume~1\admin~1.del\applic~1\SUPERAntiSpyware.com
2010-12-27 20:55:33 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-12-27 17:55:12 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2010-12-27 17:55:11 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-27 17:43:50 -------- d-----w- c:\program files\SpywareBlaster
2010-12-27 08:04:03 553696 ----a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2010-12-27 08:03:56 25048 ----a-w- c:\program files\mozilla firefox\components\browserdirprovider.dll
2010-12-27 08:03:56 140248 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2010-12-27 08:03:51 89048 ----a-w- c:\program files\mozilla firefox\nssutil3.dll
2010-12-27 08:03:51 492504 ----a-w- c:\program files\mozilla firefox\sqlite3.dll
2010-12-27 08:03:51 16856 ----a-w- c:\program files\mozilla firefox\plugin-container.exe
2010-12-27 08:03:51 11775448 ----a-w- c:\program files\mozilla firefox\xul.dll
2010-12-27 08:03:50 98304 ----a-w- c:\program files\mozilla firefox\nssdbm3.dll
2010-12-27 08:03:50 719832 ----a-w- c:\program files\mozilla firefox\mozcrt19.dll
2010-12-27 08:03:50 719832 ----a-w- c:\program files\mozilla firefox\mozcpp19.dll
2010-12-27 08:03:49 107480 ----a-w- c:\program files\mozilla firefox\crashreporter.exe
2010-12-27 05:55:04 -------- d-----w- c:\program files\Defraggler
2010-12-27 05:15:31 -------- d-----w- c:\windows\pss
2010-12-27 02:04:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-26 19:27:27 -------- d-----w- c:\docume~1\admin~1.del\applic~1\GetRightToGo
2010-12-26 02:50:20 -------- d-----w- c:\docume~1\admin~1.del\applic~1\Malwarebytes
2010-12-26 02:50:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-26 02:50:06 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-26 02:50:06 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2010-12-26 02:50:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-26 02:39:35 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Spybot - Search & Destroy
2010-12-26 02:34:58 -------- d-----w- c:\windows\{0D59735E-1DA7-4E6D-B1CC-44A4F59FD0FD}
2010-12-21 06:54:08 6273872 ----a-w- c:\docume~1\alluse~1.win\applic~1\microsoft\windows defender\definition updates\{45700c28-b3d0-445f-b054-c70be0a9d5ba}\mpengine.dll
2010-12-17 20:03:39 -------- d-----w- c:\program files\iPod
2010-12-17 20:03:16 -------- d-----w- c:\program files\iTunes
2010-12-12 22:24:58 -------- d-sh--w- c:\documents and settings\admin.dell260\IECompatCache
2010-12-12 22:22:17 -------- d-sh--w- c:\documents and settings\admin.dell260\PrivacIE
2010-12-12 21:55:09 -------- d-sh--w- c:\documents and settings\admin.dell260\IETldCache
2010-12-12 06:00:50 -------- d-----w- c:\windows\ie8updates
2010-12-12 05:41:19 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-12 05:41:17 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-12 05:41:17 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-08 01:33:23 -------- d-----w- c:\program files\Windows Media Connect 2
2010-11-29 22:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 22:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-29 13:51:02 -------- d-----w- c:\windows\system32\LogFiles
==================== Find3M ====================
2010-12-27 17:54:03 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-19 15:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-08 22:31:11 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD200BB-00GFA0 rev.09.01B09 -> Harddisk1\DR1 -> \Device\Ide\IdePort0 P0T1L0-c
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82F53555]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x82f597b0]; MOV EAX, [0x82f5982c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37C5] -> \Device\Harddisk1\DR1[0x82F99AB8]
3 CLASSPNP[0xF8578FD7] -> nt!IofCallDriver[0x804E37C5] -> [0x82EE3B18]
\Driver\atapi[0x82FA7498] -> IRP_MJ_CREATE -> 0x82F53555
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP0T1L0-c -> \??\IDE#DiskWDC_WD200BB-00GFA0______________________09.01B09#4457572d414d414b323138333436_033_0_0_0_0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x82F5339B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
============= FINISH: 2:34:16.12 ===============
I'm sorry if I've caused any trouble by running these scans prior to coming here for advice. I was honestly hoping they would clear out most of it.
Thanks in advance.