Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Google Redirect Mayhem

  • 05-07-2011 6:35pm
    #1
    Registered Users, Registered Users 2 Posts: 172 ✭✭


    Dear Friends,

    I have been devastated by an accursed Google redirect virus when using Firefox. I have read the "I Think I Have A Virus" Instructions. The story is this, I use Avast and regularly scan with Malwarebytes. Neither picked up the problem even after it was well evident. The problem does go away when I disable javascript in Firefox, but that's not a suitable solution. There are two accounts on the computer, one for my wife and the other for me. Is it possible the infection is hopping from one to the other?

    Here are the logs from DDS:


    .
    DDS (Ver_2011-06-23.01) - NTFSx86
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
    Run by Peter at 19:23:38 on 2011-07-05
    Microsoft Windows XP Professional 5.1.2600.3.1252.353.1033.18.3327.2655 [GMT 1:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\ASUS\Drive Xpert\SteelVine.exe
    C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AskBarDis\bar\bin\AskService.exe
    C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    svchost.exe
    C:\Program Files\Digidesign\Drivers\MMERefresh.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe
    C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ASUS\Drive Xpert\DriveXpert.exe
    C:\WINDOWS\system32\DeltTray.exe
    C:\Program Files\dvd43\dvd43_tray.exe
    C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
    C:\Program Files\Alwil Software\Avast5\avastUI.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\Program Files\Chromatic Dragon\Toodledo Sync Application\SyncApp.exe
    C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
    C:\Program Files\Avanquest\PowerDesk\pddlghlp.exe
    C:\Documents and Settings\Peter\Application Data\Dropbox\bin\Dropbox.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Avanquest\PowerDesk\PDExplo.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = about:blank
    uSearch Page = hxxp://www.google.com
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uSearch Bar = hxxp://www.google.com/ie
    uDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
    BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
    BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - d:\program files\easy-webprint\EWPBrowseLoader.dll
    BHO: {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - No File
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\program files\stopzilla!\SZIEBHO.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - d:\program files\easy-webprint\Toolband.dll
    TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
    uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
    mRun: [QFan Help] "c:\program files\asus\ai suite\qfan3\QFanHelp.exe"
    mRun: [Cpu Level Up help] c:\program files\asus\ai suite\CpuLevelUpHelp.exe
    mRun: [Drive Xpert] c:\program files\asus\drive xpert\DriveXpert.exe
    mRun: [DeltTray] DeltTray.exe
    mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [DigidesignMMERefresh] c:\program files\digidesign\drivers\MMERefresh.exe
    mRun: [btbb_McciTrayApp] "c:\program files\bt broadband desktop help\btbb\BTHelpNotifier.exe"
    mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    StartupFolder: c:\docume~1\peter\startm~1\programs\startup\dialog~1.lnk - c:\program files\avanquest\powerdesk\pddlghlp.exe
    StartupFolder: c:\docume~1\peter\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\peter\application data\dropbox\bin\Dropbox.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\toodle~1.lnk - c:\windows\installer\{7d0c60cd-f5ff-4758-8a96-247d0da74c52}\_ABFE74A9AD95D30FB3A626.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\WIRELE~1.LNK -
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\zdwlan~1.lnk - c:\program files\zydas technology corporation\zydas_802.11g_utility\ZDWlan.exe
    IE: c:\documents and settings\peter\application data\flashgetbho\GetAllFlvUrl.htm
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Download all by FlashGet3 - c:\documents and settings\peter\application data\flashgetbho\GetAllUrl.htm
    IE: Download by FlashGet3 - c:\documents and settings\peter\application data\flashgetbho\GetUrl.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: Easy-WebPrint Add To Print List - d:\program files\easy-webprint\Toolband.dll/RC_AddToList.html
    IE: Easy-WebPrint High Speed Print - d:\program files\easy-webprint\Toolband.dll/RC_HSPrint.html
    IE: Easy-WebPrint Preview - d:\program files\easy-webprint\Toolband.dll/RC_Preview.html
    IE: Easy-WebPrint Print - d:\program files\easy-webprint\Toolband.dll/RC_Print.html
    IE: ????3?? - c:\documents and settings\peter\application data\flashgetbho\GetUrl.htm
    IE: ????3?????? - c:\documents and settings\peter\application data\flashgetbho\GetAllFlvUrl.htm
    IE: ????3?????? - c:\documents and settings\peter\application data\flashgetbho\GetAllUrl.htm
    IE: ????3?????? - c:\documents and settings\peter\application data\flashgetbho\GetFlvUrl.htm
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1235039350304
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{1492E342-451B-4CF6-8D5B-965093C9E269} : DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{D7F16A63-7857-4EE1-9B56-BC64EEA09DC3} : DhcpNameServer = 192.168.1.254
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: GoToAssist - c:\program files\citrix\gotoassist\570\G2AWinLogon.dll
    Notify: TPSvc - TPSvc.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    mASetup: {9C450606-ED24-4958-92BA-B8940C99D441} - c:\program files\pixiepack codec pack\InstallerHelper.exe
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath -
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys [2009-11-13 16384]
    R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [2009-12-7 61328]
    R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [2010-5-12 59280]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-1-8 165584]
    R2 57xx SteelVine Manager;57xx SteelVine;c:\program files\asus\drive xpert\SteelVine.exe [2008-5-29 1286144]
    R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312]
    R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-7-21 464264]
    R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-7-21 234888]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-1-8 17744]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-1-8 40384]
    R2 PaceLicenseDServices;PACE License Services;c:\program files\common files\pace\services\licenseservices\LDSvc.exe [2010-11-8 2647552]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2011-1-8 40384]
    S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [2009-12-7 61328]
    S0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys --> c:\windows\system32\drivers\mv61xx.sys [?]
    S0 xalcywi;xalcywi;c:\windows\system32\drivers\mahfr.sys --> c:\windows\system32\drivers\mahfr.sys [?]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-23 135664]
    S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-5-15 1684736]
    S3 CyUsb;Cypress Generic USB Driver;c:\windows\system32\drivers\CyUsb.sys [2010-1-30 31104]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-11-23 135664]
    S3 MAUSBXP;Service for M-Audio Xponent (WDM);c:\windows\system32\drivers\mausbxp.sys --> c:\windows\system32\drivers\mausbxp.sys [?]
    S3 MAUSBXPONENT;Service for M-Audio Xponent;c:\windows\system32\drivers\MAudioXponent.sys [2010-3-15 158344]
    S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [2010-9-24 167424]
    S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
    S3 V0010bVd;Creative WebCam Vista #2;c:\windows\system32\drivers\V0010bVd.sys [2010-12-10 186551]
    .
    =============== Created Last 30 ================
    .
    2011-07-05 15:44:47
    d
    w- c:\program files\STOPzilla!
    2011-07-05 15:44:46
    d
    w- c:\program files\common files\iS3
    2011-07-05 15:44:46
    d
    w- c:\documents and settings\all users\application data\STOPzilla!
    2011-06-30 17:13:46 132560 ----a-r- c:\windows\system32\IS3HTUI5.dll
    2011-06-30 17:13:44 99792 ----a-r- c:\windows\system32\IS3Svc5.dll
    2011-06-30 17:13:44 99792 ----a-r- c:\windows\system32\IS3Inet5.dll
    2011-06-30 17:13:44 67024 ----a-r- c:\windows\system32\IS3Hks5.dll
    2011-06-30 17:13:44 398800 ----a-r- c:\windows\system32\IS3DBA5.dll
    2011-06-30 17:13:44 28624 ----a-r- c:\windows\system32\IS3XDat5.dll
    2011-06-30 17:13:42 738768 ----a-r- c:\windows\system32\IS3Base5.dll
    2011-06-30 17:13:42 390608 ----a-r- c:\windows\system32\IS3UI5.dll
    2011-06-30 17:13:42 230864 ----a-r- c:\windows\system32\IS3Win325.dll
    2011-06-15 20:23:12
    d
    w- c:\program files\SlySoft
    2011-06-15 18:38:58
    d
    w- C:\Garmin
    2011-06-15 18:38:54
    d
    w- C:\MapSource
    2011-06-15 18:30:17
    d
    w- c:\documents and settings\all users\application data\GARMIN
    2011-06-14 18:34:35 105472 -c----w- c:\windows\system32\dllcache\mup.sys
    2011-06-09 22:11:24
    d
    w- c:\program files\M-Audio
    2011-06-06 09:20:40
    d
    w- c:\program files\Driving Test Success - All Tests 2011 Edition
    2011-06-06 09:20:40
    d
    w- c:\documents and settings\all users\application data\Driving Test Success
    .
    ==================== Find3M ====================
    .
    .
    ============= FINISH: 19:23:58.78 ===============

    AND


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-06-23.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 01/02/2009 12:57:29
    System Uptime: 05/07/2011 19:13:48 (0 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. | | P5Q
    Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | LGA 775 | 2400/266mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 923 GiB total, 666.497 GiB free.
    D: is FIXED (NTFS) - 8 GiB total, 7.231 GiB free.
    E: is FIXED (NTFS) - 932 GiB total, 658.927 GiB free.
    F: is FIXED (NTFS) - 932 GiB total, 670.223 GiB free.
    G: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E97B-E325-11CE-BFC1-08002BE10318}
    Description: Marvell 61xx RAID Controller
    Device ID: PCI\VEN_11AB&DEV_6121&SUBSYS_82E01043&REV_B2\4&34EBACD6&0&00E4
    Manufacturer: Marvell Inc.
    Name: Marvell 61xx RAID Controller
    PNP Device ID: PCI\VEN_11AB&DEV_6121&SUBSYS_82E01043&REV_B2\4&34EBACD6&0&00E4
    Service: mv61xx
    .
    Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
    Description: Nokia Windows Portable Device Driver
    Device ID: ROOT\WPD\0000
    Manufacturer: Nokia
    Name: Nokia E51
    PNP Device ID: ROOT\WPD\0000
    Service: WUDFRd
    .
    Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
    Description: Nokia 6120 classic
    Device ID: ROOT\WPD\0001
    Manufacturer: Nokia
    Name: Nokia 6120 classic
    PNP Device ID: ROOT\WPD\0001
    Service: WUDFRd
    .
    ==== System Restore Points ===================
    .
    RP753: 06/04/2011 16:20:21 - System Checkpoint
    RP754: 07/04/2011 17:04:57 - System Checkpoint
    RP755: 08/04/2011 17:56:44 - System Checkpoint
    RP756: 11/04/2011 14:29:36 - System Checkpoint
    RP757: 11/04/2011 21:19:27 - Installed Audials
    RP758: 12/04/2011 09:40:09 - Removed Audials
    RP759: 12/04/2011 09:41:13 - Removed Audials TV
    RP760: 12/04/2011 09:55:36 - Installed Tunebite
    RP761: 13/04/2011 10:16:15 - System Checkpoint
    RP762: 13/04/2011 12:41:33 - Removed Tunebite
    RP763: 13/04/2011 13:00:07 - Installed Audials
    RP764: 14/04/2011 13:38:59 - System Checkpoint
    RP765: 15/04/2011 03:00:20 - Software Distribution Service 3.0
    RP766: 16/04/2011 03:30:33 - System Checkpoint
    RP767: 17/04/2011 03:42:22 - System Checkpoint
    RP768: 18/04/2011 03:43:21 - System Checkpoint
    RP769: 19/04/2011 03:53:14 - System Checkpoint
    RP770: 20/04/2011 17:33:36 - System Checkpoint
    RP771: 21/04/2011 14:21:51 - Software Distribution Service 3.0
    RP772: 22/04/2011 15:04:33 - System Checkpoint
    RP773: 23/04/2011 16:20:41 - System Checkpoint
    RP774: 24/04/2011 17:15:22 - System Checkpoint
    RP775: 26/04/2011 09:16:11 - System Checkpoint
    RP776: 27/04/2011 09:28:57 - System Checkpoint
    RP777: 27/04/2011 17:17:30 - Software Distribution Service 3.0
    RP778: 28/04/2011 17:36:23 - System Checkpoint
    RP779: 29/04/2011 18:40:24 - System Checkpoint
    RP780: 30/04/2011 18:55:34 - System Checkpoint
    RP781: 01/05/2011 19:38:16 - System Checkpoint
    RP782: 02/05/2011 20:39:21 - System Checkpoint
    RP783: 03/05/2011 20:40:32 - System Checkpoint
    RP784: 04/05/2011 17:59:45 - Installed Torq 2.0.1
    RP785: 04/05/2011 18:07:17 - Installed Xponent
    RP786: 04/05/2011 20:44:31 - Removed Torq 2.0.1
    RP787: 04/05/2011 20:46:06 - Installed Torq 2.0
    RP788: 05/05/2011 21:46:08 - System Checkpoint
    RP789: 07/05/2011 00:25:12 - System Checkpoint
    RP790: 08/05/2011 00:40:56 - System Checkpoint
    RP791: 09/05/2011 00:52:57 - System Checkpoint
    RP792: 10/05/2011 01:53:07 - System Checkpoint
    RP793: 11/05/2011 02:53:15 - System Checkpoint
    RP794: 12/05/2011 03:00:21 - Software Distribution Service 3.0
    RP795: 13/05/2011 09:13:37 - System Checkpoint
    RP796: 14/05/2011 09:20:11 - System Checkpoint
    RP797: 15/05/2011 10:20:30 - System Checkpoint
    RP798: 15/05/2011 16:38:54 - Removed MobileMe Control Panel
    RP799: 15/05/2011 20:11:03 - Installed Realtek High Definition Audio Driver
    RP800: 16/05/2011 21:03:10 - System Checkpoint
    RP801: 17/05/2011 22:00:04 - System Checkpoint
    RP802: 18/05/2011 22:26:11 - System Checkpoint
    RP803: 20/05/2011 00:12:23 - System Checkpoint
    RP804: 21/05/2011 02:00:14 - System Checkpoint
    RP805: 22/05/2011 02:59:19 - System Checkpoint
    RP806: 23/05/2011 03:47:17 - System Checkpoint
    RP807: 24/05/2011 04:47:28 - System Checkpoint
    RP808: 25/05/2011 04:59:27 - System Checkpoint
    RP809: 26/05/2011 10:08:13 - System Checkpoint
    RP810: 27/05/2011 10:48:06 - System Checkpoint
    RP811: 28/05/2011 11:34:17 - System Checkpoint
    RP812: 29/05/2011 11:35:23 - System Checkpoint
    RP813: 30/05/2011 11:50:25 - System Checkpoint
    RP814: 31/05/2011 12:46:28 - System Checkpoint
    RP815: 01/06/2011 12:56:53 - System Checkpoint
    RP816: 02/06/2011 13:46:18 - System Checkpoint
    RP817: 03/06/2011 14:53:50 - System Checkpoint
    RP818: 04/06/2011 15:34:12 - System Checkpoint
    RP819: 05/06/2011 15:46:13 - System Checkpoint
    RP820: 06/06/2011 17:05:53 - System Checkpoint
    RP821: 07/06/2011 17:38:15 - System Checkpoint
    RP822: 08/06/2011 19:13:26 - System Checkpoint
    RP823: 09/06/2011 19:18:16 - System Checkpoint
    RP824: 09/06/2011 22:59:41 - Update to an unsigned driver
    RP825: 09/06/2011 23:55:47 - Update to an unsigned driver
    RP826: 11/06/2011 00:24:44 - System Checkpoint
    RP827: 12/06/2011 01:09:51 - System Checkpoint
    RP828: 13/06/2011 02:09:51 - System Checkpoint
    RP829: 14/06/2011 02:23:21 - System Checkpoint
    RP830: 14/06/2011 20:48:04 - Software Distribution Service 3.0
    RP831: 15/06/2011 19:36:51 - Installed Garmin City Navigator Europe NT 2011.10
    RP832: 16/06/2011 08:31:11 - Installed Garmin City Navigator Europe NT 2012.10 Update
    RP833: 17/06/2011 08:35:21 - System Checkpoint
    RP834: 18/06/2011 08:44:59 - System Checkpoint
    RP835: 19/06/2011 08:48:03 - System Checkpoint
    RP836: 20/06/2011 08:52:24 - System Checkpoint
    RP837: 21/06/2011 09:51:50 - System Checkpoint
    RP838: 22/06/2011 10:25:07 - System Checkpoint
    RP839: 23/06/2011 11:36:02 - System Checkpoint
    RP840: 24/06/2011 12:24:02 - System Checkpoint
    RP841: 25/06/2011 12:36:03 - System Checkpoint
    RP842: 26/06/2011 13:24:07 - System Checkpoint
    RP843: 27/06/2011 13:25:07 - System Checkpoint
    RP844: 28/06/2011 13:36:02 - System Checkpoint
    RP845: 29/06/2011 00:28:22 - Software Distribution Service 3.0
    RP846: 30/06/2011 00:57:00 - System Checkpoint
    RP847: 01/07/2011 01:21:16 - System Checkpoint
    RP848: 02/07/2011 02:09:33 - System Checkpoint
    RP849: 03/07/2011 02:28:10 - System Checkpoint
    RP850: 03/07/2011 12:06:41 - Installed Java(TM) 6 Update 26
    RP851: 04/07/2011 12:21:23 - System Checkpoint
    RP852: 05/07/2011 12:33:03 - System Checkpoint
    RP853: 05/07/2011 16:44:37 - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
    RP854: 05/07/2011 18:48:04 - Automatic Restore Point
    .
    ==== Installed Programs ======================
    .
    .
    ==== Event Viewer Messages From Past Week ========
    .
    05/07/2011 18:49:24, error: Service Control Manager [7034] - The SiS WirelessLan Service service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:24, error: Service Control Manager [7034] - The PACE License Services service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:24, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:24, error: Service Control Manager [7034] - The Digidesign MME Refresh Service service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:23, error: Service Control Manager [7034] - The McciCMService service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:23, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:23, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:23, error: Service Control Manager [7034] - The Adobe Active File Monitor V7 service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:23, error: Service Control Manager [7034] - The 57xx SteelVine service terminated unexpectedly. It has done this 1 time(s).
    05/07/2011 18:49:23, error: Service Control Manager [7031] - The ASKUpgrade service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    05/07/2011 18:49:23, error: Service Control Manager [7031] - The ASKService service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    05/07/2011 18:49:23, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    05/07/2011 16:43:08, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
    01/07/2011 00:17:35, error: ipnathlp [30013] - The DHCP allocator has disabled itself on IP address 192.168.1.67, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, please change the scope to include the IP address, or change the IP address to fall within the scope.
    01/07/2011 00:17:34, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: mv61xx
    .
    ==== End Of File ===========================

    Here is the log from Gooredfix as well:

    GooredFix by jpshortstuff (03.07.10.1)
    Log created at 15:50 on 05/07/2011 (Peter)
    Firefox version 5.0 (en-GB)

    ========== GooredScan ==========


    ========== GooredLog ==========

    C:\Program Files\Mozilla Firefox\extensions\
    (none)

    C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\le2nitj1.default\extensions\
    {35f30c76-35d4-56d9-8dbc-000a6e787ef4} [12:38 22/02/2009]
    {4DC70064-89E2-4a55-8FC6-E8CDEAE3612C} [03:18 30/05/2009]
    {635abd67-4fe9-1b23-4f01-e679fa7484c1} [15:16 10/05/2011]
    {E9A1DEE0-C623-4439-8932-001E7D17607D} [21:37 21/07/2009]

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
    "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [02:03 02/04/2010]
    "bkmrksync@nokia.com"="C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\" [19:43 17/12/2010]
    "jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [19:29 03/02/2009]

    Old Logs
    GooredFix[21.09.18_03-07-2011].txt
    GooredFix[21.10.07_03-07-2011].txt

    -=E.O.F=-

    If you can help, i'd be very grateful. I've been battling this for a week now.


    S.P.


Comments

  • Site Banned Posts: 1,167 ✭✭✭ASJ112


    download and run tdsskiller

    http://support.kaspersky.com/faq/?qid=208283363

    let it fix what it finds and post its log. Redirects gone after that ?


  • Registered Users, Registered Users 2 Posts: 172 ✭✭Sinister Pete


    Negatory. It found nothing on both accounts.


    2011/07/05 23:37:47.0625 4720 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
    2011/07/05 23:37:47.0953 4720 ================================================================================
    2011/07/05 23:37:47.0953 4720 SystemInfo:
    2011/07/05 23:37:47.0953 4720
    2011/07/05 23:37:47.0953 4720 OS Version: 5.1.2600 ServicePack: 3.0
    2011/07/05 23:37:47.0953 4720 Product type: Workstation
    2011/07/05 23:37:47.0953 4720 ComputerName: PETER-0D8FD2123
    2011/07/05 23:37:47.0953 4720 UserName: Peter
    2011/07/05 23:37:47.0953 4720 Windows directory: C:\WINDOWS
    2011/07/05 23:37:47.0953 4720 System windows directory: C:\WINDOWS
    2011/07/05 23:37:47.0953 4720 Processor architecture: Intel x86
    2011/07/05 23:37:47.0953 4720 Number of processors: 4
    2011/07/05 23:37:47.0953 4720 Page size: 0x1000
    2011/07/05 23:37:47.0953 4720 Boot type: Normal boot
    2011/07/05 23:37:47.0953 4720 ================================================================================
    2011/07/05 23:37:50.0000 4720 Initialize success
    2011/07/05 23:37:54.0109 5772 ================================================================================
    2011/07/05 23:37:54.0109 5772 Scan started
    2011/07/05 23:37:54.0109 5772 Mode: Manual;
    2011/07/05 23:37:54.0109 5772 ================================================================================
    2011/07/05 23:37:55.0062 5772 Aavmker4 (8d488938e2f7048906f1fbd3af394887) C:\WINDOWS\system32\drivers\Aavmker4.sys
    2011/07/05 23:37:55.0140 5772 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2011/07/05 23:37:55.0171 5772 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2011/07/05 23:37:55.0203 5772 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    2011/07/05 23:37:55.0234 5772 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
    2011/07/05 23:37:55.0281 5772 AFS2K (b34b1ab0a7690a0e2301fec6d17b2fc1) C:\WINDOWS\system32\drivers\AFS2K.sys
    2011/07/05 23:37:55.0390 5772 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys
    2011/07/05 23:37:55.0453 5772 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
    2011/07/05 23:37:55.0515 5772 AsIO (2b4e66fac6503494a2c6f32bb6ab3826) C:\WINDOWS\system32\drivers\AsIO.sys
    2011/07/05 23:37:55.0562 5772 aswFsBlk (a0d86b8ac93ef95620420c7a24ac5344) C:\WINDOWS\system32\drivers\aswFsBlk.sys
    2011/07/05 23:37:55.0578 5772 aswMon2 (7d880c76a285a41284d862e2d798ec0d) C:\WINDOWS\system32\drivers\aswMon2.sys
    2011/07/05 23:37:55.0593 5772 aswRdr (69823954bbd461a73d69774928c9737e) C:\WINDOWS\system32\drivers\aswRdr.sys
    2011/07/05 23:37:55.0609 5772 aswSP (7ecc2776638b04553f9a85bd684c3abf) C:\WINDOWS\system32\drivers\aswSP.sys
    2011/07/05 23:37:55.0640 5772 aswTdi (095ed820a926aa8189180b305e1bcfc9) C:\WINDOWS\system32\drivers\aswTdi.sys
    2011/07/05 23:37:55.0656 5772 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2011/07/05 23:37:55.0671 5772 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2011/07/05 23:37:55.0703 5772 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2011/07/05 23:37:55.0734 5772 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2011/07/05 23:37:55.0781 5772 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2011/07/05 23:37:55.0812 5772 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
    2011/07/05 23:37:55.0843 5772 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
    2011/07/05 23:37:55.0859 5772 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
    2011/07/05 23:37:55.0875 5772 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys
    2011/07/05 23:37:55.0906 5772 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
    2011/07/05 23:37:56.0031 5772 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2011/07/05 23:37:56.0046 5772 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    2011/07/05 23:37:56.0078 5772 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2011/07/05 23:37:56.0109 5772 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    2011/07/05 23:37:56.0140 5772 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2011/07/05 23:37:56.0218 5772 CyUsb (5d7fa9b0591f0474a83a4e4a9bf7b9af) C:\WINDOWS\system32\Drivers\CyUsb.sys
    2011/07/05 23:37:56.0281 5772 DELTA (fff42aca78b2e6369f98c8c672375e0a) C:\WINDOWS\system32\DRIVERS\delta.sys
    2011/07/05 23:37:56.0312 5772 DigiFilter (ba912376605b72b1039da461c1fa19c6) C:\WINDOWS\system32\drivers\DigiFilt.sys
    2011/07/05 23:37:56.0328 5772 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    2011/07/05 23:37:56.0375 5772 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
    2011/07/05 23:37:56.0390 5772 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
    2011/07/05 23:37:56.0406 5772 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2011/07/05 23:37:56.0437 5772 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    2011/07/05 23:37:56.0500 5772 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    2011/07/05 23:37:56.0515 5772 dvd43llh (1fc1eed3ea0c3a0ecf8a95b97e1b4831) C:\WINDOWS\system32\DRIVERS\dvd43llh.sys
    2011/07/05 23:37:56.0578 5772 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    2011/07/05 23:37:56.0609 5772 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2011/07/05 23:37:56.0625 5772 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
    2011/07/05 23:37:56.0656 5772 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2011/07/05 23:37:56.0687 5772 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    2011/07/05 23:37:56.0734 5772 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2011/07/05 23:37:56.0734 5772 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2011/07/05 23:37:56.0765 5772 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
    2011/07/05 23:37:56.0781 5772 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2011/07/05 23:37:56.0828 5772 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
    2011/07/05 23:37:56.0859 5772 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2011/07/05 23:37:57.0000 5772 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    2011/07/05 23:37:57.0031 5772 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\drivers\i8042prt.sys
    2011/07/05 23:37:57.0062 5772 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2011/07/05 23:37:57.0203 5772 IntcAzAudAddService (0cacdcbbc8e6f11e2865c47bfc509848) C:\WINDOWS\system32\drivers\RtkHDAud.sys
    2011/07/05 23:37:57.0265 5772 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    2011/07/05 23:37:57.0296 5772 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    2011/07/05 23:37:57.0312 5772 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2011/07/05 23:37:57.0328 5772 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2011/07/05 23:37:57.0359 5772 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2011/07/05 23:37:57.0375 5772 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2011/07/05 23:37:57.0406 5772 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2011/07/05 23:37:57.0453 5772 is3srv (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\drivers\is3srv.sys
    2011/07/05 23:37:57.0484 5772 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2011/07/05 23:37:57.0500 5772 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2011/07/05 23:37:57.0515 5772 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
    2011/07/05 23:37:57.0546 5772 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    2011/07/05 23:37:57.0578 5772 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    2011/07/05 23:37:57.0609 5772 L1e (93e64bab9dee162ca0ca5258d132a047) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys
    2011/07/05 23:37:57.0687 5772 MAUSBXPONENT (002cea903c11756fbc33221a163979f6) C:\WINDOWS\system32\DRIVERS\MAudioXponent.sys
    2011/07/05 23:37:57.0875 5772 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2011/07/05 23:37:57.0906 5772 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
    2011/07/05 23:37:57.0953 5772 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys
    2011/07/05 23:37:57.0968 5772 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2011/07/05 23:37:58.0031 5772 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2011/07/05 23:37:58.0046 5772 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    2011/07/05 23:37:58.0125 5772 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
    2011/07/05 23:37:58.0156 5772 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
    2011/07/05 23:37:58.0171 5772 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2011/07/05 23:37:58.0218 5772 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2011/07/05 23:37:58.0234 5772 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    2011/07/05 23:37:58.0265 5772 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    2011/07/05 23:37:58.0281 5772 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2011/07/05 23:37:58.0281 5772 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    2011/07/05 23:37:58.0296 5772 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2011/07/05 23:37:58.0328 5772 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
    2011/07/05 23:37:58.0359 5772 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
    2011/07/05 23:37:58.0390 5772 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
    2011/07/05 23:37:58.0421 5772 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    2011/07/05 23:37:58.0453 5772 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    2011/07/05 23:37:58.0484 5772 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    2011/07/05 23:37:58.0500 5772 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2011/07/05 23:37:58.0531 5772 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2011/07/05 23:37:58.0546 5772 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2011/07/05 23:37:58.0578 5772 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
    2011/07/05 23:37:58.0593 5772 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2011/07/05 23:37:58.0609 5772 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2011/07/05 23:37:58.0640 5772 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
    2011/07/05 23:37:58.0671 5772 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\WINDOWS\system32\drivers\ccdcmb.sys
    2011/07/05 23:37:58.0703 5772 nmwcdc (2914ceb789964141ac6e22c6bc980c42) C:\WINDOWS\system32\drivers\ccdcmbo.sys
    2011/07/05 23:37:58.0718 5772 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    2011/07/05 23:37:58.0750 5772 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    2011/07/05 23:37:58.0812 5772 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2011/07/05 23:37:58.0984 5772 nv (1fc95a1bc5330617c60814fbe73c4fda) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    2011/07/05 23:37:59.0109 5772 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2011/07/05 23:37:59.0125 5772 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2011/07/05 23:37:59.0140 5772 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
    2011/07/05 23:37:59.0171 5772 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
    2011/07/05 23:37:59.0218 5772 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    2011/07/05 23:37:59.0234 5772 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    2011/07/05 23:37:59.0265 5772 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
    2011/07/05 23:37:59.0281 5772 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
    2011/07/05 23:37:59.0328 5772 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2011/07/05 23:37:59.0343 5772 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2011/07/05 23:37:59.0390 5772 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
    2011/07/05 23:37:59.0484 5772 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2011/07/05 23:37:59.0500 5772 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    2011/07/05 23:37:59.0515 5772 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2011/07/05 23:37:59.0546 5772 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    2011/07/05 23:37:59.0609 5772 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2011/07/05 23:37:59.0640 5772 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2011/07/05 23:37:59.0656 5772 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2011/07/05 23:37:59.0671 5772 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2011/07/05 23:37:59.0703 5772 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2011/07/05 23:37:59.0718 5772 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2011/07/05 23:37:59.0734 5772 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    2011/07/05 23:37:59.0781 5772 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    2011/07/05 23:37:59.0843 5772 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2011/07/05 23:37:59.0875 5772 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
    2011/07/05 23:37:59.0921 5772 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    2011/07/05 23:37:59.0937 5772 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
    2011/07/05 23:37:59.0968 5772 SCDEmu (23aa53256ce05b975398b78a33474265) C:\WINDOWS\system32\drivers\SCDEmu.sys
    2011/07/05 23:38:00.0000 5772 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2011/07/05 23:38:00.0031 5772 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2011/07/05 23:38:00.0062 5772 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
    2011/07/05 23:38:00.0093 5772 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2011/07/05 23:38:00.0156 5772 SIS163u (24c563c9ab67db0d80070c8e0945ff87) C:\WINDOWS\system32\DRIVERS\sis163u.sys
    2011/07/05 23:38:00.0187 5772 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    2011/07/05 23:38:00.0218 5772 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
    2011/07/05 23:38:00.0265 5772 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    2011/07/05 23:38:00.0296 5772 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
    2011/07/05 23:38:00.0328 5772 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
    2011/07/05 23:38:00.0375 5772 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    2011/07/05 23:38:00.0390 5772 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2011/07/05 23:38:00.0406 5772 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    2011/07/05 23:38:00.0484 5772 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    2011/07/05 23:38:00.0515 5772 szkg5 (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\DRIVERS\szkg.sys
    2011/07/05 23:38:00.0531 5772 szkgfs (410a02a920fa9daeec56364e839597c1) C:\WINDOWS\system32\drivers\szkgfs.sys
    2011/07/05 23:38:00.0546 5772 tbhsd (4d46f63f7ddc2442941d63327c360b90) C:\WINDOWS\system32\drivers\tbhsd.sys
    2011/07/05 23:38:00.0578 5772 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2011/07/05 23:38:00.0609 5772 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2011/07/05 23:38:00.0625 5772 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    2011/07/05 23:38:00.0687 5772 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2011/07/05 23:38:00.0750 5772 TPkd (a685ea497fb6a6f4ffee705caf185096) C:\WINDOWS\system32\drivers\TPkd.sys
    2011/07/05 23:38:00.0781 5772 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    2011/07/05 23:38:00.0796 5772 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    2011/07/05 23:38:00.0843 5772 upperdev (e526a166e6acafd0a9b3841d3941669e) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
    2011/07/05 23:38:00.0890 5772 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys
    2011/07/05 23:38:00.0921 5772 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
    2011/07/05 23:38:00.0984 5772 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    2011/07/05 23:38:01.0031 5772 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2011/07/05 23:38:01.0062 5772 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2011/07/05 23:38:01.0093 5772 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    2011/07/05 23:38:01.0156 5772 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2011/07/05 23:38:01.0187 5772 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys
    2011/07/05 23:38:01.0218 5772 UsbserFilt (6f3e3c6811b930d2414552a2e4a40f36) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
    2011/07/05 23:38:01.0250 5772 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2011/07/05 23:38:01.0281 5772 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    2011/07/05 23:38:01.0312 5772 V0010bVd (11596c313e302bc75e261974323d2aac) C:\WINDOWS\system32\DRIVERS\V0010bVd.sys
    2011/07/05 23:38:01.0359 5772 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    2011/07/05 23:38:01.0375 5772 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
    2011/07/05 23:38:01.0406 5772 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2011/07/05 23:38:01.0437 5772 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
    2011/07/05 23:38:01.0484 5772 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    2011/07/05 23:38:01.0546 5772 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
    2011/07/05 23:38:01.0578 5772 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    2011/07/05 23:38:01.0609 5772 WudfPf (eaa6324f51214d2f6718977ec9ce0def) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2011/07/05 23:38:01.0640 5772 WudfRd (f91ff1e51fca30b3c3981db7d5924252) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    2011/07/05 23:38:01.0703 5772 ZD1211BU(ZyDAS) (154fe6a5a608cd725266877901e883c2) C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys
    2011/07/05 23:38:01.0734 5772 ZDPSp50 (00ae175b903d45ed4a62384d3315dc2a) C:\WINDOWS\system32\Drivers\ZDPSp50.sys
    2011/07/05 23:38:01.0781 5772 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
    2011/07/05 23:38:01.0875 5772 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
    2011/07/05 23:38:01.0890 5772 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
    2011/07/05 23:38:01.0890 5772 Boot (0x1200) (557eb5fcd1d9c996273f41f5f0d0609b) \Device\Harddisk0\DR0\Partition0
    2011/07/05 23:38:01.0921 5772 Boot (0x1200) (3b9199478c0a6d4e69058a33508714b1) \Device\Harddisk0\DR0\Partition1
    2011/07/05 23:38:01.0937 5772 Boot (0x1200) (20738412f950ad776644feee9c974656) \Device\Harddisk1\DR1\Partition0
    2011/07/05 23:38:01.0937 5772 Boot (0x1200) (e06d8b2c1f5441a43183df271dbd8fe2) \Device\Harddisk2\DR2\Partition0
    2011/07/05 23:38:01.0953 5772 ================================================================================
    2011/07/05 23:38:01.0953 5772 Scan finished
    2011/07/05 23:38:01.0953 5772 ================================================================================
    2011/07/05 23:38:01.0953 5740 Detected object count: 0
    2011/07/05 23:38:01.0953 5740 Actual detected object count: 0


  • Site Banned Posts: 1,167 ✭✭✭ASJ112


    download and run combofix

    http://www.bleepingcomputer.com/download/anti-virus/combofix

    post the log it gives you


  • Registered Users, Registered Users 2 Posts: 172 ✭✭Sinister Pete


    That done done the trick. Thanks!


Advertisement