Hi, new to this place... and first time ever seeing this problem on my computer. Right now, my symptoms are browser redirection to other sites as well as computer running very slowly and occasionally freezing up. Would appreciate the help very much, thanks!!
Here's my HiJack file.
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:57:36 PM, on 3/12/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal
I'm kevinf80 and I will be helping with any malware issues you may have with your system.
Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Either print or Save to Notepad all instructions and please follow them carefully, if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
If you do not reply within 72 hours the thread will be closed, if you need more time let me know. Likewise if I do not respond within 48 hours feel free to PM me.
If you have any P2P applications installed such as BitTorrent, uTorrent, Limewire etc etc, please uninstall them before we begin.
If you are using Cracked or Illegal software your thread will be locked and all help will cease.
Please proceed as follows :-
Step 1
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot
Step 2
Please download OTM by OldTimer. Alternative Mirror Save it to your desktop. Double click OTM.exe to start the tool. Vista or Windows 7 users right click and select Run as Administrator
Copy the text between the dotted lines below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy): ------------------------------------------------------------------- :Services :Files ipconfig /flushdns /c C:\WINDOWS\atipehuk.dll C:\WINDOWS\winshs.dll C:\Program Files\AskBarDis :Commands [Purity] [EmptyFlash] [EmptyTemp] [ResetHosts]
Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
Click the red button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If the machine reboots, the Results log can be found here:
c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log
Where mmddyyyy_hhmmss is the date of the tool run.
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
Please save the log to a location you will remember.
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Post logs from OTM and Malwarebytes in your reply, also give update on any remaining issues. Is there a specific reason why you still have IE6, why have you not updated to IE8
To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista & Win 7).
When prompted to run the scan, click Yes.
GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
Step 2
Download OTL from any of the following links and save to your Desktop:
Double click on the icon to run it, Vista or Windows 7 users right click and select Run as Administartor. Make sure all other windows are closed and to let it run uninterrupted.
In the lower right corner, checkmark "LOP Check" and checkmark "Purity Check".
Under the Custom Scan box paste this in from between the dotted lines ------------------------------------------------------------------------------------------------------------ netsvcs drivers32 %SYSTEMDRIVE%\*.* %systemroot%\*. /mp /s CREATERESTOREPOINT %systemroot%\System32\config\*.sav HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs --------------------------------------------------------------------------------------------------------------------------------
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your reply
Thank you very much!! I'm surprised and grateful for the quick response.After having followed your instructions here are the logs for the OTM and MBAM scans respectively. As for not having yet updated to IE8, I don't use IE much so that's the only reason (Actually I just recently redownloaded IE in order to test out my website coding otherwise I almost always use firefox and chrome only). The immediate issue that I can see is that whenever I open up my firefox, sophos alerts me with "File "C:\Documents and Settings\jey\Local Settings\Application Data\{8BC5CD56-2F1B4164-856B-DBD461C1B1BB}\chrome\content\overlay.xul" belongs to virus/spyware Troj/FFAdRedr-A."
OTM log:
All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. C:\Documents and Settings\jey\Desktop\cmd.bat deleted successfully. C:\Documents and Settings\jey\Desktop\cmd.txt deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\atipehuk.dll C:\WINDOWS\atipehuk.dll moved successfully. File/Folder C:\WINDOWS\winshs.dll not found. File/Folder C:\Program Files\AskBarDis not found. ========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes
OTL logfile created on: 3/13/2011 7:03:53 PM - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\jey\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 68.48 Gb Total Space | 11.03 Gb Free Space | 16.10% Space Free | Partition Type: NTFS
Computer Name: CHOGINGA | User Name: jey | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found
@Alternate Data Stream - 999 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:M1cYjFELUVw9FgLG7mKq7 @Alternate Data Stream - 1233 bytes -> C:\Program Files\Common Files\Microsoft Shared:woHDxYGPREhzkFt2SlfuDs8v @Alternate Data Stream - 1185 bytes -> C:\Documents and Settings\jey\Local Settings\Application Data\6BURkWLd:QYEvXf364blRAEBr77oM @Alternate Data Stream - 1096 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:SpA9WLA9Ynl24YQROGQdMhhn
< End of report >
Extras Txt
OTL Extras logfile created on: 3/13/2011 7:03:53 PM - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\jey\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 68.48 Gb Total Space | 11.03 Gb Free Space | 16.10% Space Free | Partition Type: NTFS
Computer Name: CHOGINGA | User Name: jey | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 -- (Adobe Systems Incorporated) "C:\Program Files\WinSCP\WinSCP.exe" = C:\Program Files\WinSCP\WinSCP.exe:*:Enabled:SFTP, FTP and SCP client -- (Martin Prikryl) "C:\Documents and Settings\jey\Desktop\games\diablo2\Game.exe" = C:\Documents and Settings\jey\Desktop\games\diablo2\Game.exe:*:Enabled:Game "C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam "C:\Program Files\Steam\steamapps\mathfreq\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\mathfreq\team fortress 2\hl2.exe:*:Enabled:hl2 "C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager -- (Nexon) "C:\Program Files\Nexon\DFO\DFO.exe" = C:\Program Files\Nexon\DFO\DFO.exe:*:Enabled:Dungeon Fighter Online "C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Launcher -- (Blizzard Entertainment) "C:\Program Files\Autodesk\Maya2009\bin\maya.exe" = C:\Program Files\Autodesk\Maya2009\bin\maya.exe:*:Enabled:Maya -- (Autodesk) "C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe" = C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment) "C:\Program Files\World of Warcraft\Launcher.patch.exe" = C:\Program Files\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4 "{034759DA-E21A-4795-BFB3-C66D17FAD183}" = Sophos Anti-Virus "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4 "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4 "{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4 "{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4 "{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4 "{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4 "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4 "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB "{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4 "{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler "{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe "{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 14 "{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour "{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman) "{2F05CEAF-A575-41E5-B3D0-FE4CEF83CA0A}" = Maya 2009 "{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{35BA2BAF-FFD4-4B12-B42B-AA8CC902CD23}" = Autodesk DirectConnect 2009 "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4 "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4 "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4 "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin "{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA "{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit "{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets "{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4 "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension "{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4 "{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}" = Adobe Audition 3.0 "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4 "{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support "{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller "{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4 "{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support "{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4 "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK "{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en "{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files "{7F03BDCD-E21B-4035-9FC6-9DF100006841}" = openCanvas3.03E Plus "{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer "{819E24AA-DB15-4BA8-8D76-92BDF710610B}" = Adobe Setup "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4 "{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4 "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4 "{85CFC80F-B410-42E7-855F-F2AE1DF64315}" = DELETER COMICWORKS "{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4 "{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr "{8EB8E60B-315D-44EB-A896-10D88602EE46}" = Adobe Setup "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4 "{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4 "{97C4F970-C753-443F-B61C-525C739BBC3D}" = Maya 2009 Documentation (en_US) "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9F8FDE1A-FA91-43F2-887B-CF080156D57E}" = Adobe Setup "{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver "{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio "{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Fran軋is, Deutsch "{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4 "{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4 "{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4 "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module "{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4 "{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{CDEBE7FF-C832-4B91-9214-A4CA610D78C9}" = Adobe Audition 3.0.1 Patch "{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4 "{D56B0E27-4A3E-46C9-B5C1-D93D580C099C}" = NVIDIA PhysX v8.10.29 "{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4 "{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1 "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore "{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup "{EC68232E-C74E-4F1A-B296-DFD2E1944E10}" = Adobe Setup "{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help "{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi "{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4 "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4 "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4 "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All "53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) "Adobe Audition 3.0" = Adobe Audition 3.0 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe_5aab5a491a3a52ae624fd639f6aaa95" = Adobe After Effects CS4 Third Party Content "Adobe_5eba9bbdf1514a06b1a4c79a2920188" = Adobe Media Encoder CS4 Exporter "Adobe_6e02d32c7e5a9d9fc86bc91618cafda" = Adobe Premiere Pro CS4 Third Party Content "Adobe_7774cb1e022c49962995a9014500066" = Adobe Media Encoder CS4 Importer "Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "FULL CLIENT8.0" = FULL CLIENT "HDMI" = Intel(R) Graphics Media Accelerator Driver "ie8" = Windows Internet Explorer 8 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15) "Notepad++" = Notepad++ "ProInst" = Intel(R) PROSet/Wireless Software "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player 1.0.0 "Wacom Tablet Driver" = Wacom Tablet "Winamp" = Winamp "Windows Media Format Runtime" = Windows Media Format Runtime "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "winscp3_is1" = WinSCP 4.2.1 beta "World of Warcraft" = World of Warcraft
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ] Error - 12/27/2010 12:16:00 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.
Error - 12/27/2010 12:16:01 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
Error - 12/27/2010 12:16:01 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist.
Error - 12/27/2010 8:50:04 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
Error - 12/27/2010 8:50:18 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
Error - 12/27/2010 8:50:18 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
Error - 12/27/2010 8:50:37 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
Error - 12/27/2010 8:50:37 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
Error - 12/27/2010 8:51:15 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
Error - 12/27/2010 8:51:15 PM | Computer Name = CHOGINGA | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid.
[ System Events ] Error - 3/13/2011 5:02:58 AM | Computer Name = CHOGINGA | Source = SAVOnAccessControl | ID = 3997781 Description = File [...3KJVI\desktop.ini]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process OTM.exe, (start check timestamp [ 1cbe15d72ad1046]).
Error - 3/13/2011 5:03:01 AM | Computer Name = CHOGINGA | Source = SAVOnAccessControl | ID = 3997781 Description = File [...ZC92F\desktop.ini]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process OTM.exe, (start check timestamp [ 1cbe15d74793620]).
Error - 3/13/2011 5:03:36 AM | Computer Name = CHOGINGA | Source = SAVOnAccessControl | ID = 3997781 Description = File [...DeviceService.exe]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process services.exe, (start check timestamp [ 1cbe15d893b8fc2]).
Error - 3/13/2011 5:03:36 AM | Computer Name = CHOGINGA | Source = SAVOnAccessControl | ID = 3997781 Description = File [...50727.4053.policy]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process csrss.exe, (start check timestamp [ 1cbe15d8949ddde]).
Error - 3/13/2011 5:06:18 AM | Computer Name = CHOGINGA | Source = Ftdisk | ID = 262189 Description = The system could not sucessfully load the crash dump driver.
Error - 3/13/2011 5:06:18 AM | Computer Name = CHOGINGA | Source = Ftdisk | ID = 262193 Description = Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
Error - 3/13/2011 5:06:35 AM | Computer Name = CHOGINGA | Source = SAVOnAccessFilter | ID = 3997749 Description = The on-access driver failed to attach to \Device\ADVirtualDisk\Volume, because the IO method is not supported.
Error - 3/13/2011 8:19:43 PM | Computer Name = CHOGINGA | Source = Ftdisk | ID = 262189 Description = The system could not sucessfully load the crash dump driver.
Error - 3/13/2011 8:19:43 PM | Computer Name = CHOGINGA | Source = Ftdisk | ID = 262193 Description = Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
Error - 3/13/2011 8:19:55 PM | Computer Name = CHOGINGA | Source = SAVOnAccessFilter | ID = 3997749 Description = The on-access driver failed to attach to \Device\ADVirtualDisk\Volume, because the IO method is not supported.
Thanks again for all your help. I haven't noticed any new issues. Other than redirection problems, sometimes I get this
"Content Encoding Error
The page you are trying to view cannot be shown because it uses an invalid or unsupported form of compression. Please contact the website owners to inform them of this problem."
when I try to visit a website.
OTL Log
All processes killed ========== OTL ========== C:\Documents and Settings\jey\Application Data\Mozilla\Firefox\Profiles\brue07y5.default\searchplugins\ask.xml moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Qpumotefaco deleted successfully. C:\WINDOWS\tasks\Gtppze.job moved successfully. C:\WINDOWS\Egube.bin moved successfully. C:\WINDOWS\Pfepezenocopolo.dat moved successfully. C:\Documents and Settings\jey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully. ADS C:\Documents and Settings\All Users\Application Data\Microsoft:M1cYjFELUVw9FgLG7mKq7 deleted successfully. ADS C:\Program Files\Common Files\Microsoft Shared:woHDxYGPREhzkFt2SlfuDs8v deleted successfully. ADS C:\Documents and Settings\jey\Local Settings\Application Data\6BURkWLd:QYEvXf364blRAEBr77oM deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\Microsoft:SpA9WLA9Ynl24YQROGQdMhhn deleted successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. C:\Documents and Settings\jey\Desktop\cmd.bat deleted successfully. C:\Documents and Settings\jey\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes
OTL by OldTimer - Version 3.2.22.3 log created on 03142011_113904
Files\Folders moved on Reboot... C:\Documents and Settings\jey\Local Settings\Temp\PDFMCustom.dot moved successfully. File\Folder C:\Documents and Settings\jey\Local Settings\Temp\~DF52A8.tmp not found! File\Folder C:\Documents and Settings\jey\Local Settings\Temp\~DF5321.tmp not found! File\Folder C:\Documents and Settings\jey\Local Settings\Temp\~DF58A7.tmp not found! File\Folder C:\Documents and Settings\jey\Local Settings\Temp\~WRF0002.tmp not found!
Registry entries deleted on Reboot...
ESET log
C:\Program Files\IEToolbar\Google Toolbar\tbs_include_script_024945.js HTML/ScrInject.B.Gen virus C:\Program Files\IEToolbar\Google Toolbar\tbu08803\tbs_include_script_024945.js HTML/ScrInject.B.Gen virus C:\_OTM\MovedFiles\03132011_010235\C_WINDOWS\atipehuk.dll a variant of Win32/Kryptik.KNA trojan
Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Post relevant logs please and give update on remaining issues.
Thanks, I'll keep you updated on the redirected searches since it still seems to happen occasionally... but I can't tell for certain how often it happens or not : /
TDSSKiller has caught a couple by the tail, you should see an improvement now... let me know how your system is responding and what specific issues remain..
kevinf80_1d0ac6
2 Intern
•
1131 Posts
672
0
Posted March 13th, 2011 01:00
Hello kidoairaku and welcome,
I'm kevinf80 and I will be helping with any malware issues you may have with your system.
Please proceed as follows :-
Step 1
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll (file missing)
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)
O4 - HKLM\..\Run: [Qpumotefaco] rundll32.exe "C:\WINDOWS\atipehuk.dll",Startup
O4 - HKCU\..\Run: [Tvoruquga] rundll32.exe "C:\WINDOWS\winshs.dll",Startup
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot
Step 2
Please download OTM by OldTimer.
Alternative Mirror
Save it to your desktop.
Double click OTM.exe to start the tool. Vista or Windows 7 users right click and select Run as Administrator
-------------------------------------------------------------------
:Services
:Files
ipconfig /flushdns /c
C:\WINDOWS\atipehuk.dll
C:\WINDOWS\winshs.dll
C:\Program Files\AskBarDis
:Commands
[Purity]
[EmptyFlash]
[EmptyTemp]
[ResetHosts]
---------------------------------------------------------------------
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If the machine reboots, the Results log can be found here:
c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log
Where mmddyyyy_hhmmss is the date of the tool run.
Step 3
Alernative D/L mirror
Alternative D/L mirror
Double Click mbam-setup.exe to install the application.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Post logs from OTM and Malwarebytes in your reply, also give update on any remaining issues. Is there a specific reason why you still have IE6, why have you not updated to IE8
Kevin...