I have run multiple malware detection programs on my computer and each one detects threats. I have currently removed all malware detection programs from my computer except for Malwarebytes. The Google redirect virus does not seem to be having an effect on browsing at this time. However, threats continue to be found during Malwarebytes scans.
I have followed the directions at the Mlaware and Spyware Cleaning Guideto the letter. TDSS killer found two infections, one of which seems to have been eliminated and one that has not been. After that, I ran Malwarebytes, which picked up 4 Trojan.Agent files, which cannot be taken care of, even when the system is rebooted. I have tried deleting those 4 registry keys (which can be seen in the Malwarebytes log below) to no avail. I have tried to change the permissions on those registry keys so that they could be deleted, also to no avail.
Thank you for your time and effort on my behalf. I will be patiently waiting for your reply.
OTL LOG:
OTL logfile created on: 6/20/2011 9:58:15 AM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Mel\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.24 Gb Total Physical Memory | 0.73 Gb Available Physical Memory | 59.12% Memory free
1.46 Gb Paging File | 1.15 Gb Available in Paging File | 78.81% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.64 Gb Total Space | 48.40 Gb Free Space | 67.56% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Mel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/20 09:57:27 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mel\Desktop\OTL.exe
PRC - [2010/04/02 06:40:25 | 000,307,672 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/12/21 17:35:18 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/30 07:50:00 | 000,144,960 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2006/11/30 07:50:00 | 000,112,216 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2006/11/30 07:50:00 | 000,054,872 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
PRC - [2006/11/17 12:40:56 | 000,136,768 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2006/11/17 12:39:58 | 000,136,768 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2006/11/17 12:37:44 | 000,104,000 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2006/11/17 02:06:00 | 000,086,016 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2004/09/15 02:01:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2004/05/13 11:23:56 | 000,098,304 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
========== Modules (SafeList) ==========
MOD - [2011/06/20 09:57:27 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mel\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2004/05/13 11:23:50 | 000,066,048 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/04/27 12:40:26 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2006/11/30 07:50:00 | 000,144,960 | ---- | M] (McAfee, Inc.) [Auto | Paused] -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe -- (McShield)
SRV - [2006/11/30 07:50:00 | 000,054,872 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe -- (McTaskManager)
SRV - [2006/11/17 12:37:44 | 000,104,000 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2006/07/25 17:03:42 | 002,119,360 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate)
========== Driver Services (SafeList) ==========
DRV - [2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2008/04/03 04:03:08 | 001,333,152 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2007/12/11 10:12:15 | 000,019,456 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\gjrespjz.dat -- (jxuoomvo)
DRV - [2006/11/30 07:50:00 | 000,168,776 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2006/11/30 07:50:00 | 000,072,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2006/11/30 07:50:00 | 000,064,360 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2006/11/30 07:50:00 | 000,052,136 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2006/11/30 07:50:00 | 000,034,152 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2006/11/30 07:50:00 | 000,031,944 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - [2006/09/19 03:00:00 | 000,387,432 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2005/05/03 14:09:28 | 001,033,728 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.SYS -- (HSF_DPV)
DRV - [2005/05/03 14:08:50 | 000,208,384 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005/05/03 14:08:44 | 000,705,408 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004/11/01 20:52:46 | 000,272,568 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)
DRV - [2004/09/09 11:29:00 | 000,407,360 | ---- | M] (D-Link ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2004/06/30 10:39:36 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | On_Demand | Running] -- C:\Program Files\Dell\NicConfigSvc\Appdrv.sys -- (Appdrv)
DRV - [2004/06/25 18:15:54 | 000,315,392 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004/06/17 21:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004/02/13 17:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "https://huskymail.mtu.edu/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.071101000055
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/19 20:12:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/19 20:12:54 | 000,000,000 | ---D | M]
[2008/12/09 23:18:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mel\Application Data\Mozilla\Extensions
[2011/06/17 21:45:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mel\Application Data\Mozilla\Firefox\Profiles\5jos7isq.default\extensions
[2009/10/31 11:10:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mel\Application Data\Mozilla\Firefox\Profiles\5jos7isq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/10/15 19:37:51 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Mel\Application Data\Mozilla\Firefox\Profiles\5jos7isq.default\extensions\[email protected]
[2008/05/26 16:33:16 | 000,001,612 | ---- | M] () -- C:\Documents and Settings\Mel\Application Data\Mozilla\Firefox\Profiles\5jos7isq.default\searchplugins\blogmusik.xml
[2008/03/08 19:14:48 | 000,001,406 | ---- | M] () -- C:\Documents and Settings\Mel\Application Data\Mozilla\Firefox\Profiles\5jos7isq.default\searchplugins\siteadvisor.gif
[2008/03/08 19:14:48 | 000,000,276 | ---- | M] () -- C:\Documents and Settings\Mel\Application Data\Mozilla\Firefox\Profiles\5jos7isq.default\searchplugins\siteadvisor.src
[2008/03/06 20:38:11 | 000,002,386 | ---- | M] () -- C:\Documents and Settings\Mel\Application Data\Mozilla\Firefox\Profiles\5jos7isq.default\searchplugins\siteadvisor.xml
[2011/06/19 20:15:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2008/11/22 09:51:10 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2006/12/16 21:30:59 | 000,114,688 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2006/12/08 14:13:55 | 000,319,488 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
[2005/04/27 16:31:10 | 000,225,280 | ---- | M] (Asgard Software Inc.) -- C:\Program Files\Mozilla Firefox\plugins\NPUploader.dll
O1 HOSTS File: ([2011/06/19 22:56:33 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {D5440609-0F57-4548-B38A-EDB149428027} - File not found
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1212833595875 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} http://cdn2.zone.msn...gr.cab31267.cab (ZoneAxRcMgr Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...ro.cab34246.cab (ZoneIntro Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} http://www.piclens.c...ed/plinstll.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Firefox Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Firefox Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/20 09:57:27 | 000,579,072 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mel\Desktop\OTL.exe
[2011/06/20 09:50:44 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011/06/19 23:06:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mel\Desktop\tdsskiller
[2011/06/19 23:04:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mel\Desktop\GooredFix Backups
[2011/06/19 23:04:10 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\Mel\Desktop\GooredFix.exe
[2011/06/19 22:56:30 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/06/19 22:55:11 | 000,522,752 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mel\Desktop\OTM.exe
[2011/06/19 22:54:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mel\Desktop\erunt
[2011/06/19 20:19:50 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/06/19 16:45:02 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/06/19 16:38:42 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/06/19 16:38:42 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/06/19 16:38:42 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/06/19 16:38:41 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/06/19 16:38:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/06/19 16:38:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/06/19 15:09:22 | 000,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2011/06/19 15:09:22 | 000,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2011/06/19 15:09:22 | 000,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2011/06/19 15:09:22 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2011/06/19 15:09:22 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2011/06/19 15:09:22 | 000,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2011/06/19 15:09:22 | 000,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2011/06/19 15:09:22 | 000,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2011/06/19 15:09:22 | 000,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2011/06/18 17:35:24 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/18 17:35:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/18 17:34:55 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/06/18 17:34:54 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/18 17:32:37 | 009,435,312 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mel\Desktop\mbam-setup-1.51.0.1200.exe
[2011/06/18 14:10:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mel\Desktop\Acrobat 9.0
[2011/06/14 18:10:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/06/14 17:53:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/06/14 17:53:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/06/14 17:53:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/06/14 17:29:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/06/14 13:16:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mel\Local Settings\Application Data\{E9AFDEC4-74E1-496F-933A-178381E1C3D0}
[2011/06/10 11:45:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DivX
[2011/06/06 16:12:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2011/06/02 16:32:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2005/07/09 21:44:45 | 004,827,968 | ---- | C] (Mozilla) -- C:\Program Files\Firefox Setup 1.0.4.exe
========== Files - Modified Within 30 Days ==========
[2011/06/20 09:57:27 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mel\Desktop\OTL.exe
[2011/06/20 09:27:53 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/20 09:27:47 | 1333,198,848 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/20 02:04:21 | 000,446,386 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/06/20 02:04:21 | 000,073,426 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/06/19 23:06:16 | 001,309,375 | ---- | M] () -- C:\Documents and Settings\Mel\Desktop\tdsskiller.zip
[2011/06/19 23:04:10 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\Mel\Desktop\GooredFix.exe
[2011/06/19 22:56:33 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/06/19 22:55:14 | 000,522,752 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mel\Desktop\OTM.exe
[2011/06/19 22:54:05 | 000,513,320 | ---- | M] () -- C:\Documents and Settings\Mel\Desktop\erunt.zip
[2011/06/19 21:33:14 | 000,303,312 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/19 20:11:07 | 000,000,076 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
[2011/06/19 16:45:10 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/06/19 15:36:03 | 000,004,932 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2011/06/18 17:33:28 | 009,435,312 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mel\Desktop\mbam-setup-1.51.0.1200.exe
[2011/06/18 16:34:13 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/06/17 21:27:43 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/15 15:41:00 | 000,233,472 | RHS- | M] () -- C:\WINDOWS\System32\slbrccsps.dll
[2011/06/14 16:19:07 | 000,017,594 | -HS- | M] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
[2011/06/14 16:19:07 | 000,017,594 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
[2011/06/14 16:11:12 | 000,007,128 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\2755211163
[2011/06/14 16:10:47 | 000,002,964 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\3516354164
[2011/06/14 16:10:47 | 000,002,964 | -HS- | M] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\2755211163
[2011/06/14 14:04:10 | 000,000,004 | -H-- | M] () -- C:\Documents and Settings\Mel\Application Data\mlog
[2011/06/14 13:34:42 | 000,000,004 | -H-- | M] () -- C:\Documents and Settings\Mel\Application Data\inlog
[2011/06/14 13:29:51 | 000,000,004 | -H-- | M] () -- C:\Documents and Settings\Mel\Application Data\ylog
[2011/06/14 13:16:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Ppemubadisuvubov.bin
[2011/06/14 13:16:49 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Jqazahixowetohek.dat
[2011/06/13 21:58:18 | 000,085,804 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/06/13 16:13:23 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2011/06/19 23:05:41 | 001,309,375 | ---- | C] () -- C:\Documents and Settings\Mel\Desktop\tdsskiller.zip
[2011/06/19 22:54:04 | 000,513,320 | ---- | C] () -- C:\Documents and Settings\Mel\Desktop\erunt.zip
[2011/06/19 19:58:33 | 1333,198,848 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/19 16:45:10 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/06/19 16:45:06 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/06/19 16:38:42 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/06/19 16:38:42 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/06/19 16:38:42 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/06/19 16:38:42 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/06/19 16:38:42 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/06/19 15:10:01 | 000,004,932 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2011/06/19 15:09:22 | 000,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2011/06/19 15:09:22 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2011/06/15 15:41:00 | 000,233,472 | RHS- | C] () -- C:\WINDOWS\System32\slbrccsps.dll
[2011/06/14 16:10:25 | 000,002,964 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\3516354164
[2011/06/14 16:10:25 | 000,002,964 | -HS- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\2755211163
[2011/06/14 16:09:58 | 000,017,594 | -HS- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
[2011/06/14 16:09:58 | 000,007,128 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2755211163
[2011/06/14 15:58:42 | 000,017,594 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
[2011/06/14 15:58:42 | 000,009,902 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
[2011/06/14 13:18:40 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Mel\Application Data\inlog
[2011/06/14 13:17:11 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Mel\Application Data\mlog
[2011/06/14 13:16:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Ppemubadisuvubov.bin
[2011/06/14 13:16:49 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Jqazahixowetohek.dat
[2011/06/14 13:16:43 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Mel\Application Data\ylog
[2011/04/24 16:49:18 | 000,085,804 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/10/13 14:51:45 | 000,000,160 | ---- | C] () -- C:\WINDOWS\System32\ougt8.bin
[2010/07/07 17:52:43 | 000,001,130 | ---- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\FASTWiz.html
[2010/07/07 13:13:09 | 000,000,710 | ---- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\FASTApp.html
[2010/03/01 09:51:43 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/02/20 18:12:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcfriend.INI
[2008/11/22 09:46:45 | 002,869,760 | ---- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\cooliris-win-iemin-release-1.8.5.14750.msi
[2008/11/01 17:26:27 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/08/02 18:12:41 | 001,854,464 | ---- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\piclens-win-iemin-release-1.7.1.3938.msi
[2008/06/19 12:02:33 | 001,699,328 | ---- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\piclens-win-iefull-release-1.7.0.3458.msi
[2008/06/10 05:37:08 | 001,579,008 | ---- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\piclens-win-iemin-release-1.6.4.3021.msi
[2008/06/07 12:55:54 | 000,013,824 | ---- | C] () -- C:\WINDOWS\System32\wnaspi32.dll
[2008/03/22 22:12:46 | 000,000,038 | -H-- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\ucache.dat
[2007/11/25 19:40:19 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2007/11/08 12:53:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\JDSecure31.INI
[2007/10/16 08:27:17 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\gjrespjz.dat
[2007/10/16 08:27:04 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\drivers\chxoeieh.dat
[2007/08/28 10:46:54 | 000,078,848 | ---- | C] () -- C:\Documents and Settings\Mel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/23 06:41:15 | 000,005,033 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2006/05/24 07:30:30 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/05/21 12:36:14 | 000,000,076 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2005/07/09 21:46:12 | 000,099,965 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2005/07/09 21:45:51 | 000,005,643 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/07/09 12:46:34 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/07/09 12:32:49 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/01/28 19:11:51 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/01/28 19:07:32 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2005/01/28 19:03:34 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/01/28 18:57:50 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/01/28 18:56:37 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
[2005/01/28 18:23:40 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2005/01/28 18:23:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2004/12/15 18:24:59 | 000,000,390 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/09/15 22:49:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 14:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 000,303,312 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,446,386 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,073,426 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
========== LOP Check ==========
[2008/06/07 13:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2007/09/25 06:34:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
[2006/06/20 16:30:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2008/04/10 15:37:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Retrospect
[2009/10/11 19:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TERMINAL Studio
[2011/04/24 16:44:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2005/07/09 22:18:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mel\Application Data\Aim
[2005/10/12 07:22:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mel\Application Data\Leadertech
[2006/12/08 14:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mel\Application Data\Snapfish
[2008/06/08 06:10:06 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\SyncToy.job
========== Purity Check ==========
< End of report >
Malwarebytes log:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6897
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
6/20/2011 9:26:26 AM
mbam-log-2011-06-20 (09-26-26).txt
Scan type: Full scan (C:\|)
Objects scanned: 251354
Time elapsed: 56 minute(s), 4 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Value: bf -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Value: bk -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Value: iu -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Value: mu -> Delete on reboot.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)