Thanks again Gringo
Heres the combofix log. Haven't tested for the redirect yet. Will post some resulys soon.
ComboFix 13-06-28.01 - Kempr 06/28/2013 16:54:00.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1338 [GMT 10:00]
Running from: c:\documents and settings\Kempr.KEMP\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
c:\documents and settings\All Users.WINDOWS\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\All Users.WINDOWS\Application Data\vlc-1.0.1-win32.exe
c:\documents and settings\All Users.WINDOWS\VCREDI~3.EXE
c:\documents and settings\Emily\WINDOWS
c:\documents and settings\Kempr.KEMP\WINDOWS
c:\documents and settings\kempr\Stripper.exe
c:\windows\_ds5CE.tmp
c:\windows\dasetup.log
c:\windows\Installer\{44b1dc5e-407a-2745-29af-253d85709c1d}\@
c:\windows\Installer\{44b1dc5e-407a-2745-29af-253d85709c1d}\U\00000001.@
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\nsa49.tmp
c:\windows\system32\nsf48.tmp
c:\windows\wininit.ini
G:\setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-05-28 to 2013-06-28 )))))))))))))))))))))))))))))))
.
.
2013-06-27 01:03 . 2013-06-27 01:03 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2013-06-27 01:02 . 2013-06-27 01:03 -------- d-----w- c:\windows\system32\drivers\N360
2013-06-27 01:02 . 2013-06-27 01:02 -------- d-----w- c:\program files\Norton 360
2013-06-27 00:55 . 2013-06-27 01:04 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Norton
2013-06-27 00:51 . 2013-06-27 06:00 -------- d-----w- c:\program files\NortonInstaller
2013-06-27 00:26 . 2013-06-27 00:26 -------- d-----w- c:\windows\ERUNT
2013-06-27 00:26 . 2013-06-27 00:26 -------- d-----w- C:\JRT
2013-06-21 12:42 . 2013-06-21 12:42 -------- d-----w- C:\TDSSKiller_Quarantine
2013-06-19 00:53 . 2013-06-19 00:53 -------- d-sh--w- c:\documents and settings\Kempr.KEMP\IECompatCache
2013-06-12 03:55 . 2013-06-12 03:55 9089416 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-06-07 01:33 . 2013-06-07 01:33 294912 --sha-r- c:\windows\system32\jgsd4008.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 03:55 . 2012-04-01 07:18 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 03:55 . 2012-01-15 07:12 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-30 17:59 . 2013-04-30 17:59 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2013-04-30 17:59 . 2013-04-30 17:59 69632 ----a-w- c:\windows\system32\QuickTime.qts
2013-04-04 04:50 . 2009-06-01 06:01 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2008-12-09 08:48 . 2008-12-09 08:47 322720 ----a-w- c:\program files\ripsetup.exe
2007-12-15 12:42 . 2007-12-15 12:41 2840072 ----a-w- c:\program files\isobuster_all_lang.exe
2007-12-15 12:38 . 2007-12-15 12:38 1298851 ----a-w- c:\program files\setup_magicdisc.exe
2007-12-11 03:53 . 2007-12-11 03:53 3010710 ----a-w- c:\program files\Can.exe
2007-12-07 08:02 . 2007-12-07 08:02 2392722 ----a-w- c:\program files\ac3filter_1_46.exe
2007-12-07 07:54 . 2007-12-07 07:54 570702 ----a-w- c:\program files\AVIcodec_1.2_b113.exe
2007-12-02 03:41 . 2007-12-02 03:41 3380048 ----a-w- c:\program files\LimeWireWin.exe
2007-12-01 05:12 . 2007-12-01 05:11 70095 ----a-w- c:\program files\MSN_Messenger7_Current_Playing_Song.exe
2007-11-26 05:13 . 2007-11-26 05:13 899414 ----a-w- c:\program files\SetupDVDDecrypter_3.5.4.0.exe
2007-11-26 04:51 . 2007-11-26 04:50 15196432 ----a-w- c:\program files\sdsetup.exe
2007-11-26 01:11 . 2007-11-26 01:11 9409224 ----a-w- c:\program files\Install_MSN_Messenger.exe
2007-11-24 09:54 . 2007-11-24 09:54 3003113 ----a-w- c:\program files\Setup_MagicISO.exe
2007-11-24 09:52 . 2007-11-24 09:52 1206366 ----a-w- c:\program files\wrar371.exe
2007-11-24 09:47 . 2007-11-24 09:47 2400784 ----a-w- c:\program files\WLinstaller.exe
2004-03-11 02:27 . 2007-11-26 04:49 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2012-12-30 22:30 . 2012-02-04 09:53 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\documents and settings\Kempr.KEMP\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\documents and settings\Kempr.KEMP\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\documents and settings\Kempr.KEMP\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\documents and settings\Kempr.KEMP\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2013-04-03 801112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2013-02-26 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-10 136600]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-06 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 55824]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-08-25 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-08-25 221184]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2004-09-07 1400944]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-17 1848648]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-07 1753192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-07-09 110696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2012-02-23 59240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2013-04-30 421888]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-04-25 35328]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-05-15 152392]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
.
c:\documents and settings\Emily\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2007-12-15 557568]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2009-5-30 57344]
PHOTOfunSTUDIO 8.0 SE.lnk - c:\program files\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe -e "c:\program files\Panasonic\PHOTOfunSTUDIO 8.0 SE\PHOTOfunSTUDIO.exe" [2013-4-24 188600]
SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetpointII.exe [2007-8-30 319488]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/15/2007 10:52 PM 691696]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\1404000.028\symds.sys [6/27/2013 11:03 AM 367704]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\1404000.028\symefa.sys [6/27/2013 11:03 AM 934488]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130620.001\BHDrvx86.sys [6/27/2013 12:20 PM 1002072]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\1404000.028\ccsetx86.sys [6/27/2013 11:03 AM 134744]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\1404000.028\ironx86.sys [6/27/2013 11:03 AM 175264]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\20.4.0.40\ccsvchst.exe [6/27/2013 11:03 AM 144368]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/27/2013 11:26 AM 106656]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130627.001\IDSXpx86.sys [6/28/2013 11:00 AM 373728]
S2 Seagate Sync Service;Seagate Sync Service;"c:\program files\Seagate\Sync\SeaSyncServices.exe" --> c:\program files\Seagate\Sync\SeaSyncServices.exe [?]
S2 ZeppelinService;plasservice;"c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe" --> c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe [?]
S3 imhidusb;Immersion's HID USB Driver;c:\windows\system32\drivers\imhidusb.sys [11/26/2007 7:27 PM 30920]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [6/29/2011 3:18 PM 18432]
S3 phil2vid;Philips USB VGA Camera;c:\windows\system32\drivers\philcam2.sys [11/25/2007 8:38 PM 173696]
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 03:55]
.
2013-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 07:57]
.
2013-06-28 c:\windows\Tasks\Fnucekwgz.job
- c:\windows\system32\jgsd4008.dll [2013-06-07 01:33]
.
2013-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-02-26 01:45]
.
2013-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-02-26 01:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
mStart Page = about:blank
Trusted Zone: asx.com.au\myasx
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Kempr.KEMP\Application Data\Mozilla\Firefox\Profiles\gdqleh0h.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-LimeWire - f:\limewire\uninstall.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-06-28 17:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-06-28 17:12:56
ComboFix-quarantined-files.txt 2013-06-28 07:12
ComboFix2.txt 2009-07-25 09:33
ComboFix3.txt 2009-06-18 07:51
.
Pre-Run: 74,641,580,032 bytes free
Post-Run: 76,429,586,432 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 7767E8A6B7E242F8402CEAB7980D3BB8
8F558EB6672622401DA993E1E865C861