Hi, I have a problem on an Acer Aspire one notepad running Windows XP Version 5.1 SP3.
Please excuse my lack of knowledge regarding this, but I have tried and tested almost every answer I have found on forums to no avail. I am using IE6, and whenever I try to navigate to
www.microsoft.com it redirects to Yahoo search, and then clicking on the link for Microsoft brings up the page cannot be displayed blurb.
I have checked the hosts file, nothing seems to be out of the ordinary. The website can be accessed from other laptops using the same router. I have disabled firewalls, put it in trusted sites, been through almost everything to no avail. I have run Malwarebytes Anti-malware abd this hasn't fixed it. HijackThis log shows as follows:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:57 PM, on 9/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\Program Files\Webroot\WebrootSecur
ity\WRCons
umerServic
e.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iv
iRegMgr.ex
e
C:\Program Files\McAfee\SiteAdvisor\M
cSACore.ex
e
C:\PROGRA~1\McAfee\MSC\mcm
scsvc.exe
c:\PROGRA~1\COMMON~1\mcafe
e\mna\mcna
svc.exe
c:\PROGRA~1\COMMON~1\mcafe
e\mcproxy\
mcproxy.ex
e
C:\PROGRA~1\McAfee\VIRUSS~
1\mcshield
.exe
C:\Program Files\McAfee\MPF\MPFSrv.ex
e
C:\Program Files\McAfee\MSK\MskSrver.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Webroot\WebrootSecur
ity\SpySwe
eper.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
C:\WINDOWS\system32\wscntf
y.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpe
rs.exe
C:\PROGRA~1\LAUNCH~1\QtZgA
cer.EXE
C:\WINDOWS\system32\igfxtr
ay.exe
C:\WINDOWS\system32\hkcmd.
exe
C:\Acer\Empowering Technology\eRecovery\eRAge
nt.exe
C:\WINDOWS\system32\igfxsr
vc.exe
C:\Program Files\Webroot\WebrootSecur
ity\SpySwe
eperUI.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
C:\WINDOWS\system32\igfxex
t.exe
C:\DOCUME~1\MEGS\LOCALS~1\
Temp\RtkBt
Mnt.exe
C:\PROGRA~1\McAfee\VIRUSS~
1\mcsysmon
.exe
c:\PROGRA~1\mcafee\msc\mcu
imgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://ca.rd.yahoo.com/customize/ycomp/defaults/sp/*http://ca.yahoo.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://en.ca.acer.yahoo.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://en.ca.acer.yahoo.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://en.ca.acer.yahoo.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.comR1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://en.ca.acer.yahoo.com/R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F
45BD3D40CF
4} - c:\PROGRA~1\mcafee\msk\mca
pbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6
309F01C523
1} - C:\Program Files\McAfee\VirusScan\scr
iptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
A8D5E23E04
5} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
164760863C
6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2
CD0E90A88F
F} - c:\PROGRA~1\mcafee\SITEAD~
1\mcieplg.
dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-5
16ABECAE06
4} - c:\PROGRA~1\mcafee\SITEAD~
1\mcieplg.
dll
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe"
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\T
INTLGNT\TI
NTSETP.EXE
" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\T
INTLGNT\TI
NTSETP.EXE
" /IMEName
O4 - HKLM\..\Run: [Persistence] "C:\WINDOWS\system32\igfxp
ers.exe"
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\P
INTLGNT\Im
ScInst.exe
" /SYNC
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mca
gent.exe" /runkey
O4 - HKLM\..\Run: [M3000Mnt] "Rundll32.exe" M3000Rmv.dll ,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [LManager] "C:\PROGRA~1\LAUNCH~1\QtZg
Acer.EXE"
O4 - HKLM\..\Run: [LaunchApp] "Alaunch"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
JPMIG.EXE"
/Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxt
ray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd
.exe"
O4 - HKLM\..\Run: [eRecoveryService] "C:\Acer\Empowering Technology\eRecovery\eRAge
nt.exe"
O4 - HKLM\..\Run: [AzMixerSel] "C:\Program Files\Realtek\Audio\Instal
lShield\Az
MixerSel.e
xe"
O4 - HKLM\..\Run: [Alcmtr] "ALCMTR.EXE"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecur
ity\SpySwe
eperUI.exe
" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmo
n.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
" /background
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office12\
EXCEL.EXE/
3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\Offic
e12\REFIEB
AR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://download.windowsupdate.comO16 - DPF: {0CCA191D-13A6-4E29-B746-3
14DEE697D8
3} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cabO18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-0
67394E91CC
5} - c:\PROGRA~1\mcafee\SITEAD~
1\mcieplg.
dll
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iv
iRegMgr.ex
e
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\M
cSACore.ex
e
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcm
scsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe
e\mna\mcna
svc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcods.ex
e
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe
e\mcproxy\
mcproxy.ex
e
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcshield
.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcsysmon
.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.ex
e
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.
exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService)
- Webroot Software, Inc. (
www.webroot.com) - C:\Program Files\Webroot\WebrootSecur
ity\SpySwe
eper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecur
ity\WRCons
umerServic
e.exe
--
End of file - 8173 bytes
ComboFix log as follows:
ComboFix 09-09-09.07 - MEGS 09/10/2009 23:17.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.
1012.582 [GMT -7:00]
Running from: c:\documents and settings\MEGS\Desktop\Comb
oFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-D
D43BA9FAD8
3}
AV: Webroot Spy Sweeper *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-B
DBC267AD59
7}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-8
13CA00DA3E
8}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((
((((((((((
((( Other Deletions ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
.
c:\progra~1\Webroot\WEBROO
~1\Backup\
ntSVc.ocx
.
((((((((((((((((((((((((( Files Created from 2009-08-11 to 2009-09-11 ))))))))))))))))))))))))))
)))))
.
2009-09-11 06:00 . 2009-09-11 06:00 -------- d-----w- c:\program files\Trend Micro
2009-09-11 05:08 . 2009-09-11 05:08 -------- d-----w- c:\documents and settings\MEGS\Application Data\Malwarebytes
2009-09-11 05:08 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\driver
s\mbamswis
sarmy.sys
2009-09-11 05:08 . 2009-09-11 05:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-11 05:08 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\driver
s\mbam.sys
2009-09-11 05:08 . 2009-09-11 05:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-02 21:24 . 2009-09-02 21:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-09-01 01:56 . 2009-09-01 01:56 127 ----a-w- c:\documents and settings\MEGS\Local Settings\Application Data\fusioncache.dat
2009-09-01 01:56 . 2009-09-01 01:56 -------- d-----w- c:\program files\MSSOAP
2009-09-01 01:55 . 2009-09-01 01:55 -------- d-----w- c:\documents and settings\MEGS\Application Data\Webroot
2009-09-01 01:55 . 2009-05-13 22:39 1563008 ----a-w- c:\windows\WRSetup.dll
2009-09-01 01:55 . 2009-09-01 02:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Webroot
2009-09-01 01:55 . 2009-09-01 01:55 -------- d-----w- c:\program files\Webroot
2009-09-01 01:55 . 2009-09-01 01:55 164 ----a-w- c:\windows\install.dat
.
((((((((((((((((((((((((((
((((((((((
(((( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
))))))
.
2009-09-02 22:09 . 2008-07-08 18:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-21 14:06 . 2008-04-15 03:00 165141 --sha-r- c:\windows\system32\rxqfqt
.dll
.
((((((((((((((((((((((((((
((((((((((
( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
E\Microsof
t\Windows\
CurrentVer
sion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe
" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynT
PEnh.exe" [2008-04-25 1044480]
"PHIME2002ASync"="c:\windo
ws\system3
2\IME\TINT
LGNT\TINTS
ETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\s
ystem32\IM
E\TINTLGNT
\TINTSETP.
EXE" [2008-04-15 455168]
"Persistence"="c:\windows\
system32\i
gfxpers.ex
e" [2008-02-28 137752]
"MSPY2002"="c:\windows\sys
tem32\IME\
PINTLGNT\I
mScInst.ex
e" [2008-04-15 59392]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mca
gent.exe" [2007-08-04 582992]
"LManager"="c:\progra~1\LA
UNCH~1\QtZ
gAcer.EXE"
[2008-05-14 821768]
"IMJPMIG8.1"="c:\windows\I
ME\imjp8_1
\IMJPMIG.E
XE" [2008-04-15 208952]
"IgfxTray"="c:\windows\sys
tem32\igfx
tray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\
system32\h
kcmd.exe" [2008-02-28 166424]
"eRecoveryService"="c:\ace
r\Empoweri
ng Technology\eRecovery\eRAge
nt.exe" [2008-05-22 425984]
"AzMixerSel"="c:\program files\Realtek\Audio\Instal
lShield\Az
MixerSel.e
xe" [2006-07-17 53248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"SpySweeper"="c:\program files\Webroot\WebrootSecur
ity\SpySwe
eperUI.exe
" [2009-05-13 6345840]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe [2008-6-4 114688]
[HKEY_LOCAL_MACHINE\SYSTEM
\CurrentCo
ntrolSet\C
ontrol\Saf
eBoot\Mini
mal\mcmscs
vc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM
\CurrentCo
ntrolSet\C
ontrol\Saf
eBoot\Mini
mal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM
\CurrentCo
ntrolSet\C
ontrol\Saf
eBoot\Mini
mal\Webroo
tSpySweepe
rService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
\CurrentCo
ntrolSet\C
ontrol\Saf
eBoot\Mini
mal\WRCons
umerServic
e]
@="Service"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\securit
y center\Monitoring\McAfeeAn
tiVirus]
"DisableMonitoring"=dword:
00000001
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\securit
y center\Monitoring\McAfeeFi
rewall]
"DisableMonitoring"=dword:
00000001
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Auth
orizedAppl
ications\L
ist]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
=
"%windir%\\system32\\sessm
gr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.
EXE"=
"c:\\Program Files\\Messenger\\msmsgs.e
xe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASv
c.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e
xe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.
exe"=
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Glob
allyOpenPo
rts\List]
"6553:TCP"= 6553:TCP:hyyni
R0 ssfs0bbc;ssfs0bbc;c:\windo
ws\system3
2\drivers\
ssfs0bbc.s
ys [4/21/2009 6:27 PM 29808]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\M
cSACore.ex
e [10/4/2008 6:36 PM 210216]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecur
ity\WRCons
umerServic
e.exe [8/31/2009 6:57 PM 1205760]
R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32
\drivers\M
3000KNT.sy
s [5/5/2008 12:01 AM 254976]
S2 ngytoshyi;Security Microsoft;c:\windows\syste
m32\svchos
t.exe -k netsvcs [4/14/2008 8:00 PM 14336]
S3 JMCR;JMCR;c:\windows\syste
m32\driver
s\jmcr.sys
[5/21/2008 1:11 AM 96856]
HKEY_LOCAL_MACHINE\SOFTWAR
E\Microsof
t\Windows NT\CurrentVersion\Svchost - NetSvcs
ngytoshyi
.
Contents of the 'Scheduled Tasks' folder
2008-10-16 c:\windows\Tasks\McDefragT
ask.job
- c:\progra~1\mcafee\mqc\QcC
onsol.exe [2007-07-25 20:32]
2009-01-02 c:\windows\Tasks\McQcTask.
job
- c:\progra~1\mcafee\mqc\QcC
onsol.exe [2007-07-25 20:32]
2009-09-01 c:\windows\Tasks\wrSpySwee
per_LBB999
2DEFEF84B6
8A45E06044
96F4F49.jo
b
- c:\program files\Webroot\WebrootSecur
ity\SpySwe
eperUI.exe
[2009-09-01 22:39]
2009-09-01 c:\windows\Tasks\wrSpySwee
per_LBB999
2DEFEF84B6
8A45E06044
96F4F49.jo
b
- c:\program files\Webroot\WebrootSecur
ity\SpySwe
eperUI.exe
[2009-09-01 22:39]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://en.ca.acer.yahoo.co
m/
mStart Page = hxxp://en.ca.acer.yahoo.co
m
uInternet Connection Wizard,ShellNext = hxxp://en.ca.acer.yahoo.co
m/
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/cus
tomize/yco
mp/default
s/su/*
http://ca.yahoo.comIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Offic
e12\EXCEL.
EXE/3000
Trusted Zone: microsoft.com\*.update
Trusted Zone: windowsupdate.com\download
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-M3000Mnt - M3000Rmv.dll
**************************
**********
**********
**********
**********
********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-10 23:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
**********
**********
**********
**********
********
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ngytos
hyi]
"ServiceDll"="c:\windows\s
ystem32\rx
qfqt.dll"
.
Completion time: 2009-09-11 23:30
ComboFix-quarantined-files
.txt 2009-09-11 06:30
Pre-Run: 101,185,527,808 bytes free
Post-Run: 101,343,952,896 bytes free
WindowsXP-KB310994-SP2-Hom
e-BootDisk
-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdi
sk(0)parti
tion(2)\WI
NDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="M
icrosoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)par
tition(2)\
WINDOWS="M
icrosoft Windows XP Home Edition" /noexecute=optin /fastdetect
141 --- E O F --- 2009-09-02 21:16
Please help if possible. I am not the most technological person so if any more information is needed please let me know, and if possible how to find it and I will be glad to post. Thanks in advance.