Yes, I did try that and it was the same.
Main Topics
Browse All TopicsMy computer was recently infected with a browser helper object (or similar) and I cannot seem to remove it. I have done a lot of research and tried everything I have read about. When I do a Google search and click on the links I get redirected to other sites. My system info: Win XP Professional Service Pack 3, Avast Professional Anti-Virus, Ad-Aware (free version). Here is what I have run so far to try and detect and remove it: Avast, AVG, Kapersky Online scan, Combofix, Malwarebytes, Super Anti Spyware, Ad-Aware, Spybot Search & Destroy. I normally do not run all of these applications. Just trying to get it clean.
Please let me know if you need additional info.
Here is my HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:22, on 10/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\Ati2ev
C:\Program Files\AVG\AVG9\avgchsvx.ex
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
C:\Program Files\Alwil Software\Avast4\ashServ.ex
C:\Program Files\AVG\AVG9\avgcsrvx.ex
C:\WINDOWS\system32\spools
C:\Program Files\AVG\AVG9\avgwdsvc.ex
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.ex
C:\WINDOWS\system32\CTsvcC
C:\Program Files\Java\jre6\bin\jqs.ex
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\UPS\WSTD\MSSQL$UPSWSDBS
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm
C:\Program Files\Common Files\Intuit\QuickBooks\QB
C:\WINDOWS\system32\svchos
C:\PROGRA~1\ALWILS~1\Avast
C:\UPS\WSTD\UPSNA1Msgr.exe
C:\WINDOWS\System32\svchos
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Java\jre6\bin\jusche
C:\Program Files\AVG\AVG9\avgcsrvx.ex
C:\PROGRA~1\AVG\AVG9\avgtr
C:\Program Files\Common Files\InstallShield\Update
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Google\GoogleToolbar
C:\WINDOWS\system32\ctfmon
C:\Program Files\Common Files\Intuit\QuickBooks\QB
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\dllhos
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EX
C:\Program Files\AVG\AVG9\avgcsrvx.ex
C:\Program Files\Lavasoft\Ad-Aware\AA
C:\Program Files\Lavasoft\Ad-Aware\AA
C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe
C:\WINDOWS\System32\vssvc.
C:\WINDOWS\system32\dllhos
C:\PROGRA~1\Intuit\QUICKB~
C:\Program Files\Common Files\Intuit\QuickBooks\ax
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\Hijack-This\HijackTh
C:\Program Files\Common Files\InstallShield\Update
C:\WINDOWS\system32\rundll
C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
C:\Program Files\Alwil Software\Avast4\ashWebSv.e
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-7
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-E
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\UPSNA1Msgr.exe
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtr
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbar
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: {5ED80217-570B-4DA9-BF44-B
O16 - DPF: {CAFEEFAC-0016-0000-0005-A
O16 - DPF: {CAFEEFAC-0016-0000-0007-A
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O17 - HKLM\System\CCS\Services\T
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-0
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-8
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-F
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-5
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrss
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.ex
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.ex
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.ex
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcC
O23 - Service: Google Update Service (gupdate1c9c426ed159bec) (gupdate1c9c426ed159bec) - Google Inc. - C:\Program Files\Google\Update\Google
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.ex
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AA
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QB
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FC
O23 - Service: QuickBooksDB18 - Unknown owner - C:\PROGRA~1\Intuit\QUICKB~
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 12729 bytes
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Try scanning that system with this live cd:(hopefully it detects and removes the "dns changer")
Kaspersky live cd http://devbuilds.kaspersky
--It is in iso/image format so you will have to burn it to a cd.
--Once the cd is created, boot the infected machine to that cd and scan your system
NB-Update the virus database in live cd before scanning.
Also, do you have your installation media?
If so you may have to do a repair installation afterwards, depending on what infected files are removed:
http://michaelstevenstech.
I removed the following, but it is still doing it. I removed them, rebooted, ran CCleaner and it is still doing it.
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-5
Optoma - I am burning the ISO and scanning now
OK, the Kapersky boot scan found nothing. Not really sure what to do next. I am posting an updated HijackThis log. I have removed some apps to 'unclutter' it. If there are any other log files or scans I can do just let me know.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:01:51, on 10/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\Ati2ev
C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
C:\Program Files\Lavasoft\Ad-Aware\AA
C:\Program Files\Alwil Software\Avast4\ashServ.ex
C:\WINDOWS\system32\spools
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.ex
C:\WINDOWS\system32\CTsvcC
C:\Program Files\Java\jre6\bin\jqs.ex
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\UPS\WSTD\MSSQL$UPSWSDBS
C:\WINDOWS\system32\HPZipm
C:\Program Files\Common Files\Intuit\QuickBooks\QB
C:\WINDOWS\system32\svchos
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
C:\Program Files\Alwil Software\Avast4\ashWebSv.e
C:\Program Files\Lavasoft\Ad-Aware\AA
C:\PROGRA~1\ALWILS~1\Avast
C:\UPS\WSTD\UPSNA1Msgr.exe
C:\WINDOWS\System32\svchos
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Java\jre6\bin\jusche
C:\Program Files\Common Files\InstallShield\Update
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbar
C:\WINDOWS\system32\ctfmon
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QB
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\System32\vssvc.
C:\WINDOWS\system32\dllhos
C:\WINDOWS\system32\dllhos
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EX
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\Hijack-This\HijackTh
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-7
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-E
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\UPSNA1Msgr.exe
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbar
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: {5ED80217-570B-4DA9-BF44-B
O16 - DPF: {CAFEEFAC-0016-0000-0005-A
O16 - DPF: {CAFEEFAC-0016-0000-0007-A
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O17 - HKLM\System\CCS\Services\T
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-0
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-8
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.ex
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.ex
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcC
O23 - Service: Google Update Service (gupdate1c9c426ed159bec) (gupdate1c9c426ed159bec) - Google Inc. - C:\Program Files\Google\Update\Google
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.ex
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AA
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QB
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FC
O23 - Service: QuickBooksDB18 - Unknown owner - C:\PROGRA~1\Intuit\QUICKB~
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 10927 bytes
Ok
Could you run autoruns (dont make any changes within autoruns)
Autoruns http://technet.microsoft.c
Within Autoruns,select the file tab and select save(Ctrl+S)
Upload that file(autoruns.arn) to http://www.ee-stuff.com/Ex
If we cant see anything in autoruns, we acn try and get other experts in to review:)
Can you please attach the Combofix log? located at C:\Combofix.txt
Also please run Gmer and show us the log.
Download the GMER Rootkit Scanner. Unzip it to your Desktop.
http://www.gmer.ne
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Click NO
In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity.
Click OK.
GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
Save it where you can easily find it, such as your desktop.
Here is the ComboFix log. I will run the GMER Rootkit Scanner and post next.
ComboFix 09-10-25.02 - Stephen 10/26/2009 8:00.3.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.
Running from: c:\documents and settings\Stephen\Desktop\C
AV: avast! antivirus 4.8.1351 [VPS 091025-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1
* Created a new restore point
.
((((((((((((((((((((((((((
.
Infected copy of c:\windows\system32\DRIVER
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-09-26 to 2009-10-26 ))))))))))))))))))))))))))
.
2009-10-26 11:57 . 2008-01-31 21:23 308248 ----a-w- c:\windows\system32\driver
2009-10-22 20:26 . 2009-10-22 20:26 -------- d-----w- c:\program files\AVG
2009-10-22 15:26 . 2009-10-22 15:26 -------- d-----w- c:\windows\Performance
2009-10-22 15:26 . 2009-10-22 15:26 -------- d-----w- c:\documents and settings\Stephen\Local Settings\Application Data\Microsoft Corporation
2009-10-21 19:59 . 2009-10-21 19:58 411368 ----a-w- c:\windows\system32\deploy
2009-10-21 17:23 . 2009-10-21 17:41 -------- d-----w- c:\documents and settings\Stephen\.housecal
2009-10-21 13:37 . 2009-10-21 13:42 -------- d-----w- C:\ComboFix
2009-10-20 13:25 . 2009-10-20 13:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-20 13:25 . 2009-10-21 20:08 -------- d-----w- c:\documents and settings\Stephen\Applicati
2009-10-19 16:03 . 2009-10-20 15:32 -------- d-----w- c:\program files\BHODemon 2
2009-10-19 15:55 . 2009-10-23 14:07 -------- d-----w- c:\program files\Trend Micro
2009-10-19 15:06 . 2009-10-19 15:06 -------- d-----w- c:\program files\Safer Networking
2009-10-19 14:58 . 2009-10-23 16:07 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-19 14:58 . 2009-10-23 16:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-19 13:57 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\driver
2009-10-19 13:57 . 2009-10-19 13:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-19 13:57 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\driver
2009-10-19 13:18 . 2009-09-03 09:17 15688 ----a-w- c:\windows\system32\lsdele
2009-10-19 12:36 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\driver
2009-10-19 12:34 . 2009-10-19 12:34 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-8
2009-10-19 12:34 . 2009-10-19 12:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-19 12:34 . 2009-10-19 12:34 -------- d-----w- c:\program files\Lavasoft
2009-10-19 12:27 . 2009-10-19 12:27 -------- d-sh--w- c:\windows\system32\config
2009-10-19 12:26 . 2009-10-19 12:26 -------- d-----w- c:\program files\CCleaner
2009-10-19 11:55 . 2009-10-19 11:55 -------- d-sh--w- c:\documents and settings\LocalService\IETl
2009-10-15 14:21 . 2009-10-15 14:22 -------- d-----w- c:\program files\Microsoft IntelliPoint
2009-10-09 12:55 . 2009-10-09 12:55 -------- d-----w- c:\documents and settings\Stephen\Applicati
2009-10-05 18:41 . 2009-10-05 18:41 -------- d-----w- c:\program files\Microsoft
.
((((((((((((((((((((((((((
.
2009-10-26 11:48 . 2008-10-07 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-10-23 16:05 . 2008-09-19 15:16 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-10-23 16:00 . 2009-07-14 17:59 -------- d-----w- c:\documents and settings\Stephen\Applicati
2009-10-22 13:31 . 2008-09-19 19:48 -------- d-----w- c:\program files\Esi-Tools
2009-10-21 19:58 . 2008-09-13 04:07 -------- d-----w- c:\program files\Java
2009-10-21 19:55 . 2009-03-02 17:31 -------- d-----w- c:\documents and settings\Stephen\Applicati
2009-10-21 18:30 . 2008-09-13 04:12 -------- d-----w- c:\program files\Google
2009-10-21 18:17 . 2009-01-22 21:43 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-19 15:33 . 2009-04-16 16:33 -------- d-----w- c:\documents and settings\Stephen\Applicati
2009-10-19 11:59 . 2009-10-19 11:59 361600 ----a-w- c:\windows\system32\driver
2009-10-15 15:38 . 2008-09-13 04:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-15 14:39 . 2008-09-13 04:16 75848 ----a-w- c:\documents and settings\Administrator\Loc
2009-10-06 21:03 . 2008-09-13 04:11 -------- d-----w- c:\program files\Microsoft Works
2009-10-05 18:43 . 2008-09-18 13:30 -------- d-----w- c:\program files\Windows Live
2009-09-18 15:38 . 2008-09-18 12:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
2009-09-18 15:20 . 2009-09-18 15:20 -------- d-----w- c:\documents and settings\Stephen\Applicati
2009-09-11 14:18 . 2008-04-25 16:16 136192 ----a-w- c:\windows\system32\msv1_0
2009-09-11 11:56 . 2009-01-09 19:00 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-04 21:03 . 2008-04-25 16:16 58880 ----a-w- c:\windows\system32\msasn1
2009-08-29 08:08 . 2008-04-25 16:16 916480 ------w- c:\windows\system32\winine
2009-08-26 08:00 . 2008-04-25 16:16 247326 ----a-w- c:\windows\system32\strmdl
2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.D
2009-08-17 16:10 . 2008-09-17 21:15 1279456 ----a-w- c:\windows\system32\aswBoo
2009-08-17 16:06 . 2008-09-17 21:15 93392 ----a-w- c:\windows\system32\driver
2009-08-17 16:06 . 2008-09-17 21:15 94160 ----a-w- c:\windows\system32\driver
2009-08-17 16:05 . 2008-09-17 21:15 114768 ----a-w- c:\windows\system32\driver
2009-08-17 16:05 . 2008-09-17 21:15 20560 ----a-w- c:\windows\system32\driver
2009-08-17 16:04 . 2008-09-17 21:15 51376 ----a-w- c:\windows\system32\driver
2009-08-17 16:04 . 2008-09-17 21:15 23152 ----a-w- c:\windows\system32\driver
2009-08-17 16:03 . 2008-09-17 21:15 26944 ----a-w- c:\windows\system32\driver
2009-08-17 16:02 . 2008-09-17 21:15 97480 ----a-w- c:\windows\system32\AvastS
2009-08-05 09:01 . 2008-04-25 16:16 204800 ----a-w- c:\windows\system32\mswebd
2009-08-04 15:13 . 2008-04-25 16:16 2145280 ------w- c:\windows\system32\ntoskr
2009-08-04 14:20 . 2008-04-14 00:01 2023936 ------w- c:\windows\system32\ntkrnl
2009-08-03 19:07 . 2009-08-03 19:07 403816 ----a-w- c:\windows\system32\OGAChe
2009-08-03 19:07 . 2009-08-03 19:07 322928 ----a-w- c:\windows\system32\OGAAdd
2009-08-03 19:07 . 2009-08-03 19:07 230768 ----a-w- c:\windows\system32\OGAEXE
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\softwa
@="{95A27763-F62A-4114-907
[HKEY_CLASSES_ROOT\CLSID\{
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\softwa
@="{E300CD91-100F-4E67-9AF
[HKEY_CLASSES_ROOT\CLSID\{
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\softwa
@="{5E529433-B50E-4bef-A63
[HKEY_CLASSES_ROOT\CLSID\{
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_CURRENT_USER\SOFTWAR
"ISUSPM"="c:\program files\Common Files\InstallShield\Update
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe
"swg"="c:\program files\Google\GoogleToolbar
[HKEY_LOCAL_MACHINE\SOFTWA
"avast!"="c:\progra~1\ALWI
"NA1Messenger"="c:\ups\WST
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-01-09 669840]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe
"IntelliPoint"="c:\program
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="c:\p
c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QB
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adob
backup=c:\windows\pss\Adob
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quic
backup=c:\windows\pss\Quic
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Serv
backup=c:\windows\pss\Serv
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\UPS WorldShip Messaging Utility.lnk
backup=c:\windows\pss\UPS WorldShip Messaging Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\UPS WorldShip PLD Reminder Utility.lnk
backup=c:\windows\pss\UPS WorldShip PLD Reminder Utility.lnkCommon Startup
[HKLM\~\services\sharedacc
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
"%windir%\\system32\\sessm
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.
"c:\\UPS\\WSTD\\MSSQL$UPSW
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.ex
"c:\\Program Files\\CoffeeCup Software\\FreeFTPFree-4.0.
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.ex
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSyn
"c:\\WINDOWS\\system32\\mm
[HKLM\~\services\sharedacc
"1434:UDP"= 1434:UDP:UDP 1434
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22
R0 Lbd;Lbd;c:\windows\system3
R1 aswSP;avast! Self Protection;c:\windows\syst
R2 aswFsBlk;aswFsBlk;c:\windo
R2 LANPkt;Realtek LANPkt Protocol Driver;c:\windows\system32
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AA
R2 MSSQL$UPSWSDBSERVER;MSSQL$
S2 gupdate1c9c426ed159bec;Goo
S2 QuickBooksDB18;QuickBooksD
S3 Diag69xp;Diag69xp;c:\windo
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32
S3 motccgpfl;MotCcgpFlService
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\d
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32
S3 SQLAgent$UPSWSDBSERVER;SQL
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWAR
BtwSrv
.
Contents of the 'Scheduled Tasks' folder
2009-10-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad
2009-10-21 c:\windows\Tasks\AppleSoft
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-10-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google
2009-10-26 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
2009-10-23 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
.
.
------- Supplementary Scan -------
.
uStart Page = partnerpage.google.com/sma
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: Convert link target to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: Convert selected links to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: Convert selection to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: Convert to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: Convert to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClien
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Offic
TCP: {72416BE3-010B-4335-98B4-2
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-8
FF - ProfilePath - c:\documents and settings\Stephen\Applicati
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/sear
FF - prefs.js: browser.search.selectedEng
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?h
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCI
FF - plugin: c:\program files\Google\Update\1.2.18
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.d
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugi
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-0
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-26 08:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2ev
.
Completion time: 2009-10-26 8:08
ComboFix-quarantined-files
ComboFix2.txt 2009-10-21 13:57
Pre-Run: 251,965,136,896 bytes free
Post-Run: 252,172,439,552 bytes free
- - End Of File - - F8F4E3FF23F6548623EE5FCED8
ok, here is the GMER log. Not really a lot to it. I received no notifications while it was scanning.
GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-10-26 11:16:05
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Stephen\LOCALS
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
SSDT \SystemRoot\System32\Drive
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\servic
IAT C:\WINDOWS\system32\servic
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \FileSystem\Fastfat \Fat A8FDBD20
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
---- EOF - GMER 1.0.15 ----
OK, now I have a question. Does the GMER Rootkit Scanner automatically remove unwanted items? The reason I ask is because my search results are no longer being redirected. I have been trying to get it to happen for half hour or so, but it appears to be fixed and I am trying to figure out exactly what fixed it.
I am doubting that ComboFix fixed it because I had run it two previous times. Anyway, I will keep trying it today and let you know if it starts redirecting again. If it stays clean I will post back tonight (and award points).
Thanks again for all your help.
Thanks for the log.
<<<"Does the GMER Rootkit Scanner automatically remove unwanted items? The reason I ask is because my search results are no longer being redirected.">>>
No. Gmer doesn't automatically remove any threats found.
Combofix must've fixed the redirects.. see line below from Combofix log. Recent nasties patched atapi.sys and also caused redirects.
<<<<Infected copy of c:\windows\system32\DRIVER
No problem... though you fixed it yourself, well done...
When you're done with Combofix, please uninstall it. Uninstallation will delete its backups, reset System Restore and creates one restore point.
To uninstall Combofix:
Go to Start > Run and 'copy and paste' next command in the field:
ComboFix /u
Thanks!
If you want to uninstall Gmer and need guidance let me know.
Thanks for the info on how your pc got infected.
Yes, since last year Myspace/Facebook had been targetted by malicious hackers and infecting many systems.
http://www.pcworld
I just wanted to let everyone know what worked for me when I was in this situation with a PC I was working on.
The following programs were up to date and reported NO problems- Combofix, Malwarebytes, Spybot, Microsoft MSRT, SuperAntiSpyware.
I then found Dr. Web's CureIT (http://majorgeeks.com/Dr.
Business Accounts
Answer for Membership
by: iWinSolveBustPosted on 2009-10-23 at 08:03:36ID: 25645079
Did you try running IE or FF in safe mode to see if it's some plugin or toolbar crap that's causing it? Unlikely, but still worth a try.