Click links and goes to wrong website

November 4, 2009 at 10:39:07
Specs: Windows XP

Hello. Almost everytime I click a link in Firefox or Internet Explorer I get redirected to random websites. When I place the mouse over links the web address that shows up on the bottom of the screen usually begins with www.thefeedwater.com.... or www.greatfeedmill.com... or something similar.

I've tried doing a system restore but it doesn't allow me to do so. I also can't go into Safe Mode because a blue screen appears and the pc crashes. I've run Malwarebites multiple times and it usually find around 9 infections, 3 or 4 of which cannot be removed without restarting. Upon restart I will get a couple of errors.

Also, Firefox keeps crashing every now and then. Don't know if this is related...


See More: Click links and goes to wrong website

Report •


#1
November 4, 2009 at 17:57:43

See if you can run these programs and post there logs. You may have to download these to a usb drive or cd from an uninfected computer then run them on the infected compter.

Please save this file to your desktop.

Win32kDiag.exe

Please double click on the Win32kDiag file and post the log it produces. This log might be quite lengthy and may take more than one post to get all of it posted.

Please run RSIT.exe by random/random and post its logs.

Download random's system information tool (RSIT) by random/random from the following link and save it to your desktop.

RSIT.exe

1. Double click on RSIT.exe to launch program.
2.(Vista Users Only) Right click on the RSIT.exe icon and select "Run as Administrator" to run the program.
3. Click Continue at the disclaimer screen.
4. Your firewall may alert you that RSIT is requesting Internet access. Please allow it.
5.Once it has finished, two logs will open: log.txt<-- this will be maximized and info.txt<-- this will be minimized.

Please post the contents of both logs (in separate post) in your next reply.


Report •

#2
November 4, 2009 at 19:37:23

I downloaded and ran Spybot Search and Destroy. Things seemed to have cleared up.

Report •

#3
November 4, 2009 at 19:51:06

I doubt that spybot cleaned up everything, you should run those scans and the three or four more that are usually needed to clean up computers with browser redirecting problems.

Report •

Related Solutions

#4
December 12, 2009 at 08:44:10

this is the log after the rsit.exe


Logfile of random's system information tool 1.06 (written by random/random)
Run by Maxx Reyes at 2009-12-12 11:45:31
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 131 GB (57%) free of 228 GB
Total RAM: 2811 MB (52% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\User_Feed_Synchronization-{991D68C5-A0E4-4142-9E52-D2AF9B9A624C}.job
C:\Windows\tasks\User_Feed_Synchronization-{DFB45B3C-1513-458A-888A-F619018084F5}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2009-12-12 1484056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1115392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-31 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-14 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-08-31 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-31 256112]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1115392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-20 1008184]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-04-21 7420448]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-02 30192]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2009-06-23 703008]
"EgisTecLiveUpdate"=C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [2009-05-13 199464]
"mwlDaemon"=C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009-05-15 345384]
"Acer Assist Launcher"=C:\Program Files\Acer\Acer Assist\launcher.exe [2007-11-19 1261568]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-05-05 61440]
"PLFSetI"=C:\Windows\PLFSetI.exe [2008-07-29 200704]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-01-08 1418536]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-02-11 862728]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2009-05-05 156968]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2009-05-05 206120]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2009-05-04 173288]
"Acer Product Registration"=C:\Program Files\Acer\Acer Registration\ACE1.exe [2007-11-26 3387392]
"Carbonite Backup"=C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe [2009-01-09 669840]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-04-21 1833504]
"PLFSetL"=C:\Windows\\PLFSetL.exe [2007-07-05 94208]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2009-12-12 2033432]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-20 125952]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2009-10-06 289072]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-30 68856]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-20 202240]
"Weather"=C:\Program Files\AWS\WeatherBug\Weather.exe 1 []

C:\Users\Maxx Reyes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Orion.lnk - C:\Program Files\Convesoft\Orion\Messenger.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-12-12 11:34:42 ----D---- C:\Program Files\trend micro
2009-12-12 11:34:41 ----D---- C:\rsit
2009-12-11 11:42:38 ----HD---- C:\$AVG
2009-12-11 11:42:35 ----A---- C:\Windows\system32\avgrsstx.dll
2009-12-11 11:42:19 ----D---- C:\ProgramData\AVG Security Toolbar
2009-12-11 11:41:53 ----D---- C:\Windows\LastGood
2009-12-11 11:41:37 ----D---- C:\ProgramData\avg9
2009-12-11 11:31:04 ----D---- C:\Program Files\AVG
2009-12-11 01:06:54 ----N---- C:\Windows\system32\MpSigStub.exe
2009-12-11 00:42:17 ----A---- C:\Windows\system32\nshhttp.dll
2009-12-11 00:42:10 ----A---- C:\Windows\system32\httpapi.dll
2009-12-11 00:36:42 ----A---- C:\Windows\system32\winhttp.dll
2009-12-11 00:36:36 ----A---- C:\Windows\system32\mshtml.dll
2009-12-11 00:36:35 ----A---- C:\Windows\system32\ieframe.dll
2009-12-11 00:36:31 ----A---- C:\Windows\system32\iertutil.dll
2009-12-11 00:36:30 ----A---- C:\Windows\system32\wininet.dll
2009-12-11 00:36:30 ----A---- C:\Windows\system32\urlmon.dll
2009-12-11 00:36:30 ----A---- C:\Windows\system32\msfeeds.dll
2009-12-11 00:36:29 ----A---- C:\Windows\system32\occache.dll
2009-12-11 00:36:29 ----A---- C:\Windows\system32\iedkcs32.dll
2009-12-11 00:36:28 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-12-11 00:36:28 ----A---- C:\Windows\system32\ieUnatt.exe
2009-12-11 00:36:28 ----A---- C:\Windows\system32\ieui.dll
2009-12-11 00:36:28 ----A---- C:\Windows\system32\iesysprep.dll
2009-12-11 00:36:28 ----A---- C:\Windows\system32\iepeers.dll
2009-12-11 00:36:27 ----A---- C:\Windows\system32\msfeedssync.exe
2009-12-11 00:36:27 ----A---- C:\Windows\system32\jsproxy.dll
2009-12-11 00:36:27 ----A---- C:\Windows\system32\ie4uinit.exe
2009-12-11 00:36:26 ----A---- C:\Windows\system32\iesetup.dll
2009-12-11 00:36:26 ----A---- C:\Windows\system32\iernonce.dll
2009-12-11 00:32:56 ----A---- C:\Windows\system32\rastls.dll
2009-12-11 00:26:46 ----D---- C:\Program Files\Ask.com
2009-12-08 23:15:19 ----D---- C:\Program Files\Alwil Software
2009-11-30 23:34:28 ----D---- C:\Program Files\Take Screenshot
2009-11-30 19:38:50 ----D---- C:\Users\Maxx Reyes\AppData\Roaming\Malwarebytes
2009-11-30 19:38:41 ----D---- C:\ProgramData\Malwarebytes
2009-11-30 19:38:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-26 21:02:12 ----D---- C:\Windows\system32\Adobe
2009-11-25 11:37:26 ----A---- C:\Windows\system32\tzres.dll
2009-11-25 11:24:56 ----A---- C:\Windows\system32\msxml6.dll
2009-11-25 11:24:55 ----A---- C:\Windows\system32\msxml3.dll
2009-11-25 00:19:28 ----D---- C:\Users\Maxx Reyes\AppData\Roaming\Webroot
2009-11-25 00:19:28 ----D---- C:\ProgramData\Webroot
2009-11-25 00:19:28 ----D---- C:\Program Files\Webroot
2009-11-25 00:19:28 ----A---- C:\Windows\WRSetup.dll
2009-11-25 00:17:32 ----D---- C:\Users\Maxx Reyes\AppData\Roaming\WeatherBug
2009-11-24 21:26:36 ----D---- C:\dir
2009-11-24 21:26:31 ----D---- C:\Users\Maxx Reyes\AppData\Roaming\WinRAR
2009-11-24 21:26:08 ----D---- C:\Program Files\WinRAR
2009-11-24 13:56:40 ----D---- C:\Users\Maxx Reyes\AppData\Roaming\blinkx
2009-11-24 13:56:13 ----D---- C:\Users\Maxx Reyes\AppData\Roaming\Yahoo!
2009-11-24 13:56:10 ----D---- C:\Program Files\Yahoo!
2009-11-20 10:00:22 ----A---- C:\Windows\_MSRSTRT.EXE
2009-11-17 06:21:43 ----D---- C:\Program Files\Windows Portable Devices
2009-11-17 06:05:24 ----A---- C:\Windows\system32\UIAnimation.dll
2009-11-17 06:05:20 ----A---- C:\Windows\system32\UIRibbonRes.dll
2009-11-17 06:05:19 ----A---- C:\Windows\system32\UIRibbon.dll
2009-11-17 06:04:27 ----A---- C:\Windows\system32\WMPhoto.dll
2009-11-17 06:04:23 ----A---- C:\Windows\system32\cdd.dll
2009-11-17 06:04:18 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-11-17 06:04:18 ----A---- C:\Windows\system32\d3d10warp.dll
2009-11-17 06:04:16 ----A---- C:\Windows\system32\XpsRasterService.dll
2009-11-17 06:04:16 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2009-11-17 06:04:16 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-11-17 06:04:16 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-11-17 06:04:16 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-11-17 06:04:16 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-11-17 06:04:16 ----A---- C:\Windows\system32\dxdiagn.dll
2009-11-17 06:04:16 ----A---- C:\Windows\system32\dxdiag.exe
2009-11-17 06:04:16 ----A---- C:\Windows\system32\d2d1.dll
2009-11-17 06:04:15 ----A---- C:\Windows\system32\xpsservices.dll
2009-11-17 06:04:15 ----A---- C:\Windows\system32\XpsPrint.dll
2009-11-17 06:04:15 ----A---- C:\Windows\system32\OpcServices.dll
2009-11-17 06:04:14 ----A---- C:\Windows\system32\FntCache.dll
2009-11-17 06:04:14 ----A---- C:\Windows\system32\DWrite.dll
2009-11-17 06:04:14 ----A---- C:\Windows\system32\d3d10level9.dll
2009-11-17 06:04:13 ----A---- C:\Windows\system32\dxgi.dll
2009-11-17 06:04:13 ----A---- C:\Windows\system32\d3d11.dll
2009-11-17 06:04:13 ----A---- C:\Windows\system32\d3d10core.dll
2009-11-17 06:04:13 ----A---- C:\Windows\system32\d3d10_1core.dll
2009-11-17 06:04:13 ----A---- C:\Windows\system32\d3d10_1.dll
2009-11-17 06:04:13 ----A---- C:\Windows\system32\d3d10.dll
2009-11-17 06:03:35 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2009-11-17 06:03:35 ----A---- C:\Windows\system32\wpdbusenum.dll
2009-11-17 06:03:35 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2009-11-17 06:03:19 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2009-11-17 06:03:09 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2009-11-17 06:03:09 ----A---- C:\Windows\system32\wpdshext.dll
2009-11-17 06:03:09 ----A---- C:\Windows\system32\wpd_ci.dll
2009-11-17 06:03:09 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-11-17 06:03:08 ----A---- C:\Windows\system32\WPDSp.dll
2009-11-17 06:03:08 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2009-11-17 06:03:08 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-11-17 06:03:08 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-11-17 06:00:58 ----A---- C:\Windows\system32\oleaccrc.dll
2009-11-17 06:00:56 ----A---- C:\Windows\system32\UIAutomationCore.dll
2009-11-17 06:00:56 ----A---- C:\Windows\system32\oleacc.dll
2009-11-17 04:46:53 ----A---- C:\Windows\system32\WINCNMDB.DLL
2009-11-17 04:46:34 ----D---- C:\Program Files\ActMak
2009-11-17 03:34:21 ----D---- C:\Program Files\Auto Clicker Typer

======List of files/folders modified in the last 1 months======

2009-12-12 11:45:28 ----D---- C:\Windows\Temp
2009-12-12 11:34:42 ----RD---- C:\Program Files
2009-12-12 04:59:18 ----D---- C:\Windows\Prefetch
2009-12-12 00:37:20 ----D---- C:\Windows\.jagex_cache_32
2009-12-11 13:06:50 ----D---- C:\Windows\system32\Tasks
2009-12-11 13:06:48 ----D---- C:\Windows\Tasks
2009-12-11 11:54:57 ----D---- C:\Windows\System32
2009-12-11 11:54:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-12-11 11:54:56 ----D---- C:\Windows\inf
2009-12-11 11:49:07 ----D---- C:\Windows
2009-12-11 11:42:34 ----D---- C:\Windows\system32\drivers
2009-12-11 11:42:19 ----HD---- C:\ProgramData
2009-12-11 11:41:53 ----D---- C:\Windows\system32\catroot
2009-12-11 11:41:19 ----SHD---- C:\Windows\Installer
2009-12-11 11:40:55 ----SD---- C:\Users\Maxx Reyes\AppData\Roaming\Microsoft
2009-12-11 11:39:05 ----D---- C:\ProgramData\McAfee
2009-12-11 11:39:05 ----D---- C:\Program Files\Common Files
2009-12-11 11:30:44 ----D---- C:\Windows\winsxs
2009-12-11 11:30:30 ----D---- C:\Program Files\Common Files\microsoft shared
2009-12-11 03:13:49 ----D---- C:\Windows\system32\Msdtc
2009-12-11 03:13:44 ----D---- C:\Windows\system32\wbem
2009-12-11 01:12:53 ----D---- C:\Windows\rescache
2009-12-11 00:49:37 ----D---- C:\Windows\system32\migration
2009-12-11 00:49:35 ----D---- C:\Windows\system32\en-US
2009-12-11 00:49:35 ----D---- C:\Program Files\Internet Explorer
2009-12-11 00:49:34 ----D---- C:\Program Files\Windows Mail
2009-12-11 00:42:56 ----D---- C:\Windows\system32\catroot2
2009-12-11 00:41:49 ----D---- C:\ProgramData\Microsoft Help
2009-12-11 00:12:32 ----D---- C:\Windows\system32\config
2009-12-11 00:11:56 ----SD---- C:\Windows\Downloaded Program Files
2009-12-11 00:11:56 ----RSD---- C:\Windows\Media
2009-12-11 00:11:52 ----RD---- C:\Windows\system32\32 boots loggin
2009-12-11 00:11:52 ----D---- C:\Windows\system32\spool
2009-12-11 00:11:52 ----D---- C:\Windows\system32\CodeIntegrity
2009-12-11 00:11:51 ----D---- C:\Users\Maxx Reyes\AppData\Roaming\uTorrent
2009-12-11 00:11:49 ----D---- C:\ProgramData\McAfee Security Scan
2009-12-11 00:11:49 ----D---- C:\Program Files\uTorrent
2009-12-11 00:11:45 ----D---- C:\Windows\registration
2009-12-11 00:11:42 ----RHD---- C:\MSOCache
2009-12-11 00:06:56 ----SHD---- C:\System Volume Information
2009-12-10 11:57:37 ----D---- C:\ProgramData\ACASystems
2009-12-10 10:14:23 ----SD---- C:\ProgramData\Microsoft
2009-12-10 10:13:09 ----D---- C:\Program Files\Mozilla Firefox
2009-12-01 15:06:19 ----A---- C:\Windows\system32\mrt.exe
2009-11-26 21:03:22 ----D---- C:\Windows\system32\Macromed
2009-11-20 10:04:39 ----D---- C:\ProgramData\Adobe
2009-11-19 14:42:31 ----D---- C:\Program Files\Common Files\Adobe
2009-11-19 14:42:17 ----D---- C:\Program Files\Adobe
2009-11-17 06:21:37 ----D---- C:\Windows\system32\uk-UA
2009-11-17 06:21:37 ----D---- C:\Windows\system32\pt-PT
2009-11-17 06:21:37 ----D---- C:\Windows\system32\pt-BR
2009-11-17 06:21:37 ----D---- C:\Windows\system32\pl-PL
2009-11-17 06:21:37 ----D---- C:\Windows\system32\ko-KR
2009-11-17 06:21:37 ----D---- C:\Windows\system32\it-IT
2009-11-17 06:21:37 ----D---- C:\Windows\system32\hu-HU
2009-11-17 06:21:37 ----D---- C:\Windows\system32\hr-HR
2009-11-17 06:21:37 ----D---- C:\Windows\system32\he-IL
2009-11-17 06:21:37 ----D---- C:\Windows\system32\bg-BG
2009-11-17 06:21:36 ----D---- C:\Windows\system32\zh-HK
2009-11-17 06:21:36 ----D---- C:\Windows\system32\tr-TR
2009-11-17 06:21:36 ----D---- C:\Windows\system32\th-TH
2009-11-17 06:21:36 ----D---- C:\Windows\system32\sv-SE
2009-11-17 06:21:36 ----D---- C:\Windows\system32\sr-Latn-CS
2009-11-17 06:21:36 ----D---- C:\Windows\system32\sl-SI
2009-11-17 06:21:36 ----D---- C:\Windows\system32\nl-NL
2009-11-17 06:21:36 ----D---- C:\Windows\system32\fr-FR
2009-11-17 06:21:36 ----D---- C:\Windows\system32\fi-FI
2009-11-17 06:21:36 ----D---- C:\Windows\system32\el-GR
2009-11-17 06:21:35 ----D---- C:\Windows\system32\zh-TW
2009-11-17 06:21:35 ----D---- C:\Windows\system32\zh-CN
2009-11-17 06:21:35 ----D---- C:\Windows\system32\sk-SK
2009-11-17 06:21:35 ----D---- C:\Windows\system32\lv-LV
2009-11-17 06:21:35 ----D---- C:\Windows\system32\lt-LT
2009-11-17 06:21:35 ----D---- C:\Windows\system32\et-EE
2009-11-17 06:21:35 ----D---- C:\Windows\system32\es-ES
2009-11-17 06:21:35 ----D---- C:\Windows\system32\de-DE
2009-11-17 06:21:35 ----D---- C:\Windows\system32\cs-CZ
2009-11-17 06:21:34 ----D---- C:\Windows\system32\ru-RU
2009-11-17 06:21:34 ----D---- C:\Windows\system32\ro-RO
2009-11-17 06:21:34 ----D---- C:\Windows\system32\nb-NO
2009-11-17 06:21:34 ----D---- C:\Windows\system32\ja-JP
2009-11-17 06:21:34 ----D---- C:\Windows\system32\da-DK
2009-11-17 06:21:34 ----D---- C:\Windows\system32\ar-SA
2009-11-13 17:23:20 ----D---- C:\PerfLogs

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2009-12-11 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-12-11 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-12-11 28424]
R1 AvgTdiX;AVG Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-12-11 360584]
R1 DPMemGridVista;Physical Memory I/O for GridVista; \??\C:\Program Files\GridVista\DPMemGridVista.sys [2008-09-30 10504]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\Program Files\Launch Manager\DPortIO.sys [2006-11-02 20112]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2008-12-04 19504]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2008-12-04 16432]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2008-12-04 59952]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-09-30 1184768]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-05-05 4492288]
R3 AVGIDSDrivervtx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2009-12-11 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2009-12-11 30216]
R3 AVGIDSShimvtx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2009-12-11 27800]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-20 14208]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2009-03-25 21000]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-04-21 2361504]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C60x86.sys [2009-09-04 53248]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-01-08 204976]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2008-10-10 23096]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-20 134016]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-20 11264]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-02-20 1882616]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-20 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-20 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-20 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-20 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-20 6016]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-03-26 64000]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-20 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-05-05 176128]
R2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2009-12-11 906520]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2009-12-11 285392]
R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2009-12-12 2303680]
R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2009-12-11 5832712]
R2 CarboniteService;CarboniteService; C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe [2009-01-09 1951376]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2009-04-14 75048]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2009-06-23 723488]
R2 MWLService;MyWinLocker Service; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-05-15 305448]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-20 21504]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-02 30192]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-31 182768]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------


Report •

#5
December 12, 2009 at 09:06:56

Download Gmer.exe from the following link.

Link1

1. Disconnect from the Internet and close all running programs.
2. Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
3. Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
4. Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.
5. GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
6. If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
7. Now click the Scan button. If you see a rootkit warning window, click OK.
8. When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
9. Click the Copy button and paste the results into your next reply.
•Exit GMER and re-enable all active protection when done.


Report •


Ask Question