go.google go.yahoo redirect problem

Today when I try to access search through Yahoo or Google the results have a go.google.com or .yahoo.com in the url and redirect me to nonsense sites unrelated to the search. This affects Opera, Firefox, and IE. Chrome will not even connect to the internet, I am only having luck with Safari.

IE must be running in the background as I get an IE error occassionally.

None of my Spyware, Anti-Virus, or Malware programs will update and their sites are blocked.

Here's my HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:25:54 PM, on 9/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - ?p=ZKfox000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147911654390
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.13/ttinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

--
End of file - 8949 bytes

Comments

  • edited October 2008
    Hello and Welcome to the forums!

    My name is Carolyn and I'll be glad to help you with your computer problems. HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that it happens.

    Please do not run any other tool untill instructed to do so!
    Please reply to this thread, do not start another!
    Please tell me about any problems that have occurred during the fix.
    Please tell me of any other symptoms you may be having as these can help also.
    Please try as much as possible not to run anything while executing a fix.


    If you follow these instructions, everything should go smoothly.


    I notice that there is more than one antivirus program installed on your computer. This is very dangerous, as multiple antivirus programs can interfere with one another and actually allow MORE viruses to get through. When you have more than one antivirus program installed at the same time, they conflict with each other rendering the computer vulnerable or unusable.

    It is NOT safe to have more than one anti-virus installed on a system, and doing so not only does NOT provide better protection, it will actually cause additional problems. Anti-virus programs patch into the system kernel. Having more than one anti-virus patching into the system kernel will not only destabilize a system, it can corrupt system files and it WILL cause crashes!
      Go to "Start -> Control Panel -> Add/Remove Programs" and uninstall all but one antivirus program.



      Please download Malwarebytes' Anti-Malware and save it to a convenient location.
      1. Double click on mbam-setup.exe to install it.
      2. Before clicking the Finish button, make sure that these 2 boxes are checked (ticked):
          Update Malwarebytes' Anti-Malware
          Launch Malwarebytes' Anti-Malware
        [*]Malwarebytes' Anti-Malware will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update Mirror, select one of the websites and click on Check for Updates.
        [*]Select the Scanner tab. Click on Perform full scan, then click on Scan.
        [*]Leave the default options as it is and click on Start Scan.
        [*]When done, you will be prompted. Click OK, then click on Show Results.
        [*]Checked (ticked) all items and click on Remove Selected.
        [*]After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.

        Next,
        • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
        • Double click on RSIT.exe to run RSIT.
        • Click Continue at the disclaimer screen.
        • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

        Please post the following:
        1. The Malwarebyte's Anti-Malware log
        2. The contents of log.txt
        3. The contents of info.txt
      3. edited October 2008
        I am preparing to run the Malwarebytes.

        Some more symptoms:

        Malwarebytes will only update using the second mirror site, the first is unreachable. The same problem with any of the anti-virus programs.

        As I said earlier Google Chrome will not work at all but I have downloaded and can use the Iron browser as well as Safari without the redirects.

        The Malicious Software removal tool download from Microsoft is blocked as well as Windows update.

        I get the following error when I try to click on the link http://images.malwareremoval.com/random/RSIT.exe :

        This webpage is not available.

        The webpage at http://images.malwareremoval.com/random/RSIT.exe

        Which is the same error I get from Microsoft.

        I have uninstalled the other anti-virus programs besides Avast! and am in the process of running the Malwarebytes Ant-Malware scan, I will post the log upon completion.

        Thank you so much for you help and time it is GREATLY appreciated!
      4. edited October 2008
        Malwarebytes' Anti-Malware 1.28
        Database version: 1226
        Windows 5.1.2600 Service Pack 2

        10/2/2008 5:48:39 PM
        mbam-log-2008-10-02 (17-48-39).txt

        Scan type: Full Scan (C:\|D:\|E:\|)
        Objects scanned: 136183
        Time elapsed: 47 minute(s), 10 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 2
        Registry Values Infected: 0
        Registry Data Items Infected: 2
        Folders Infected: 0
        Files Infected: 6

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully.

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        C:\WINDOWS\system32\ (Trojan.Agent) -> Delete on reboot.
        C:\WINDOWS\system32\drivers\ (Trojan.Agent) -> Delete on reboot.
        C:\WINDOWS\system32\tdssinit.dll (Rootkit.Agent) -> Delete on reboot.
        C:\WINDOWS\system32\tdssmain.dll (Rootkit.Agent) -> Delete on reboot.
        C:\WINDOWS\system32\tdssserf.dll (Rootkit.Agent) -> Delete on reboot.
        C:\WINDOWS\system32\drivers\tdssserv.sys (Rootkit.Agent) -> Delete on reboot.
      5. edited October 2008
        After the scan it went to reboot to remove some of the problems. When windows would start the screen would flash blue, then go to a black screen that would as if I wanted to start Normal, Safe Mode With Networking, Safe Mode, or Last Good Known settings. Only the last Good Know Settings option would load Windows.
      6. edited October 2008
        Please post a fresh HijackThis log.
      7. edited October 2008
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 7:07:58 PM, on 10/2/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18241)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Windows Defender\MsMpEng.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\system32\lxdccoms.exe
        C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\VTTimer.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\Program Files\Verizon\McciTrayApp.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
        C:\Program Files\SRWare Iron\iron.exe
        C:\Program Files\SRWare Iron\iron.exe
        C:\Program Files\SRWare Iron\iron.exe
        C:\Program Files\SRWare Iron\iron.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Internet Explorer\Iexplore.exe
        C:\Program Files\SRWare Iron\iron.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
        O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
        O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
        O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
        O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
        O8 - Extra context menu item: &Search - ?p=ZKfox000
        O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147911654390
        O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
        O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.13/ttinst.cab
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
        O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
        O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
        O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

        --
        End of file - 8730 bytes
      8. edited October 2008
        Hi,

        Download and Run ComboFix (by sUBs)

        A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
        ComboFix SHOULD NOT be used unless requested by a forum helper.


        We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

        http://www.bleepingcomputer.com/combofix/how-to-use-combofix

        Please ensure you read this guide carefully and install the Recovery Console first.

        The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

        Once installed, you should see a blue screen prompt that says:

        The Recovery Console was successfully installed.

        Please continue as follows:
        1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

        2. Click Yes to allow ComboFix to continue scanning for malware.

        When the tool is finished, it will produce a report for you.

        Please include the following reports for further review, and so we may continue cleansing the system:

        C:\ComboFix.txt
        New HijackThis log.
      9. edited October 2008
        C:\ComboFix.txt

        ComboFix 08-10-02.04 - Owner 2008-10-02 19:42:04.1 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.96 [GMT -4:00]

        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .

        ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
        C:\WINDOWS\system32\drivers\tdssserv.sys
        C:\WINDOWS\system32\TDSSadw.dll
        C:\WINDOWS\system32\TDSSerrors.log
        C:\WINDOWS\system32\tdssinit.dll
        C:\WINDOWS\system32\tdssl.dll
        C:\WINDOWS\system32\TDSSlog.dll
        C:\WINDOWS\system32\tdssmain.dll
        C:\WINDOWS\system32\tdssserf.dll
        C:\WINDOWS\system32\TDSSserf1.dll
        C:\WINDOWS\system32\tdssservers.dat
        C:\WINDOWS\system32\vrecorder.dll
        C:\WINDOWS\system32\windows_update.exe
        D:\Autorun.inf

        .
        ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        \Legacy_MYWEBSEARCHSERVICE


        ((((((((((((((((((((((((( Files Created from 2008-09-02 to 2008-10-02 )))))))))))))))))))))))))))))))
        .

        2008-10-02 17:50 . 2008-10-02 17:50 61,440 --a--c--- C:\WINDOWS\system32\drivers\indvsgyx.sys
        2008-10-01 14:03 . 2008-10-01 14:03 <DIR> d----c--- C:\Program Files\Apple Software Update
        2008-09-30 17:37 . 2008-09-30 17:39 <DIR> d----c--- C:\Program Files\DAP
        2008-09-30 17:37 . 2008-09-30 17:37 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SpeedBit
        2008-09-30 17:37 . 2008-09-30 17:37 479,298 --a--c--- C:\WINDOWS\system32\wbocx.ocx
        2008-09-30 17:37 . 2008-09-30 17:37 172,032 --a--c--- C:\WINDOWS\system32\AniGIF.ocx
        2008-09-30 17:37 . 2008-09-30 17:37 50,688 --a--c--- C:\WINDOWS\system32\wbhelp2.dll
        2008-09-28 20:57 . 2008-09-28 20:57 410,976 --a--c--- C:\WINDOWS\system32\deploytk.dll
        2008-09-28 20:20 . 2008-09-29 21:30 <DIR> d----c--- C:\Program Files\SRWare Iron
        2008-09-28 16:49 . 2008-09-28 16:49 <DIR> d----c--- C:\Program Files\Malware Removal Tool
        2008-09-28 13:50 . 2008-09-28 13:50 <DIR> d----c--- C:\Documents and Settings\Kool-Aid\Application Data\Malwarebytes
        2008-09-28 09:23 . 2008-09-28 09:23 <DIR> d----c--- C:\Program Files\AVG
        2008-09-28 09:23 . 2008-10-02 16:47 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\avg8
        2008-09-28 08:56 . 2008-09-28 08:56 <DIR> d----c--- C:\Program Files\Trend Micro
        2008-09-28 08:51 . 2008-09-28 08:51 <DIR> d----c--- C:\Program Files\IObit
        2008-09-27 20:45 . 2008-09-27 20:55 <DIR> d----c--- C:\Documents and Settings\Owner\amaya
        2008-09-27 20:39 . 2008-09-27 20:39 <DIR> d----c--- C:\Program Files\Opera
        2008-09-27 20:33 . 2008-09-27 20:33 72,720 --ah-c--- C:\WINDOWS\system32\mlfcache.dat
        2008-09-25 21:33 . 2008-09-25 21:33 <DIR> d--hsc--- C:\Documents and Settings\Kool-Aid\PrivacIE
        2008-09-23 23:47 . 2008-09-23 23:47 <DIR> d----c--- C:\Documents and Settings\Kool-Aid\Application Data\Apple Computer
        2008-09-19 14:51 . 2008-09-30 17:39 <DIR> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
        2008-09-16 15:07 . 2006-10-26 19:56 32,592 --a--c--- C:\WINDOWS\system32\msonpmon.dll
        2008-09-16 15:05 . 2008-09-16 15:05 <DIR> d----c--- C:\Program Files\Microsoft Works
        2008-09-16 15:03 . 2008-09-16 15:03 <DIR> d----c--- C:\Program Files\Microsoft.NET
        2008-09-16 14:57 . 2008-09-18 03:08 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Microsoft Help
        2008-09-16 14:56 . 2008-09-16 14:56 <DIR> dr-h-c--- C:\MSOCache
        2008-09-09 14:12 . 2008-10-02 15:38 54,156 --ah-c--- C:\WINDOWS\QTFont.qfn
        2008-09-09 14:12 . 2008-09-09 14:12 1,409 --a--c--- C:\WINDOWS\QTFont.for
        2008-09-02 09:25 . 2008-09-02 09:25 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\Malwarebytes
        2008-09-02 09:25 . 2008-09-10 00:03 17,200 --a--c--- C:\WINDOWS\system32\drivers\mbam.sys
        2008-09-02 09:24 . 2008-09-27 19:01 <DIR> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
        2008-09-02 09:24 . 2008-09-02 09:24 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
        2008-09-02 09:24 . 2008-09-10 00:04 38,528 --a--c--- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
        2008-09-02 04:27 . 2008-09-02 04:27 <DIR> d--hsc--- C:\Documents and Settings\Owner\PrivacIE

        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-10-02 23:54
        dc----w C:\Program Files\Lx_cats
        2008-10-01 18:06
        dc----w C:\Program Files\Safari
        2008-09-30 00:28
        dc----w C:\Documents and Settings\Owner\Application Data\CoreFTP
        2008-09-29 18:29
        dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
        2008-09-29 00:57
        dc----w C:\Program Files\Java
        2008-09-28 20:04
        dc----w C:\Program Files\Common Files\Wise Installation Wizard
        2008-09-28 20:03
        dc----w C:\Program Files\Beneton Movie GIF
        2008-09-28 17:37 592 -c--a-w C:\Program Files\shqpy.txt
        2008-09-27 22:30
        dc----w C:\Program Files\SpywareBlaster
        2008-09-26 19:00
        dc----w C:\Program Files\Norton Security Scan
        2008-09-25 23:08
        dc----w C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
        2008-09-25 14:39
        dc----w C:\Program Files\Common Files\Symantec Shared
        2008-09-22 02:12
        dc----w C:\Program Files\Mozilla Thunderbird
        2008-09-15 21:13
        dc----w C:\Program Files\Windows Media Connect 2
        2008-09-02 13:38
        dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft
        2008-09-02 13:36
        dc----w C:\Program Files\Lavasoft
        2008-09-01 14:48
        dc----w C:\Documents and Settings\Owner\Application Data\StarOffice8
        2008-08-31 22:29
        dc----w C:\Program Files\Spybot - Search & Destroy
        2008-08-31 22:13
        dc----w C:\Program Files\TeaTimer (Spybot - Search & Destroy)
        2008-08-30 22:22
        dc----w C:\Documents and Settings\Kool-Aid\Application Data\StarOffice8
        2008-08-30 20:32
        dc----w C:\Documents and Settings\Kool-Aid\Application Data\OpenOffice.org2
        2008-08-19 14:07
        dc----w C:\Program Files\NStorm
        2008-08-19 01:59
        dc----w C:\Program Files\Microsoft Silverlight
        2008-02-26 15:07 4 -csh--r C:\Documents and Settings\All Users\Application Data\sysqcl1129139270.dat
        2006-07-18 22:50 0 -c--a-w C:\Documents and Settings\Kool-Aid\Application Data\wklnhst.dat
        .

        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
        "Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2006-11-30 4662776]
        "Google Update"="C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-07 737370]
        "Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-06-06 936960]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-28 144792]
        "LXDCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 102400]
        "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 212992]
        "Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2005-03-14 966656]
        "VTTimer"="VTTimer.exe" [2005-03-08 C:\WINDOWS\system32\VTTimer.exe]
        "AGRSMMSG"="AGRSMMSG.exe" [2005-10-14 C:\WINDOWS\AGRSMMSG.exe]

        C:\Documents and Settings\Kool-Aid\Start Menu\Programs\Startup\
        OpenOffice.org 2.0.lnk.disabled [2006-07-18 876]
        StarOffice 8.lnk.disabled [2008-05-27 900]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
        "NoResolveSearch"= 1 (0x1)

        [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
        "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-09-28 77824]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
        2006-10-19 11:12 258048 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "vidc.X264"= x264vfw.dll
        "vidc.hfyu"= huffyuv.dll
        "msacm.divxa32"= DivXa32.acm

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
        "MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
        "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
        "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
        "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        "SpiralFrog"=C:\Program Files\SpiralFrog\Spiralfrog.exe
        "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
        "lxdcamon"="C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
        "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
        "C:\\StubInstaller.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "C:\\Program Files\\Messenger\\msmsgs.exe"=
        "C:\\Program Files\\CoreFTP\\coreftp.exe"=
        "C:\\WINDOWS\\system32\\lxdccoms.exe"=
        "C:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
        "C:\\Program Files\\Lexmark 1300 Series\\App4R.exe"=
        "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
        "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=
        "C:\\Program Files\\Auxiliary Power\\Demo\\DerbyDemo.exe"=
        "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
        "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
        "C:\\Program Files\\Trillian\\trillian.exe"=

        R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 78416]
        R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 20560]
        R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-28 147456]
        R2 lxdc_device;lxdc_device;C:\WINDOWS\system32\lxdccoms.exe [2007-02-12 537520]
        R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2006-08-31 43008]
        R3 vidcap;vidcap;C:\WINDOWS\system32\DRIVERS\vidcap.sys [2006-12-27 9006]
        S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys [2006-10-19 10664]

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b4dbc11-af60-11dc-9b05-0003252fbf98}]
        \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.mgae.com/keylauncher/?code=3654339936746538
        .
        Contents of the 'Scheduled Tasks' folder
        .
        .
        Supplementary Scan
        .
        FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\i0gvumse.default\
        FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
        FF -: plugin - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
        FF -: plugin - C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
        FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
        FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
        FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
        FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
        FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
        FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPMGWRAP.DLL
        FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
        FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPSFDMGR.dll
        FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
        FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\np32dsw.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npdrmv2.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npdsplay.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npnul32.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\NPOFF12.DLL
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\nppl3260.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npqtplugin.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npqtplugin2.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npqtplugin3.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npqtplugin4.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npqtplugin5.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npqtplugin6.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npqtplugin7.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\nprfxins.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\nprjplug.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\nprpjplug.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\NPSWF32.dll
        FF -: plugin - C:\Program Files\Netscape\Communicator\Program\Plugins\npwmsdrm.dll
        FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
        FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
        FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
        FF -: plugin - C:\WINDOWS\system32\C2MP\npdivx32.dll
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-10-02 19:54:06
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************

        [HKEY_LOCAL_MACHINE\System\ControlSet006\Services\PSSdk23]
        "ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk23.drv"
        .
        Other Running Processes
        .
        C:\Program Files\Windows Defender\MsMpEng.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
        .
        **************************************************************************
        .
        Completion time: 2008-10-02 19:59:44 - machine was rebooted
        ComboFix-quarantined-files.txt 2008-10-02 23:59:36

        Pre-Run: 37,967,261,696 bytes free
        Post-Run: 37,886,181,376 bytes free

        233 --- E O F --- 2008-09-26 05:58:29
      10. edited October 2008
        Hijack Log:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 8:02:25 PM, on 10/2/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18241)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Windows Defender\MsMpEng.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\system32\lxdccoms.exe
        C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\VTTimer.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\Program Files\Verizon\McciTrayApp.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
        C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\system32\notepad.exe
        C:\Program Files\SRWare Iron\iron.exe
        C:\Program Files\SRWare Iron\iron.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
        O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
        O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
        O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
        O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
        O8 - Extra context menu item: &Search - ?p=ZKfox000
        O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147911654390
        O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
        O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.13/ttinst.cab
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
        O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
        O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
        O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

        --
        End of file - 8135 bytes
      11. edited October 2008
        The redirect isn't appearing in my Firefox, or IE Google or yahoo searches right now. Google Chrome is working now as well. Thank you very much!
      12. edited October 2008
        Hello,

        I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager -- the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.
        To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.
        Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
        I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
        1. Click Start, point to Settings, and then click Control Panel.
        2. In Control Panel, double-click Add or Remove Programs.
        3. In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
        4. Do the same for each Viewpoint component.


        Download CCleaner from here and save it to your desktop.


        Run CCleaner
        CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!
        • Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
        • Then select the items you wish to clean up.
          • In the Windows Tab:
            • Clean all entries in the Internet Explorer section except Cookies
            • Clean all the entries in the Windows Explorer section
            • Clean all entries in the System section
            • Clean all entries in the Advanced section
            • Clean any others that you choose
          • In the Applications Tab:
            • Clean all except cookies in the Firefox/Mozilla section if you use it
            • Clean all in the Opera section if you use it
            • Clean Sun Java in the Internet Section
            • Clean any others that you choose
        • Click the Run Cleaner button.
        • A pop up box will appear advising this process will permanently delete files from your system.
        • Click OK and it will scan and clean your system.
        • Click exit when done.
        • If it asks you to reboot at the end, click NO
        CCleaner should be run with the above settings for each User Account!


        Please go to Kaspersky website and perform an online antivirus scan.
        1. Read through the requirements and privacy statement and click on Accept button.
        2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
        3. When the downloads have finished, click on Settings.
        4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
            Spyware, Adware, Dialers, and other potentially dangerous programs
            Archives
            Mail databases
          [*]Click on My Computer under Scan.
          [*]Once the scan is complete, it will display the results. Click on View Scan Report.
          [*]You will see a list of infected items there. Click on Save Report As....
          [*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
          [*]Please post this log in your next reply along with a fresh HijackThis log.
        5. edited October 2008

          KASPERSKY ONLINE SCANNER 7 REPORT
          Saturday, October 4, 2008
          Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
          Kaspersky Online Scanner 7 version: 7.0.25.0
          Program database last update: Saturday, October 04, 2008 02:05:02
          Records in database: 1287555

          Scan settings:
          Scan using the following database: extended
          Scan archives: yes
          Scan mail databases: yes

          Scan area - My Computer:
          C:\
          D:\
          E:\

          Scan statistics:
          Files scanned: 94946
          Threat name: 9
          Infected objects: 9
          Suspicious objects: 3
          Duration of the scan: 03:29:32


          File name / Threat name / Threats count
          C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\ih2cwgvs.default\Mail\Local Folders\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 2
          C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\ih2cwgvs.default\Mail\natureverse.com\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 1
          C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\ih2cwgvs.default\Mail\natureverse.com\Inbox Infected: Trojan-Spy.HTML.Bayfraud.hn 2
          C:\Documents and Settings\Owner\My Documents\WebfettiSetup2.3.50.19.ZKfox000.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.cw 1
          C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\tdssserv.sys.vir Infected: Rootkit.Win32.Agent.eeq 1
          C:\QooBox\Quarantine\C\WINDOWS\system32\tdssadw.dll.vir Infected: Rootkit.Win32.Clbd.ks 1
          C:\QooBox\Quarantine\C\WINDOWS\system32\tdssl.dll.vir Infected: Hoax.Win32.Renos.ebd 1
          C:\QooBox\Quarantine\C\WINDOWS\system32\tdsslog.dll.vir Infected: Backdoor.Win32.Agent.rfv 1
          C:\QooBox\Quarantine\C\WINDOWS\system32\tdssserf.dll.vir Infected: Trojan-Downloader.Win32.FraudLoad.vbxt 1
          D:\i386\Apps\App00577\comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1

          The selected area was scanned.
        6. edited October 2008
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 8:20:28 AM, on 10/4/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18241)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\lxdccoms.exe
          C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\VTTimer.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\WINDOWS\AGRSMMSG.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\Verizon\McciTrayApp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\Java\jre6\bin\java.exe
          C:\Program Files\SRWare Iron\iron.exe
          C:\WINDOWS\system32\NOTEPAD.EXE
          C:\Program Files\SRWare Iron\iron.exe
          C:\Program Files\SRWare Iron\iron.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
          O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
          O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
          O8 - Extra context menu item: &Search - ?p=ZKfox000
          O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
          O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147911654390
          O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
          O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.13/ttinst.cab
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
          O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
          O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
          O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

          --
          End of file - 8251 bytes
        7. edited October 2008
          Hello,

          There appears to be one or more infected emails in your Thunderbird Inboxes under Local Folders and natureverse.com... I recommend that you go through those Inboxes, save any important emails that you want to keep (do so by dragging them to another folder), then delete all of the remaining emails from the Inboxes and compact the folders.


          Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to and find the following files. If found, delete them:

          C:\Documents and Settings\Owner\My Documents\WebfettiSetup2.3.50.19.ZKfox000.exe <<File
          D:\i386\Apps\App00577\comps\toolbar\toolbr.exe <<File

          Now empty you’re Recycle Bin.


          Update Java
          Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
          • Download the latest version of http://java.sun.com/javase/downloads/index.jsp.
          • Scroll down to where it says Java Runtime Environment (JRE) 6 Update 7.
          • Click the "Download" button to the right.
          • Check the box that says: "Accept License Agreement".
          • The page will refresh.
          • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
          • Close any programs you may have running - especially your web browser.
          • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
          • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
          • Click the Remove or Change/Remove button.
          • Repeat as many times as necessary to remove each Java versions.
          • Reboot your computer once all Java components are removed.
          • Then from your desktop double-click on the download to install the newest version.
          • Note: If you don't want the Google toolbar, make sure you uncheck the option included in the installer!


          I can't see any firewall in your HijackThis log, so i assume you use windows firewall.

          FIREWALL
          Without a firewall your computer is susceptible to being hacked and taken over. If you use the Windows Firewall you might think that's sufficient but it only controls one way of the traffic (inbound). Simply using a Firewall in its default configuration can lower your risk greatly.
          It's preferable to install one of the suggested firewalls.

          FREE FIREWALLS
          Tutorial about Firewalls can be found here


          I recommend that you uninstall Google Chrome and Safari. They are both considered to be insecure browsers and not worth the security risk. Firefox or Opera are much better alternatives.


          This is my general post for when your logs show no more signs of malware ;)- Please let me know if you still are having problems with your computer and what these problems are

          Your log now appears to be clean. Congratulations!

          Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints. You need to be registered to post as, unfortunately, we were hit with too many spam posts to allow guest posting to continue. Just find your country room and register your complaint.


          Delete ComboFix and Clean Up
          Click Start > Run > type combofix /u > OK (Note the space between combofix and /u)
          CF_Cleanup.png
          Please advise if this step is missed for any reason as it performs some important actions.

          Protection Programs
          Don't forget to re-enable any protection programs we disabled during your fix.

          General Security and Computer Health
          Below are some steps to follow in order to dramatically lower the chances of reinfection. You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented.
          • Set correct settings for files
            • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
            • Under Hidden files and folders if necessary select Do not show hidden files and folders.
            • If unchecked please check Hide protected operating system files (Recommended)
            • If necessary check Display content of system folders
            • If necessary Uncheck Hide file extensions for known file types.
            • Click OK
          • Make sure that you keep your antivirus updated
            New viruses come out every minute, so it is essential that you have the latest signatures for your antivirus program to provide you with the best possible protection from malicious software.
            Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.
          • Install and use a firewall with outbound protection See my recommendations above:
            The Windows firewall only monitors incoming traffic, NOT outgoing. Using a software firewall in its default configuration to replace the Windows firewall greatly reduces the risk of your computer being hacked. Make sure your firewall is always enabled while your computer is connected to the internet.
            Note: You should only have one firewall installed at a time. Having more than one firewall installed at once is likely to cause conflicts and may well decrease your overall protection as well as seriously impairing the performance of your PC.
          • Security Updates for Windows, Internet Explorer & Microsoft Office
            Whenever a security problem in its software is found, Microsoft will usually create a patch so that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC. Keeping up with these patches will help to prevent malicious software being installed on your PC. Ensure you are registered for Windows updates via Start > right-click on My Computer > Properties > Automatic Updates tab or visit the Microsoft Update site on a regular basis.
            Note: The update process uses ActiveX, so you will need to use internet explorer for it and allow the ActiveX control to install.
          • Update Non-Microsoft Programs
            Microsoft isn't the only company whose products can contain security vulnerabilities. To check whether other programs running on your PC are in need of an update, you can use the Secunia Software Inspector - I suggest that you run it at least once a month.
          • Make Internet Explorer More Secure
            You are using Internet Explorer v. 7. Therefore please read and follow the recommendations at this SITE


          Recommended Programs

          I would recommend the download and installation of some or all of the following programs (if not already present), and the updating of them on a regular basis.
          • WinPatrol
            As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge. For more information, please visit HERE.
          • SpywareBlaster
            SpywareBlaster sets killbits in the registry to prevent known malicious ActiveX controls from installing on your computer. If you don't know what ActiveX controls are, see HERE. You can download SpywareBlaster from HERE.
          • Malwarebytes' Anti-Malware
            Malwarebytes' Anti-Malware is an anti-malware application that can thoroughly remove even the most advanced malware. It includes a number of features, including a built in protection monitor that blocks malicious processes before they even start.You can download Malwarebytes' Anti-Malware from HERE. You can find a tutorial HERE.
          • Hosts File
            For added protection you may also like to add a host file. A simple explanation of what a Hosts file does is HERE and for more information regarding host files read HERE.

            Be sure to disable the service "DNS Client" FIRST to allow the use of large HOSTS files without slowdowns.
            If this isn't done first, the next reboot may take a VERY LONG TIME.
            This is how to do it. First be sure you are signed in as a user with administrative privileges:
            Stop and Disable the DNS Client Service
            Go to Start, Run and type Services.msc and click OK.
            Under the Extended Tab, Scroll down and find this service.
            DNS Client
            Right-Click on the DNS Client Service. Choose Properties
            Select the General tab. Click on the Stop button.
            Click the Arrow-down tab on the right-hand side at the Start-up Type box.
            From the drop-down menu, click on Manual
            Click the Apply tab, then click OK
          • Use an alternative Internet Browser
            Many of the exploits are directed to users of Internet Explorer. Try using a different browser instead:
            Firefox
            Opera


          Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date.

          Also please read this great article by Tony Klein So How Did I Get Infected In First Place

          I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
        8. edited October 2008
          A couple of problems I ran into:

          I could not find a folder natureverse.com
          I couldn't access the D:\ to delete D:\i386\Apps\App00577\comps\toolbar\toolbr.exe

          I also was wondering about removing Safari and Chrome. When this hijack happened the only way I could search for help was with those two browsers as the hijack effected the search engine links in IE, Firefox, and Opera, the way I found this forum was Googling through Safari. Would it be safe to keep one of them, and only use for emergencies like this, or is deletion the best route?

          Thank you again for you help Firefox is my preferred browser and it was such a pain to navigate with the others.

          I plan on reading all the tutorials/info you linked to.
        9. edited October 2008
          duderawk wrote:
          A couple of problems I ran into:

          I could not find a folder natureverse.com
          I couldn't access the D:\ to delete D:\i386\Apps\App00577\comps\toolbar\toolbr.exe

          I also was wondering about removing Safari and Chrome. When this hijack happened the only way I could search for help was with those two browsers as the hijack effected the search engine links in IE, Firefox, and Opera, the way I found this forum was Googling through Safari. Would it be safe to keep one of them, and only use for emergencies like this, or is deletion the best route?

          Thank you again for you help Firefox is my preferred browser and it was such a pain to navigate with the others.

          I plan on reading all the tutorials/info you linked to.

          Do you have more than one Inbox in Thunderbird? If not, is there another User account on this computer? Perhaps the second inbox belongs to another User's Thunderbird Profile.

          Don't worry about the file on D:\

          I think you should uninstall Chrome and Safari. If you feel better keeping one, then I guess Safari is the better choice. I would uninstall them both though.
        10. edited October 2008
          Resolved

          If you wish to reopen your topic, please send a Private Message (PM) to Trogan with a link to your thread.

          If you are not the user who started this thread, you must start your own Thread instead (grin)

        This discussion has been closed.