<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT Log IE7 Browser Gets Redirected in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22563951</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 01:19:10 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 01:19:10 EDT</lastBuildDate>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22632428</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I'm glad to have been able to help. :)<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22632428</guid>
<pubDate>Tue, 30 Jun 2009 05:25:16 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22631927</link>
<description><![CDATA[<A HREF="/useremail/u/1066676"><b>gda6</b></A> : Joker,<br><br>I finally did the clean-up work.<br>Uninstalled combofix, created restore point, ran cleanmgr.<br>Installed hosts file; spyware blaster; spyware guard.<br><br>Everything is running fine.<br><br>Thanks so much for your help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22631927</guid>
<pubDate>Tue, 30 Jun 2009 00:37:09 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22582217</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : That's fine if it takes a few days. :)<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22582217</guid>
<pubDate>Sat, 20 Jun 2009 08:38:07 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22581229</link>
<description><![CDATA[<A HREF="/useremail/u/1066676"><b>gda6</b></A> : Joker,<br><br>Everything was working fine after your previous set of instructions.  I took the machine back to my friend's house because I thought that everything had been wrapped up.<br><br>Apparently, there is still some clean-up left.  I probably won't be able to do these tasks for another day or two.<br><br>I'll take care of the clean-up as you've specified.<br>I will also install the security utilities that you suggest so that hopefully the machine won't get infected again in the same fashion.<br><br>I will post again within a couple of days with an update.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22581229</guid>
<pubDate>Fri, 19 Jun 2009 23:08:12 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22576443</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Go to start > run and copy and paste next command in the field:<br><b>ComboFix /u</b><br><br>Make sure there's a space between Combofix and /<br>Then hit enter.<br><br>This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.<br><br>Create a <b>Restore Point</b><br>&#8226;Go to Start > Programs > Accessories > System Tools > <b>System Restore</b><br>&#8226;Select <b>Cr<u>e</u>ate a Restore Point</b> and then <b>Next</b>. <br>&#8226;In the box for "Restore point description", enter a descriptive name and press <b>Create</b><br>&#8226;When the "Restore Point Created" window appears, click <b>Close</b><br><br>Run <b>Disk Cleanup</b><br>&#8226;Go to Start > Run and type the below line:<br><b>cleanmgr</b><br>&#8226;Click <b>OK</b><br>&#8226;If you have more than one drive, select the drive Windows is installed on<br>&#8226;Click <b>OK</b><br>&#8226;When Disk Cleanup opens, select the <b>More Options</b> tab<br>&#8226;In the System Restore section (bottom of window), click <b>Cleanup</b><br>&#8226;In the confirmation window that opens, click <b>Yes</b>[<br><br>Now click on the <b>Disk Cleanup</b> tab and select the following items:<br>&#8226;Downloaded Program Files<br>&#8226;Temporary Internet Files<br>&#8226;Recycle Bin<br>&#8226;Temporary Files<br>Click <b>OK</b><br>in the confirmation window, select <b>Yes</b> (Disk Cleanup will close).<br><br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites known to be associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at &raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A>. <br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at &raquo;<A HREF="http://www.javacoolsoftware.com/products.html" >www.javacoolsoftware.com/products.html</A>. <br><br>I recommend reading Tony Klein's article <i>So How did I get Infected in the First Place?</i> at &raquo;<A HREF="http://www.spywareinfoforum.com/index.php?showtopic=60955" >www.spywareinfoforum.com/index.p&middot;&middot;&middot;ic=60955</A><br><br>Does your problem appear resolved?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22576443</guid>
<pubDate>Fri, 19 Jun 2009 05:58:11 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22575226</link>
<description><![CDATA[<A HREF="/useremail/u/1066676"><b>gda6</b></A> : Joker,<br><br>I seems that everything is working normally now.<br>I deleted the zip file as you suggested, and also<br>updated the java-runtime-environment.<br><br>I'm going to drop the machine off at my friend's house.<br><br>Both he and I thank you greatly for your help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22575226</guid>
<pubDate>Thu, 18 Jun 2009 21:41:12 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22570617</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>I had turned off system restore, before posting my first hijackthis log.<hr></blockquote><br><br>It's not a good idea to do that until cleaning is finished. When you turned off System Restore, it deleted all the Restore Points that there were, eliminating one source of file backups if needed.<br><br>Using Internet Explorer, you can delete the file:<br>c:\windows\Internet Logs\<b>tvDebug.zip</b><br>The file will return, but it will save some room due to it's size.<br><br>You can also delete the contents of C:\<b>temp</b>. Don't delete the folder itself, just the contents<br><br>Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.<br><b>Updating Java:</b><br>- Download the latest version of  <b><A HREF="http://java.sun.com/javase/downloads/index.jsp">Java Runtime Environment (JRE) 6</a></b>.<br>- Scroll down to where it says "<i>Java SE Runtime Environment (JRE), JRE 6 Update 14</i>".<br>- Click the "<b>Download</b>" button to the right.<br>- In the Window that opens, select Windows, and check the "agree" box and click "Continue".<br>- Click on the link to download <i>Windows Offline Installation</i> and save to your desktop.<br>- Close any programs you may have running - especially your web browser.<br>- Go to <b>Start</b> > <b>Control Panel</b> double-click on <b>Add or Remove Programs</b> and remove all older versions of Java.<br>- Check any item with Java Runtime Environment (JRE or J2SE) in the name.<br>- Examples of older versions in Add or Remove Programs:<br>-- Java 2 Runtime Environment, SE v1.4.2<br>-- J2SE Runtime Environment 5.0<br>-- J2SE Runtime Environment 5.0 Update 2<br>- Click the <b>Remove</b> or <b>Change/Remove</b> button.<br>- Repeat as many times as necessary to remove each Java versions.<br>- Reboot your computer once all Java components are removed.<br>- Then from your desktop double-click on <b>jre-6u14-windows-i586-p.exe</b> that you downloaded to install the newest version.<br><br>Are you still being redirected?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22570617</guid>
<pubDate>Thu, 18 Jun 2009 05:59:56 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22569750</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : Logfile of Trend Micro HijackThis v2.0.2 <br>Scan saved at 8:53:46 PM, on 6/17/2009 <br>Platform: Windows XP SP3 (WinNT 5.01.2600) <br>MSIE: Internet Explorer v7.00 (7.00.6000.16850) <br>Boot mode: Normal <br><br>Running processes: <br>C:\WINDOWS\System32\smss.exe <br>C:\WINDOWS\system32\winlogon.exe <br>C:\WINDOWS\system32\services.exe <br>C:\WINDOWS\system32\lsass.exe <br>C:\WINDOWS\system32\svchost.exe <br>C:\WINDOWS\System32\svchost.exe <br>C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe <br>C:\WINDOWS\system32\spoolsv.exe <br>C:\Program Files\Avira\AntiVir Desktop\sched.exe <br>C:\Program Files\Avira\AntiVir Desktop\avguard.exe <br>C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe <br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe <br>C:\WINDOWS\explorer.exe <br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe <br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A> <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080529 <br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll <br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" <br>O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min <br>O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe <br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE <br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime <br>O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe <br>O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" <br>O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe <br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe <br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe <br>O4 - HKLM\..\Run: [dyaaserv.exe] "C:\Program Files\DYMO DiscPainter\Drivers\dyaaserv.exe" <br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" <br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe <br>O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler <br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 <br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL <br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe <br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe <br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe <br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe <br>O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe <br>O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe <br>O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe <br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe <br>O23 - Service: V2i Protector - PowerQuest Corporation - C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe <br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe <br><br>-- <br>End of file - 4463 bytes <br><small>--<br><b>~<A HREF="/forum/cleanup">Safe Hex</a>~<A HREF="/forum/disco"> Team Discovery</a></b> <b><A HREF="http://www.tdprojecthope.com/"> ~ Project Hope ~ </b><b><A HREF="http://www.azlyrics.com/lyrics/neilyoung/likeahurricane.html">Like A Hurricane~</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22569750</guid>
<pubDate>Wed, 17 Jun 2009 22:52:12 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22569748</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : I'm going to open those logs up for ease of viewing<br><br>Malwarebytes' Anti-Malware 1.37 <br>Database version: 2296 <br>Windows 5.1.2600 Service Pack 3 <br><br>6/17/2009 8:40:49 AM <br>mbam-log-2009-06-17 (08-40-49).txt <br><br>Scan type: Quick Scan <br>Objects scanned: 81942 <br>Time elapsed: 2 minute(s), 1 second(s) <br><br>Memory Processes Infected: 0 <br>Memory Modules Infected: 0 <br>Registry Keys Infected: 0 <br>Registry Values Infected: 0 <br>Registry Data Items Infected: 0 <br>Folders Infected: 0 <br>Files Infected: 1 <br><br>Memory Processes Infected: <br>(No malicious items detected) <br><br>Memory Modules Infected: <br>(No malicious items detected) <br><br>Registry Keys Infected: <br>(No malicious items detected) <br><br>Registry Values Infected: <br>(No malicious items detected) <br><br>Registry Data Items Infected: <br>(No malicious items detected) <br><br>Folders Infected: <br>(No malicious items detected) <br><br>Files Infected: <br>C:\WINDOWS\system32\ieupdates.exe.tmp (Adware.Agent) -> Quarantined and deleted successfully. <br><br>ComboFix 09-06-17.02 - Lamar 06/17/2009 20:40.1 - NTFSx86 <br>Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1633 [GMT -5:00] <br>Running from: c:\documents and settings\Lamar\Desktop\ComboFix.exe <br>AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} <br>FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} <br>. <br><br>((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) <br>. <br><br>c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat <br>c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat <br>c:\documents and settings\Lamar\Application Data\inst.exe <br>c:\windows\system32\drivers\SKYNETpmeevkax.sys <br>c:\windows\system32\SKYNETgylclswx.dat <br>c:\windows\system32\SKYNETkpuakgyd.dll <br>c:\windows\system32\SKYNETowfnanim.dll <br>c:\windows\system32\SKYNETqkkeuytv.dat <br><br>----- BITS: Possible infected sites ----- <br><br>hxxp://binuser.fileave.com <br>. <br>((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) <br>. <br><br>-------\Service_SKYNETyutgwmri <br><br>((((((((((((((((((((((((( Files Created from 2009-05-18 to 2009-06-18 ))))))))))))))))))))))))))))))) <br>. <br><br>2009-06-17 13:43 . 2009-06-17 13:56 -------- d-----w- c:\temp\working <br>2009-06-17 13:36 . 2009-06-17 13:36 -------- d-----w- c:\documents and settings\Lamar\Application Data\Malwarebytes <br>2009-06-17 13:36 . 2009-05-26 18:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys <br>2009-06-17 13:36 . 2009-06-17 13:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware <br>2009-06-17 13:36 . 2009-06-17 13:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes <br>2009-06-17 13:36 . 2009-05-26 18:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys <br>2009-06-17 13:34 . 2009-06-17 13:34 3371384 ----a-w- c:\temp\mbam-setup.exe <br>2009-06-17 04:26 . 2009-06-17 04:26 -------- d-----w- c:\program files\Trend Micro <br>2009-06-17 04:24 . 2009-06-17 04:24 812344 ----a-w- c:\temp\HJTInstall.exe <br>2009-06-17 04:15 . 2009-06-17 03:09 15688 ----a-w- c:\windows\system32\lsdelete.exe <br>2009-06-17 03:09 . 2009-06-17 03:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys <br>2009-06-17 03:09 . 2009-06-17 03:09 314200 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe <br>2009-06-17 03:09 . 2009-06-17 03:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll <br>2009-06-17 03:09 . 2009-06-17 03:09 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll <br>2009-06-17 03:09 . 2009-06-17 03:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe <br>2009-06-17 03:09 . 2009-06-17 03:09 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll <br>2009-06-17 03:09 . 2009-06-17 03:09 294240 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll <br>2009-06-17 03:09 . 2009-06-17 03:09 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll <br>2009-06-17 03:08 . 2009-06-17 03:08 1630048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll <br>2009-06-17 03:08 . 2009-06-17 03:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll <br>2009-06-17 03:08 . 2009-06-17 03:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys <br>2009-06-17 03:08 . 2009-06-17 03:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll <br>2009-06-17 03:08 . 2009-06-17 03:08 640360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll <br>2009-06-17 03:08 . 2009-06-17 03:08 540536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe <br>2009-06-17 03:08 . 2009-06-17 03:08 559464 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe <br>2009-06-17 03:08 . 2009-06-17 03:08 2352456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe <br>2009-06-17 03:08 . 2009-06-17 03:08 627536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe <br>2009-06-17 03:08 . 2009-06-17 03:08 518488 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe <br>2009-06-17 03:08 . 2009-06-17 03:08 1005904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe <br>2009-06-17 03:07 . 2009-06-17 03:07 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} <br>2009-06-17 03:07 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe <br>2009-06-17 03:07 . 2009-06-17 03:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft <br>2009-06-17 03:07 . 2009-06-17 03:07 -------- d-----w- c:\program files\Lavasoft <br>2009-06-17 03:06 . 2009-06-17 03:06 37452296 ----a-w- c:\temp\Ad-AwareAE.exe <br>2009-06-17 00:41 . 2009-06-17 02:45 -------- d-----w- c:\documents and settings\Lamar\.housecall6.6 <br>2009-06-16 05:03 . 2009-03-30 15:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys <br>2009-06-16 05:03 . 2009-03-24 21:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys <br>2009-06-16 05:03 . 2009-02-13 17:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys <br>2009-06-16 05:03 . 2009-02-13 17:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys <br>2009-06-16 05:03 . 2009-06-16 05:03 -------- d-----w- c:\program files\Avira <br>2009-06-16 05:03 . 2009-06-16 05:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira <br>2009-06-16 04:47 . 2009-06-16 04:48 -------- d-----w- c:\program files\Spybot - Search & Destroy <br>2009-06-16 04:44 . 2009-06-16 04:44 30075904 ----a-w- c:\temp\avira_antivir_personal_en.exe <br>2009-06-16 04:39 . 2009-06-16 04:39 16409960 ----a-w- c:\temp\spybotsd162.exe <br><br>. <br>(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) <br>. <br>2009-06-16 04:49 . 2008-05-31 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy <br>2009-06-09 23:49 . 2008-06-03 20:48 -------- d-----w- c:\documents and settings\Lamar\Application Data\NewsBin <br>2009-06-07 15:18 . 2009-06-07 15:19 3087360 ----a-w- c:\windows\Internet Logs\xDB25.tmp <br>2009-06-07 15:18 . 2009-06-07 15:19 1887744 ----a-w- c:\windows\Internet Logs\xDB24.tmp <br>2009-06-04 14:18 . 2008-08-12 09:36 -------- d-----w- c:\documents and settings\Lamar\Application Data\dvdcss <br>2009-06-01 01:56 . 2009-02-07 03:00 -------- d-----w- c:\program files\DYMO DiscPainter <br>2009-05-30 21:16 . 2009-05-30 21:19 1884160 ----a-w- c:\windows\Internet Logs\xDB22.tmp <br>2009-05-30 21:16 . 2009-05-30 21:19 372224 ----a-w- c:\windows\Internet Logs\xDB23.tmp <br>2009-05-22 06:32 . 2008-06-05 02:24 -------- d-----w- c:\documents and settings\Lamar\Application Data\CopyToDvd <br>2009-05-22 06:24 . 2008-06-05 02:15 -------- d-----w- c:\program files\VSO <br>2009-05-12 07:34 . 2008-10-25 09:12 2595102 ----a-w- c:\windows\Internet Logs\tvDebug.zip <br>2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll <br>2009-04-29 04:56 . 2004-08-10 17:51 827392 ----a-w- c:\windows\system32\wininet.dll <br>2009-04-29 04:55 . 2004-08-10 17:51 78336 ----a-w- c:\windows\system32\ieencode.dll <br>2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys <br>2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll <br>2009-04-05 18:15 . 2009-01-12 02:48 10022 --sha-w- c:\windows\system32\KGyGaAvL.sys <br>2009-03-30 02:12 . 2009-03-30 03:09 60928 ----a-w- c:\windows\Internet Logs\xDB21.tmp <br>2009-03-30 01:50 . 2009-03-30 03:09 1833472 ----a-w- c:\windows\Internet Logs\xDB20.tmp <br>. <br><br>((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) <br>. <br>. <br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4 <br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] <br>"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032] <br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>"Zone Labs Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2005-01-26 902936] <br>"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] <br>"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-17 518488] <br>"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720] <br>"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-14 138008] <br>"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200] <br>"Omnipage"="c:\program files\ScanSoft\OmniPagePro11.0\opware32.exe" [2001-06-21 49152] <br>"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-14 142104] <br>"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-14 162584] <br>"dyaaserv.exe"="c:\program files\DYMO DiscPainter\Drivers\dyaaserv.exe" [2007-11-12 177152] <br>"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792] <br>"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-06-14 16132608] <br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] <br>@="Service" <br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center] <br>"AntiVirusOverride"=dword:00000001 <br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] <br>"DisableMonitoring"=dword:00000001 <br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] <br>"EnableFirewall"= 0 (0x0) <br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] <br>"%windir%\\system32\\sessmgr.exe"= <br>"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"= <br>"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"= <br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"= <br><br>R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/16/2009 10:09 PM 64160] <br>R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [6/3/2003 3:52 PM 123957] <br>R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [6/3/2003 3:52 PM 46900] <br>R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/16/2009 12:03 AM 108289] <br>R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1005904] <br>S3 DYUSB;DYMO DiscPainter USB Status Monitor Driver;c:\windows\system32\drivers\dyusb.sys [10/22/2007 12:07 PM 35200] <br>. <br>Contents of the 'Scheduled Tasks' folder <br><br>2009-06-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job <br>- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 03:08] <br>. <br>. <br>------- Supplementary Scan ------- <br>. <br>uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 <br>IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 <br>. <br><br>************************************************************************** <br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A> <br>Rootkit scan 2009-06-17 20:44 <br>Windows 5.1.2600 Service Pack 3 NTFS <br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ... <br><br>scan completed successfully <br>hidden files: 0 <br><br>************************************************************************** <br>. <br>Completion time: 2009-06-18 20:46 <br>ComboFix-quarantined-files.txt 2009-06-18 01:46 <br><br>Pre-Run: 57,662,877,696 bytes free <br>Post-Run: 57,822,457,856 bytes free <br><br>WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe <br>[boot loader] <br>timeout=2 <br>default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS <br>[operating systems] <br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons <br>multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect <br><br>164 --- E O F --- 2009-06-10 00:03 <br><small>--<br><b>~<A HREF="/forum/cleanup">Safe Hex</a>~<A HREF="/forum/disco"> Team Discovery</a></b> <b><A HREF="http://www.tdprojecthope.com/"> ~ Project Hope ~ </b><b><A HREF="http://www.azlyrics.com/lyrics/neilyoung/likeahurricane.html">Like A Hurricane~</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22569748</guid>
<pubDate>Wed, 17 Jun 2009 22:51:27 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22569714</link>
<description><![CDATA[<A HREF="/useremail/u/1066676"><b>gda6</b></A> : Hello The Joker,<br><br>... or is it just Hello Joker ... ?<br><br>Okay, first to answer your questions.<br><br>0.  This is my friend's computer.  So, I don't know the exact history of how it got infected.  But I'll do my best to describe the situation.<br><br>1. Why didn't Avira identify the trojan earlier?  It was configured to virus-scan the entire hard disk on demand.  For this computer, that happens infrequently.  Avira was setup to detect suspicious file reads/writes on-the-fly.  When my friend gave me his machine after being infected.  I immediately uninstaled Avira -- and re-installed the latest version.  So, the scan that I previously submitted is from the re-installed version.<br><br>2. I don't suspect that the winrar_patch.exe did something malicious.  That file has been around for about a year without any ill effects.<br><br>3. The power-quest backup for this machine is 11 months old.  It's too far out of date to use.  Therefore, I'm going to go through the "cleaning" process.  But if cleaning doesn't work -- then we'll either have to re-install windows -- or restore the 11-month-old backup.<br><br>.... okay here are the cleaning steps that I performed today.<br>A. Cleaned ALL IE files/history/cookies/passwords/etc.<br>B. Ran cleanmgr<br>C. Ran Malwarebytes.  Log file is attached: f1_mbam....txt.<br>D. Reran Hijackthis. Log file is attached: f2_hijackthis....log.<br>E. Allowes Hijackthis to remove R0 entry.<br><br>Note: at this time I enabled most of the start-up programs<br>that were being blocked by msconfig.exe.  The reason that<br>I did this is that I wanted to create a restore point.  I had turned off system restore, before posting my first hijackthis log.  So I needed to turn it back on to create a restore point.<br>I couldn't create a restore point after turning system-restore back on.  Windows told me to restart the computer.  After doing so; I still could not create a restore point.  That is why I unblocked a lot of start-up programs.  I thought maybe one of them was part of the problem.  It was not.  I still was not able to create a restore point.<br><br>... okay back to the clean-up activities ...<br><br>F. Ran Combofix. Log file is attached: f3_combo_fix....txt<br>G. Reran Hijackthis. Log file is attached: f4_hijackthis....log.<br><br>I have not tried to use the computer after these actions.<br>Combofix advises that I should not try to fix anything without advice from security forum.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22569714</guid>
<pubDate>Wed, 17 Jun 2009 22:43:51 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22564324</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi gda6<br><br>Several questions for you to start with.<br><br>Why did Avira not identify the trojans ealrier? Did you just install it, and you had no antivirus program previously installed, or did you have it disabled?<br><br>Did you see that your problem appears to likely have been from trying to illegaly bypass the registration of a program (WinRAR_Patch.exe)?<br><br>I see that you have PowerQuest Drive Image installed. It's an excellent image based backup and restore program. Although outdated (it won't work with Vista), Drive Image 7 works just fine with Windows XP, I use it myself. Have you considered restoring your system rather than disinfecting it? It would be the more secure way to go unless you don't have a current backup image, or you have upgraded to a SATA drive which the Powerquest boot disc won't recognize. If you do have a recent backup image, I would recommend a restore rather than disinfection. It's what I would do if it was my system. I would save any essential data files (do NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.rar files) more current than your backup, boot from the Powerquest restore disc, restore the system, and then after rebooting, replace the newer data files you saved. <br><br>If you don't want to or can't do that, we can proceed with disinfection.<br><br>Clean your Cache and Cookies in IE:<br>-Close all instances of Outlook Express and Internet Explorer <br>-Go to Control Panel > Internet Options > General tab<br>-Click the "Delete Cookies" button<br>-Next to it, Click the "Delete Files" button<br>-When prompted, place a check in: "Delete all offline content", click OK<br>Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):<br>Go to Tools > Options.<br>Click Privacy in the menu on the left side of the Options window.<br>Click the Clear button located to the right of each option (History, Cookies, Private Data).<br>Click OK to close the Options window<br>Alternatively, you can clear all information stored while browsing by clicking Clear All. <br>A confirmation dialog box will be shown before clearing the information.<br>Clean other Temporary files + Recycle bin<br>-Go to start > run and type: <b>cleanmgr</b> and click ok.<br>-Let it scan your system for files to remove.<br>-Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.<br>-Press OK to remove them.<br><br>Please download Malwarebytes' Anti-Malware from <br><br><textarea name="code" class="text" cols=50 rows=10>http://www.malwarebytes.org/mbam-download.php&#012;</textarea><!--end code block--><br>Double Click mbam-setup.exe to install the application.<br>- Make sure a checkmark is placed next to <b>Update Malwarebytes' Anti-Malware</b> and <b>Launch Malwarebytes' Anti-Malware</b>, then click Finish.<br>- If an update is found, it will download and install the latest version.<br>- Once the program has loaded, select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. There are some difficult to remove infections that will only be fixed if you have the Recovery Console installed.<br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Please post a new HijackThis log, the log from MBAM, the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22564324</guid>
<pubDate>Wed, 17 Jun 2009 06:00:38 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22564010</link>
<description><![CDATA[<A HREF="/useremail/u/1066676"><b>gda6</b></A> : FYI, I have attached the antivir scan, which found trojans on the initial virus scan.<br><br>Avira AntiVir Personal <br>Report file date: Monday, June 15, 2009 21:42 <br><br>Scanning for 1466500 virus strains and unwanted programs. <br><br>Licensed to: Avira AntiVir PersonalEdition Classic <br>Serial number: 0000149996-ADJIE-0001 <br>Platform: Windows XP <br>Windows version: (Service Pack 3) [5.1.2600] <br>Boot mode: Normally booted <br>Username: SYSTEM <br>Computer name: LDDVTOWER <br><br>Version information: <br>BUILD.DAT : 8.2.0.337 16934 Bytes 11/18/2008 13:05:00 <br>AVSCAN.EXE : 8.1.4.10 315649 Bytes 11/18/2008 15:21:26 <br>AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 14:56:40 <br>LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 19:44:19 <br>LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 14:58:52 <br>ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 18:30:36 <br>ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 2/11/2009 17:45:27 <br>ANTIVIR2.VDF : 7.1.4.87 2982912 Bytes 6/12/2009 02:27:03 <br>ANTIVIR3.VDF : 7.1.4.95 42496 Bytes 6/15/2009 02:27:04 <br>Engineversion : 8.2.0.187 <br>AEVDF.DLL : 8.1.1.1 106868 Bytes 6/16/2009 02:27:20 <br>AESCRIPT.DLL : 8.1.2.6 409978 Bytes 6/16/2009 02:27:19 <br>AESCN.DLL : 8.1.2.3 127347 Bytes 6/16/2009 02:27:17 <br>AERDL.DLL : 8.1.1.3 438645 Bytes 11/4/2008 20:58:38 <br>AEPACK.DLL : 8.1.3.18 401783 Bytes 6/16/2009 02:27:16 <br>AEOFFICE.DLL : 8.1.0.36 196987 Bytes 4/5/2009 17:45:42 <br>AEHEUR.DLL : 8.1.0.131 1786232 Bytes 6/16/2009 02:27:14 <br>AEHELP.DLL : 8.1.3.6 205174 Bytes 6/16/2009 02:27:09 <br>AEGEN.DLL : 8.1.1.45 348532 Bytes 6/16/2009 02:27:08 <br>AEEMU.DLL : 8.1.0.9 393588 Bytes 10/14/2008 17:05:56 <br>AECORE.DLL : 8.1.6.12 180599 Bytes 6/16/2009 02:27:06 <br>AEBB.DLL : 8.1.0.3 53618 Bytes 10/14/2008 17:05:56 <br>AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 15:40:05 <br>AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 16:28:01 <br>AVREP.DLL : 8.0.0.3 155688 Bytes 6/16/2009 02:27:05 <br>AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 18:26:40 <br>AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 15:29:23 <br>AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 19:27:49 <br>SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 00:28:02 <br>SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 19:49:40 <br>NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 19:05:10 <br>RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 20:48:07 <br>RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 20:34:37 <br><br>Configuration settings for the scan: <br>Jobname..........................: Complete system scan <br>Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp <br>Logging..........................: low <br>Primary action...................: quarantine <br>Secondary action.................: ignore <br>Scan master boot sector..........: on <br>Scan boot sector.................: on <br>Boot sectors.....................: C:, <br>Process scan.....................: on <br>Scan registry....................: on <br>Search for rootkits..............: off <br>Scan all files...................: Intelligent file selection <br>Scan archives....................: on <br>Recursion depth..................: 20 <br>Smart extensions.................: on <br>Macro heuristic..................: on <br>File heuristic...................: medium <br><br>Start of the scan: Monday, June 15, 2009 21:42 <br><br>The scan of running processes will be started <br>Scan process 'avscan.exe' - '1' Module(s) have been scanned <br>Scan process 'avcenter.exe' - '1' Module(s) have been scanned <br>Scan process 'avgnt.exe' - '1' Module(s) have been scanned <br>Scan process 'ctfmon.exe' - '1' Module(s) have been scanned <br>Scan process 'zlclient.exe' - '1' Module(s) have been scanned <br>Scan process 'explorer.exe' - '1' Module(s) have been scanned <br>Scan process 'alg.exe' - '1' Module(s) have been scanned <br>Scan process 'vsmon.exe' - '1' Module(s) have been scanned <br>Scan process 'gearsec.exe' - '1' Module(s) have been scanned <br>Scan process 'avguard.exe' - '1' Module(s) have been scanned <br>Scan process 'svchost.exe' - '1' Module(s) have been scanned <br>Scan process 'sched.exe' - '1' Module(s) have been scanned <br>Scan process 'spoolsv.exe' - '1' Module(s) have been scanned <br>Scan process 'svchost.exe' - '1' Module(s) have been scanned <br>Scan process 'svchost.exe' - '1' Module(s) have been scanned <br>Scan process 'svchost.exe' - '1' Module(s) have been scanned <br>Scan process 'svchost.exe' - '1' Module(s) have been scanned <br>Scan process 'svchost.exe' - '1' Module(s) have been scanned <br>Scan process 'lsass.exe' - '1' Module(s) have been scanned <br>Scan process 'services.exe' - '1' Module(s) have been scanned <br>Scan process 'winlogon.exe' - '1' Module(s) have been scanned <br>Scan process 'csrss.exe' - '1' Module(s) have been scanned <br>Scan process 'smss.exe' - '1' Module(s) have been scanned <br>23 processes with 23 modules were scanned <br><br>Starting master boot sector scan: <br>Master boot sector HD0 <br>[INFO] No virus was found! <br>[WARNING] System error [1381]: The maximum number of secrets that may be stored in a single system has been exceeded. <br><br>Start scanning boot sectors: <br>Boot sector 'C:\' <br>[INFO] No virus was found! <br><br>Starting to scan the registry. <br>The registry was scanned ( '54' files ). <br><br>Starting the file scan: <br><br>Begin scan in 'C:\' <br>C:\hiberfil.sys <br>[WARNING] The file could not be opened! <br>C:\hsyte12.exe <br>[DETECTION] Is the TR/Generic.1568657.1 Trojan <br>[NOTE] The file was moved to '4ab0070b.qua'! <br>C:\Iexplor490.exe <br>[DETECTION] Is the TR/Dldr.LoadAdv.Ace.39 Trojan <br>[NOTE] The file was moved to '4aaf06fd.qua'! <br>C:\pagefile.sys <br>[WARNING] The file could not be opened! <br>C:\Documents and Settings\Lamar\Local Settings\Temporary Internet Files\Content.IE5\8FA2JQ66\Setup[1].exe <br>[DETECTION] Is the TR/Downloader.Gen Trojan <br>[NOTE] The file was moved to '4aab075e.qua'! <br>C:\Program Files\WinRAR\WinRAR_Patch.exe <br>[DETECTION] Is the TR/Packed.39760 Trojan <br>[NOTE] The file was moved to '4aa5184b.qua'! <br><br>End of the scan: Monday, June 15, 2009 23:03 <br>Used time: 1:21:23 Hour(s) <br><br>The scan has been done completely. <br><br>4718 Scanning directories <br>336146 Files were scanned <br>4 viruses and/or unwanted programs were found <br>0 Files were classified as suspicious: <br>0 files were deleted <br>0 files were repaired <br>4 files were moved to quarantine <br>0 files were renamed <br>2 Files cannot be scanned <br>336140 Files not concerned <br>42968 Archives were scanned <br>3 Warnings <br>4 Notes ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22564010</guid>
<pubDate>Wed, 17 Jun 2009 01:30:49 EDT</pubDate>
</item>

<item>
<title>HJT Log IE7 Browser Gets Redirected</title>
<link>http://www.dslreports.com/forum/remark,22563951</link>
<description><![CDATA[<A HREF="/useremail/u/1066676"><b>gda6</b></A> : I am having problems with the IE7 browser.<br>If I right-click-open-in-new-window for a list<br>item within a google web search, the new window<br>is redirected to some porno or other unwanted website.<br>I have run spybot-search-destroy; adaware; avira-anivir;<br>trend-micro-online-scanner.  There were some viruses<br>detected on first anti-vir scan.  These were cleaned,<br>and all subsequent scans only find cookie threats.<br>But still, I have the browser redirecting problem.<br>Interestingly, if I click-on a list item in a google web<br>search page (requesting the clicked item opens within<br>the current window) this kind of hyper-link seems to work okay.<br><br>Any help would be greatly appreciated.<br><br>Logfile of Trend Micro HijackThis v2.0.2 <br>Scan saved at 11:26:53 PM, on 6/16/2009 <br>Platform: Windows XP SP3 (WinNT 5.01.2600) <br>MSIE: Internet Explorer v7.00 (7.00.6000.16850) <br>Boot mode: Normal <br><br>Running processes: <br>C:\WINDOWS\System32\smss.exe <br>C:\WINDOWS\system32\winlogon.exe <br>C:\WINDOWS\system32\services.exe <br>C:\WINDOWS\system32\lsass.exe <br>C:\WINDOWS\system32\svchost.exe <br>C:\WINDOWS\System32\svchost.exe <br>C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe <br>C:\WINDOWS\system32\spoolsv.exe <br>C:\Program Files\Avira\AntiVir Desktop\sched.exe <br>C:\WINDOWS\Explorer.EXE <br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe <br>C:\Program Files\Avira\AntiVir Desktop\avgnt.exe <br>C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe <br>C:\WINDOWS\system32\ctfmon.exe <br>C:\Program Files\Avira\AntiVir Desktop\avguard.exe <br>C:\WINDOWS\System32\GEARSec.exe <br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe <br>C:\Program Files\Internet Explorer\iexplore.exe <br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe <br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080529 <br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A> <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080529 <br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll <br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" <br>O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min <br>O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe <br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe <br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 <br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL <br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe <br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe <br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe <br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe <br>O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe <br>O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe <br>O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe <br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe <br>O23 - Service: V2i Protector - PowerQuest Corporation - C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe <br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe <br><br>-- <br>End of file - 4111 bytes ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22563951</guid>
<pubDate>Wed, 17 Jun 2009 01:01:18 EDT</pubDate>
</item>

</channel>
</rss>
