📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Google redirecting

Options
12346

Comments

  • Nick42_2
    Nick42_2 Posts: 65 Forumite

    Supplementary Scan
    .
    uStart Page = hxxp://xxx.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
    IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
    IE: Lookup on Merriam Webster - [URL]file://c:\program[/URL] files\ieSpell\Merriam Webster.HTM
    IE: Lookup on Wikipedia - [URL]file://c:\program[/URL] files\ieSpell\wikipedia.HTM
    DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab?1271050377000
    .
    - - - - ORPHANS REMOVED - - - -
    Toolbar-Locked - (no file)
    WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)

    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://xxx.gmer.net
    Rootkit scan 2010-06-23 22:00
    Windows 5.1.2600 Service Pack 3, v.3311 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    DLLs Loaded Under Running Processes
    - - - - - - - > 'winlogon.exe'(1416)
    c:\windows\system32\netprovcredman.dll
    c:\windows\system32\igfxdev.dll
    .
    Completion time: 2010-06-23 22:02:51
    ComboFix-quarantined-files.txt 2010-06-23 21:02
    Pre-Run: 86,159,491,072 bytes free
    Post-Run: 86,125,981,696 bytes free
    - - End Of File - - 6809CB84D7757E3327405BB9DDB8E24A
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Open notepad and copy/paste the text in RED below

    File::
    c:\windows\system32\firewallp.dll


    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

    CFScript.gif


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.

    ..........................................................................
    Ive noticed a 'facebook plugin'
    Would you say the troubles started after that was installed?

    :idea:
  • Nick42_2
    Nick42_2 Posts: 65 Forumite
    Its not me who uses facebook so not sure when that was installed,or what it is!

    Timings could have been right for the problem - is this a known issue?

    Does the combofix log show a problem, or one dealt with?

    Will try your advice.

    It is hard to know if problem is resolved as it comes and goes.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Facebooks well known for its dodgy apps, so theres every chance
    :idea:
  • Nick42_2
    Nick42_2 Posts: 65 Forumite
    thought I had uninstalled AVG????

    Here is updated log as requested:

    ComboFix 10-06-23.03 - user1 24/06/2010 15:13:24.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1014.490 [GMT 1:00]
    Running from: c:\documents and settings\user1\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\user1\Desktop\CFScript.txt
    AV: avast! Internet Security *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: avast! Internet Security *disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ((((((((((((((((((((((((( Files Created from 2010-05-24 to 2010-06-24 )))))))))))))))))))))))))))))))
    .
    2010-06-24 05:51 . 2010-06-24 05:51
    d
    w- c:\windows\LastGood
    2010-06-22 06:43 . 2010-06-22 06:44
    d
    w- C:\9bb173bfb99b51356307babc
    2010-06-15 17:33 . 2001-08-17 13:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
    2010-06-15 17:33 . 2008-02-12 03:04 2188928 -c--a-w- c:\windows\system32\dllcache\ntoskrnl.exe
    2010-06-15 17:21 . 2010-06-15 17:21
    d
    w- c:\documents and settings\user1\Application Data\GlarySoft
    2010-06-15 17:15 . 2010-06-15 17:15
    d
    w- c:\program files\Glary Utilities
    2010-06-14 20:56 . 2010-06-14 20:56
    d
    w- c:\program files\iPod
    2010-06-14 20:56 . 2010-06-14 20:57
    d
    w- c:\program files\iTunes
    2010-06-14 20:56 . 2010-06-14 20:57
    d
    w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    2010-06-14 20:45 . 2010-06-14 20:47
    d
    w- c:\program files\QuickTime
    2010-06-14 20:32 . 2010-06-14 20:32
    d
    w- c:\program files\Bonjour
    2010-06-14 13:02 . 2010-06-14 13:02
    d-sh--w- c:\documents and settings\NetworkService\IETldCache
    2010-06-14 10:35 . 2010-06-14 10:35
    d
    w- c:\program files\Trend Micro
    2010-06-14 09:38 . 2010-06-14 09:38
    d
    w- c:\documents and settings\user1\Local Settings\Application Data\Threat Expert
    2010-06-13 13:31 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2010-06-13 13:31 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2010-06-13 13:31 . 2010-05-06 20:41 307280 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2010-06-13 13:31 . 2010-05-06 20:41 99280 ----a-w- c:\windows\system32\drivers\aswFW.sys
    2010-06-13 13:30 . 2010-05-06 20:40 190416 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
    2010-06-13 13:30 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2010-06-13 13:30 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2010-06-13 13:30 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2010-06-13 13:30 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2010-06-13 13:30 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2010-06-13 13:29 . 2010-03-19 19:10 12112 ----a-w- c:\windows\system32\drivers\aswNdis.sys
    2010-06-13 13:29 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
    2010-06-13 13:29 . 2010-04-14 16:47 38848 ----a-w- c:\windows\system32\avastSS.scr
    2010-06-13 13:29 . 2010-06-13 13:29
    d
    w- c:\program files\Alwil Software
    2010-06-13 13:29 . 2010-06-13 13:29
    d
    w- c:\documents and settings\All Users\Application Data\Alwil Software
    2010-06-13 12:28 . 2010-06-13 12:28 63488 ----a-w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
    2010-06-13 12:28 . 2010-06-13 12:28 52224 ----a-w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-06-13 12:28 . 2010-06-13 12:28 117760 ----a-w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-06-13 12:26 . 2010-06-13 12:26
    d
    w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com
  • Nick42_2
    Nick42_2 Posts: 65 Forumite
    2010-06-13 12:28 . 2010-06-13 12:28 63488 ----a-w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
    2010-06-13 12:28 . 2010-06-13 12:28 52224 ----a-w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-06-13 12:28 . 2010-06-13 12:28 117760 ----a-w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-06-13 12:26 . 2010-06-13 12:26
    d
    w- c:\documents and settings\user1\Application Data\SUPERAntiSpyware.com
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-06-24 05:51 . 2010-06-24 05:51 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
    2010-06-23 18:23 . 2009-07-11 14:49
    d
    w- c:\documents and settings\All Users\Application Data\Google Updater
    2010-06-23 13:32 . 2009-01-28 16:50
    d
    w- c:\documents and settings\All Users\Application Data\CanonIJPLM
    2010-06-14 20:56 . 2009-11-24 22:15
    d
    w- c:\program files\Common Files\Apple
    2010-06-14 20:40 . 2008-10-10 17:10
    d
    w- c:\program files\Apple Software Update
    2010-06-14 20:18 . 2008-10-11 20:15
    d
    w- c:\program files\CCleaner
    2010-06-14 13:46 . 2009-04-29 13:09
    d
    w- c:\program files\Spyware Doctor
    2010-06-14 13:44 . 2009-04-29 13:09
    d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-06-14 13:21 . 2009-10-28 22:13
    d
    w- c:\program files\Spybot - Search & Destroy
    2010-06-14 13:21 . 2009-10-28 22:13
    d
    w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-06-14 09:42 . 2010-04-11 21:38
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2010-06-08 13:17 . 2009-11-24 20:37
    d
    w- c:\program files\Windows Live Safety Center
    2010-06-08 08:06 . 2010-04-11 07:13 439816 ----a-w- c:\documents and settings\user1\Application Data\Real\Update\setup3.10\setup.exe
    2010-06-05 19:22 . 2009-02-17 09:51
    d
    w- c:\program files\Microsoft Silverlight
    2010-05-24 15:21 . 2010-05-24 15:21 69120 --sha-r- c:\windows\system32\firewallp.dll
    2010-05-21 13:14 . 2010-03-13 20:21 221568
    w- c:\windows\system32\MpSigStub.exe
    2010-05-16 18:22 . 2009-07-11 14:49
    d
    w- c:\program files\Google
    2010-05-12 13:26 . 2010-05-12 13:21
    d
    w- c:\program files\Common Files\Adobe
    2010-04-29 14:39 . 2010-04-11 21:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-29 14:39 . 2010-04-11 21:38 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-04-25 17:35 . 2009-09-22 19:28
    d
    w- c:\program files\Common Files\Adobe AIR
    2010-04-25 17:35 . 2010-06-14 21:31 38784 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\xxx.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-04-25 17:35 . 2009-09-22 19:31 38784 ----a-w- c:\documents and settings\user1\Application Data\Macromedia\Flash Player\xxx.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-04-24 17:33 . 2010-04-24 17:33 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.11\SetupAdmin.exe
    2010-04-12 05:33 . 2010-04-12 05:33 50354 ----a-w- c:\documents and settings\user1\Application Data\Facebook\uninstall.exe
    2010-04-12 05:33 . 2010-04-12 05:33 2114184 ----a-w- c:\documents and settings\user1\Application Data\Facebook\Install_Facebook_Plug-In_1.0.3.exe
    2010-04-08 22:01 . 2009-10-20 19:57 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-04-08 12:20 . 2010-04-08 12:20 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-04-08 12:20 . 2010-04-08 12:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
    .
    ((((((((((((((((((((((((((((( [EMAIL="SnapShot@2010-06-23_21.00.18"]SnapShot@2010-06-23_21.00.18[/EMAIL] )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-06-24 05:23 . 2010-06-24 05:23 16384 c:\windows\Temp\Perflib_Perfdata_a6c.dat
    + 2007-06-18 19:18 . 2007-06-18 19:18 23680 c:\windows\system32\drivers\motmodem.sys
    + 2006-11-13 19:45 . 2006-11-13 19:45 1419232 c:\windows\system32\wdfcoinstaller01005.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
  • Nick42_2
    Nick42_2 Posts: 65 Forumite
    REGEDIT4
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
    @="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
    [HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
    2010-05-06 21:02 151648 ----a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-11 39408]
    "FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-03-03 155648]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-30 138008]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-30 162584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-30 138008]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-20 149280]
    "CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
    "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-17 1848648]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
    "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
    c:\documents and settings\user1\Start Menu\Programs\Startup\
    Memeo AutoBackup Launcher.lnk - c:\program files\Memeo\AutoBackup\MemeoLauncher.exe [2007-1-9 199704]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [6/13/2010 2:29 PM 12112]
    R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [6/13/2010 2:30 PM 190416]
    R0 sonypvl2;sonypvl2;c:\windows\system32\drivers\sonypvl2.sys [7/4/2009 6:28 PM 19478]
    R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [6/13/2010 2:31 PM 99280]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [6/13/2010 2:31 PM 307280]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6/13/2010 2:31 PM 164048]
    R1 sonypvf2;sonypvf2;c:\windows\system32\drivers\sonypvf2.sys [7/4/2009 6:28 PM 635012]
    R1 sonypvt2;sonypvt2;c:\windows\system32\drivers\sonypvt2.sys [7/4/2009 6:28 PM 431236]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/13/2010 2:31 PM 19024]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
    S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [6/13/2010 2:29 PM 119200]
    S2 gupdate1ca02372d73c8a0;Google Update Service (gupdate1ca02372d73c8a0);c:\program files\Google\Update\GoogleUpdate.exe [7/11/2009 3:52 PM 133104]
    S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [10/10/2008 12:08 PM 20160]
    S3 DrmRAudio;DrmRAudio;c:\windows\system32\drivers\DrmRAudio.sys [11/23/2009 11:58 PM 23096]
    S3 TfBulk;TfBulk;c:\windows\system32\drivers\TfBulk.SYS [5/31/2007 10:11 PM 13312]
    S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [11/23/2009 9:28 AM 25704]
    S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [11/23/2009 9:28 AM 25704]
    S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [11/23/2009 9:29 AM 25704]
    S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [11/23/2009 9:29 AM 25704]
    S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [11/23/2009 9:29 AM 25704]
    .
    Contents of the 'Scheduled Tasks' folder
    2010-06-14 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
    2010-06-24 c:\windows\Tasks\GlaryInitialize.job
    - c:\program files\Glary Utilities\initialize.exe [2010-06-15 09:01]
    2010-06-24 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-11 14:49]
    2010-06-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 14:52]
    2010-06-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 14:52]
    2010-06-24 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
    2010-06-23 c:\windows\Tasks\User_Feed_Synchronization-{E9BB3528-F175-4F8A-9845-5FB44061DADE}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://xxx.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
    IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
    IE: Lookup on Merriam Webster - [URL]file://c:\program[/URL] files\ieSpell\Merriam Webster.HTM
    IE: Lookup on Wikipedia - [URL]file://c:\program[/URL] files\ieSpell\wikipedia.HTM
    DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab?1271050377000
    .
    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://xxx.gmer.net
    Rootkit scan 2010-06-24 15:28
    Windows 5.1.2600 Service Pack 3, v.3311 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    DLLs Loaded Under Running Processes
    - - - - - - - > 'winlogon.exe'(1424)
    c:\windows\system32\netprovcredman.dll
    c:\windows\system32\igfxdev.dll
    - - - - - - - > 'explorer.exe'(4060)
    c:\windows\system32\ieframe.dll
    c:\windows\system32\dot3dlg.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2010-06-24 15:31:03
    ComboFix-quarantined-files.txt 2010-06-24 14:31
    ComboFix2.txt 2010-06-23 21:02
    Pre-Run: 86,025,719,808 bytes free
    Post-Run: 86,014,455,808 bytes free
    - - End Of File - - AAB4349FD133CE52F2B7A07257F8E3C1
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Use the 32 bit AVG removal tool
    http://www.avg.com/download-tools
    :idea:
  • Nick42_2
    Nick42_2 Posts: 65 Forumite
    Thanks,

    How did that last log look?

    Out of interest why redo it was CScript?

    Do I need to do anything about that facebook thing you mentioned?


    What do you recommend keeping out of all the spyware/virus/etc stuff?

    Appreciate your help.
  • Nick42_2
    Nick42_2 Posts: 65 Forumite
    aliEnRIK wrote: »
    Use the 32 bit AVG removal tool
    http://www.avg.com/download-tools


    thought had already done that!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.1K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.1K Work, Benefits & Business
  • 599.1K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.