askey127,
Ran Combofix with no problems. I am still getting the same problems. Yahoo! search results are still being redirected in IE and FF. Google search results have no problems. Below is the log.
ComboFix 10-10-11.03 - Owner 10/12/2010 8:16.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.540 [GMT -4:00]
Running from: c:\documents and settings\Owner.Sutter\Desktop\zzz.exe
Command switches used :: c:\documents and settings\Owner.Sutter\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\system32\drivers\jdukxgpovlspg.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_REXFBZYBDLH
-------\Service_rexfbzybdlh
((((((((((((((((((((((((( Files Created from 2010-09-12 to 2010-10-12 )))))))))))))))))))))))))))))))
.
2010-10-11 15:32 . 2010-10-11 15:32 -------- d-----w- C:\rsit
2010-10-11 12:52 . 2010-10-11 12:52 -------- d-----w- c:\program files\Common Files\Adobe
2010-10-08 20:07 . 2010-10-08 20:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Boost
2010-10-08 19:59 . 2010-10-08 19:59 -------- d-----w- c:\program files\Microsoft
2010-10-08 19:59 . 2010-10-08 19:59 -------- d-----w- c:\program files\MSN Toolbar
2010-10-08 19:58 . 2010-10-08 20:00 -------- d-----w- c:\program files\MSN Toolbar Installer
2010-10-08 19:58 . 2010-10-08 19:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-10-08 19:53 . 2010-10-08 19:53 -------- d-----w- c:\documents and settings\Owner.Sutter\Application Data\ElevatedDiagnostics
2010-10-08 19:47 . 2004-08-04 02:32 231552 -c--a-w- c:\windows\system32\dllcache\ac97ali.sys
2010-10-08 19:47 . 2004-08-04 02:32 231552 ----a-w- c:\windows\system32\drivers\ac97ali.sys
2010-10-08 19:37 . 2005-12-29 03:42 634880 ------w- c:\windows\system32\stlang.dll
2010-10-08 12:46 . 2010-10-08 12:46 -------- d-----w- c:\documents and settings\Owner.Sutter\Application Data\Avira
2010-10-08 12:39 . 2010-10-08 12:39 -------- d-----w- c:\program files\Avira
2010-10-08 12:39 . 2010-10-08 12:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-10-08 12:39 . 2010-03-01 14:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-08 12:39 . 2010-02-16 18:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-08 12:39 . 2009-05-11 16:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-08 12:39 . 2009-05-11 16:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-06 03:36 . 2010-10-06 03:36 388096 ----a-r- c:\documents and settings\Owner.Sutter\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-06 02:25 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-06 02:25 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-06 00:19 . 2010-10-06 00:19 -------- d-----w- c:\windows\system32\wbem\Repository
2010-10-06 00:18 . 2010-10-06 00:18 -------- d-----w- c:\documents and settings\Owner.Sutter\Application Data\abelhadigital.com
2010-10-05 13:58 . 2010-10-06 00:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-10-05 13:57 . 2010-10-06 00:18 -------- d-----w- c:\program files\HostsMan(2)
2010-10-05 13:53 . 2010-10-06 02:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-05 03:42 . 2010-10-11 15:32 -------- d-----w- c:\program files\Trend Micro
2010-10-01 17:25 . 2010-10-01 17:25 -------- d-----w- C:\spoolerlogs
2010-10-01 01:53 . 2010-10-01 01:52 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-01 01:53 . 2010-10-01 01:52 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-10-01 01:53 . 2010-10-01 01:52 423656 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-09-30 19:47 . 2010-09-30 19:47 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-09-30 07:11 . 2010-09-30 07:11 -------- d-----w- c:\documents and settings\Owner.Sutter\Application Data\SUPERAntiSpyware.com
2010-09-30 05:54 . 2010-09-30 05:54 -------- d-----w- c:\documents and settings\Owner.Sutter\Application Data\Malwarebytes
2010-09-30 05:52 . 2010-09-30 05:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-30 05:29 . 2010-10-05 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\abelhadigital.com
2010-09-30 04:55 . 2010-09-30 04:55 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-09-30 04:53 . 2010-09-30 04:53 -------- d-----w- c:\program files\MSSOAP
2010-09-30 04:53 . 2010-09-30 04:53 -------- d-----w- c:\program files\Webroot
2010-09-30 04:02 . 2010-09-30 04:02 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-09-22 22:10 . 2010-09-22 22:10 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-09-22 22:10 . 2010-09-22 22:10 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0417.0\mswinext.exe" [2010-07-06 240480]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-26 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"RoxWatch9"=2 (0x2)
"RoxMediaDB9"=3 (0x3)
"RoxLiveShare9"=2 (0x2)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"PrismXL"=2 (0x2)
"iPod Service"=3 (0x3)
"accoca"=2 (0x2)
"acautoup"=2 (0x2)
"acachsrv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10/8/2010 8:39 AM 135336]
S3 APL531;CRS Photo Scanner;c:\windows\system32\Drivers\PS550.sys --> c:\windows\system32\Drivers\PS550.sys [?]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2/22/2010 10:56 PM 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2/22/2010 10:56 PM 30104]
S3 QuarticsWP;QuarticsWP_Display_Driver;c:\windows\system32\DRIVERS\QuarticsWP.sys --> c:\windows\system32\DRIVERS\QuarticsWP.sys [?]
S3 QuarticsWPMirror;QuarticsWPMirror_Display_Driver;c:\windows\system32\DRIVERS\QuarticsWPMirror.sys --> c:\windows\system32\DRIVERS\QuarticsWPMirror.sys [?]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [10/17/2007 11:11 PM 56448]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page =
hxxp://www.yahoo.com/Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\www.update
FF - ProfilePath - c:\documents and settings\Owner.Sutter\Application Data\Mozilla\Firefox\Profiles\uvbhgmvr.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=FF - prefs.js: browser.startup.homepage - yahoo.com
FF - prefs.js: keyword.URL -
hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4D36E769-B7A1-49B0-7FF57AC1710650DC}\{A2C50D74-0103-0472-B4B4032F319B5A49}\{CF55CBC2-03B6-AE3E-9F7994016B214C0B}*]
"JWOYTVPITEDJCHYUGDR5XL6BSC1"=hex:01,00,01,00,00,00,00,00,b1,dc,8a,ef,e5,23,43,
80,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EB668333-F612-E1D7-2FB00B30B4B4E4AA}\{D1B6E034-64F3-148A-55D2E81E9958627F}\{B02B1958-B4EC-2E2F-D228BAC73E6936F4}*]
"JWOYTVPITEDJCHYUGDR5XL6BSC1"=hex:01,00,01,00,00,00,00,00,b1,dc,8a,ef,e5,23,43,
80,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2924)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\windows\stsystra.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MICROS~3\rapimgr.exe
.
**************************************************************************
.
Completion time: 2010-10-12 08:35:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-12 12:35
ComboFix2.txt 2010-10-09 13:04
Pre-Run: 18,457,272,320 bytes free
Post-Run: 18,346,958,848 bytes free
- - End Of File - - 03DAF51E93397FCA67A92E7FC28DBE18
Thanks for all your help so far. Looking forward to your next post.
-sutman04