also @ TechSpot: Intel says Haswell will improve battery life by 50 percent

Using Firefox or IE if open Google, get redirect to Google.com.br

Discussion in 'Virus and Malware Removal' started by NutnFunny, Mar 4, 2011.

  1. NutnFunny Newcomer, in training Posts: 44

    used a different computer, my laptop with a sprint modem and downloaded rkill to a jump stick.
    Now in the first 8 steps Rkill and DDS would not let me download.
    I will also download DDS to jumpstick.

    Let me know if i should delete the existing ComboFix first before i download it again
    thanks
  2. Broni Malware Annihilator Posts: 39,397   +177

    Yes.
  3. NutnFunny Newcomer, in training Posts: 44

    Here is new ComboFix file:

    ComboFix 11-03-06.01 - admin 03/06/2011 18:45:42.3.8 - x64
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.8182.6315 [GMT -6:00]
    Running from: c:\users\admin\Desktop\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-02-07 to 2011-03-07 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-07 00:52 . 2011-03-07 00:52 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-03-06 17:02 . 2011-03-03 18:16 25048 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browserdirprovider.dll
    2011-03-06 17:02 . 2011-03-03 18:16 140248 ----a-w- c:\program files (x86)\Mozilla Firefox\components\brwsrcmp.dll
    2011-03-06 04:07 . 2011-03-06 04:07 -------- d-----w- c:\program files (x86)\Common Files\Adobe
    2011-03-06 03:59 . 2011-03-06 03:59 -------- d-----w- c:\windows\SysWow64\wbem\Logs
    2011-03-06 01:06 . 2011-03-06 01:06 -------- d-----w- C:\_OTL
    2011-03-06 00:59 . 2011-02-03 03:40 472808 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    2011-03-06 00:59 . 2011-02-03 03:40 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2011-03-06 00:58 . 2011-03-06 00:58 -------- d-----w- c:\programdata\McAfee
    2011-03-05 01:53 . 2011-03-05 01:54 -------- d-----w- c:\program files (x86)\FileBulldog Toolbar
    2011-03-05 01:53 . 2011-03-05 01:53 -------- d-----w- c:\program files (x86)\Temp File Cleaner
    2011-03-04 21:33 . 2011-02-11 07:30 7947600 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64085234-D7AC-4F4E-9D03-52AB13065D9F}\mpengine.dll
    2011-03-03 05:22 . 2011-03-03 05:22 -------- d-----w- c:\program files (x86)\ESET
    2011-03-01 13:33 . 2011-03-01 13:33 -------- d-----w- c:\program files (x86)\Common Files\Skype
    2011-03-01 04:52 . 2011-02-23 14:57 505176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-02-24 02:50 . 2011-02-24 02:50 -------- d-----w- c:\program files\iPod
    2011-02-24 02:50 . 2011-02-24 02:50 -------- d-----w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
    2011-02-24 02:50 . 2011-02-24 02:50 -------- d-----w- c:\program files\iTunes
    2011-02-24 02:42 . 2011-02-24 02:42 -------- d-----w- c:\program files\Bonjour
    2011-02-24 02:42 . 2011-02-24 02:42 -------- d-----w- c:\program files (x86)\Bonjour
    2011-02-21 23:42 . 2011-02-21 23:42 -------- d-----w- c:\users\admin\AppData\Local\Yahoo!
    2011-02-10 03:36 . 2011-01-20 16:46 900480 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2011-02-10 03:35 . 2010-10-15 14:02 4699024 ----a-w- c:\windows\system32\ntoskrnl.exe
    2011-02-10 03:35 . 2010-10-15 13:43 1168512 ----a-w- c:\windows\SysWow64\ntdll.dll
    2011-02-10 03:35 . 2010-10-15 13:43 1585168 ----a-w- c:\windows\system32\ntdll.dll
    2011-02-10 03:35 . 2011-01-08 09:03 48128 ----a-w- c:\windows\system32\atmlib.dll
    2011-02-10 03:35 . 2011-01-08 08:47 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
    2011-02-10 03:35 . 2011-01-08 06:45 367104 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-10 03:35 . 2011-01-08 06:28 292352 ----a-w- c:\windows\SysWow64\atmfd.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-02-23 15:04 . 2010-07-10 19:29 40648 ----a-w- c:\windows\avastSS.scr
    2011-02-23 15:04 . 2010-05-15 15:06 190016 ----a-w- c:\windows\SysWow64\aswBoot.exe
    2011-02-23 15:04 . 2011-01-22 16:22 238968 ----a-w- c:\windows\system32\aswBoot.exe
    2011-02-23 14:57 . 2010-05-15 15:06 280408 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-02-23 14:55 . 2010-05-15 15:06 53592 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-02-23 14:55 . 2010-05-15 15:06 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-02-23 14:55 . 2010-05-15 15:06 64344 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2011-02-23 14:54 . 2010-05-15 15:06 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-02-02 23:11 . 2010-08-22 18:32 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-01-23 00:51 . 2011-01-23 00:51 53248 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
    2010-12-28 16:08 . 2011-01-12 09:34 466944 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-28 15:55 . 2011-01-12 09:34 413696 ----a-w- c:\windows\SysWow64\odbc32.dll
    2010-12-21 00:09 . 2009-05-18 03:30 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
    2010-12-21 00:08 . 2009-10-03 22:58 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-12-14 16:15 . 2011-01-12 09:34 1251840 ----a-w- c:\windows\system32\sdclt.exe
    .
    .
    ((((((((((((((((((((((((((((( SnapShot_2011-03-06_18.17.04 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-01-21 03:20 . 2011-03-06 18:16 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-01-21 03:20 . 2011-03-07 00:54 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-01-21 03:20 . 2011-03-06 18:16 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-01-21 03:20 . 2011-03-07 00:54 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-01-21 03:20 . 2011-03-06 18:16 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-01-21 03:20 . 2011-03-07 00:54 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-01-21 02:23 . 2011-03-07 00:56 61168 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2006-11-02 15:45 . 2011-03-07 00:56 79516 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2009-05-17 18:48 . 2011-03-07 00:56 12298 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3792922179-2174670505-3486552871-1000_UserData.bin
    - 2009-05-17 18:45 . 2011-03-06 17:28 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-05-17 18:45 . 2011-03-06 22:23 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-05-17 18:45 . 2011-03-06 22:23 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-05-17 18:45 . 2011-03-06 17:28 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-05-17 18:45 . 2011-03-06 17:28 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-05-17 18:45 . 2011-03-06 22:23 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-11-26 21:14 . 2011-03-04 14:40 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-11-26 21:14 . 2011-03-06 23:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-11-26 21:14 . 2011-03-04 14:40 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-11-26 21:14 . 2011-03-06 23:05 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-11-26 21:14 . 2011-03-04 14:40 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-26 21:14 . 2011-03-06 23:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-26 21:14 . 2011-03-07 00:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-11-26 21:14 . 2011-03-06 17:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-11-26 21:14 . 2011-03-06 17:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-26 21:14 . 2011-03-07 00:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2011-03-07 00:53 . 2011-03-07 00:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2011-03-06 18:15 . 2011-03-06 18:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2011-03-07 00:53 . 2011-03-07 00:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2011-03-06 18:15 . 2011-03-06 18:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2006-11-02 12:46 . 2011-03-06 17:42 604264 c:\windows\system32\perfh009.dat
    + 2006-11-02 12:46 . 2011-03-06 23:31 604264 c:\windows\system32\perfh009.dat
    - 2006-11-02 12:46 . 2011-03-06 17:42 103964 c:\windows\system32\perfc009.dat
    + 2006-11-02 12:46 . 2011-03-06 23:31 103964 c:\windows\system32\perfc009.dat
    - 2010-04-30 05:55 . 2011-03-06 18:14 328912 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2010-04-30 05:55 . 2011-03-07 00:52 328912 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2010-05-01 04:13 . 2011-03-07 00:52 957760 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3792922179-2174670505-3486552871-1000-8192.dat
    - 2010-05-01 04:13 . 2011-03-06 18:14 957760 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3792922179-2174670505-3486552871-1000-8192.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
    "Steam"="c:\program files (x86)\steam\steam.exe" [2010-11-18 1242448]
    "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312]
    "Logitech Vid"="c:\program files (x86)\Logitech\Vid\vid.exe" [2010-05-11 6061400]
    "Logitech Vid HD"="c:\program files (x86)\Logitech\Vid\vid.exe" [2010-05-11 6061400]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-07-16 61440]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
    "nmctxth"="c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-13 642856]
    "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-08 165208]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-01-25 421160]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
    Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2009-08-29 49152]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2007-11-14 53488]
    S1 aswSnx;aswSnx; [x]
    S1 aswSP;aswSP; [x]
    S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2008-12-22 88576]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-25 202752]
    S2 aswFsBlk;aswFsBlk; [x]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
    S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-09-24 155648]
    S2 LinksysUpdater;Linksys Updater;c:\program files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe [2008-11-13 204800]
    S2 LVPrcS64;Process Monitor;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-05-08 197976]
    S2 WinFLdrv;WinFLdrv;SysWOW64\WinFLdrv.sys [x]
    S3 CompFilter64;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbflt64.sys [2010-11-10 24032]
    S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [2008-09-28 316544]
    S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [2010-05-08 30304]
    S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2010-11-10 341856]
    S3 LVUVC64;Logitech HD Pro Webcam C910(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2010-11-10 4162784]
    .
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-03-07 c:\windows\Tasks\SDMsgUpdate (SD).job
    - c:\progra~2\SMARTD~1\Messages\SDNotify.exe [2011-01-19 17:29]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2011-02-23 15:04 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2008-12-22 6931488]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.bing.com/?pc=Z045&form=ZGAPHP
    mLocal Page = %SystemRoot%\system32\blank.htm
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\caulprq5.default\
    FF - prefs.js: browser.search.selectedEngine - Bing
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:eek:fficial
    FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z045&form=ZGAADF&q=
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: Zemanta: firefox@zemanta.com - %profile%\extensions\firefox@zemanta.com
    FF - Ext: KGen: kgen@elitwork.com - %profile%\extensions\kgen@elitwork.com
    FF - Ext: TACO with Abine: optout@dubfire.net - %profile%\extensions\optout@dubfire.net
    FF - Ext: SeoQuake Plugin - Seolinx: seoquake-plugin-seolinx@seoquake.com - %profile%\extensions\seoquake-plugin-seolinx@seoquake.com
    FF - Ext: SeoQuake: {317B5128-0B0B-49b2-B2DB-1E7560E16C74} - %profile%\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
    FF - Ext: SEOpen: {ff6bdc07-eed6-4815-ad95-d7938b673ab5} - %profile%\extensions\{ff6bdc07-eed6-4815-ad95-d7938b673ab5}
    FF - user.js: yahoo.homepage.dontask - true
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-3792922179-2174670505-3486552871-1000\Software\SecuROM\License information*]
    "datasecu"=hex:5d,7a,11,54,95,f3,ed,78,68,27,50,c9,80,1c,b0,4d,56,c3,a4,bc,f8,
    4e,78,92,67,65,1d,08,5f,90,a3,cc,14,61,cb,39,d7,d1,3f,7d,5e,f3,93,38,05,c3,\
    "rkeysecu"=hex:44,08,c1,7a,cf,c3,bf,2d,ef,f6,ad,12,77,f9,0e,ed
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Alwil Software\Avast5\AvastSvc.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Bonjour\mDNSResponder.exe
    c:\program files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe
    c:\windows\SysWOW64\PnkBstrA.exe
    c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\windows\SysWOW64\java.exe
    c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
    c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
    .
    **************************************************************************
    .
    Completion time: 2011-03-06 19:04:59 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-03-07 01:04
    ComboFix2.txt 2011-03-06 18:26
    ComboFix3.txt 2011-03-05 22:57
    .
    Pre-Run: 377,477,726,208 bytes free
    Post-Run: 377,322,381,312 bytes free
    .
    - - End Of File - - EE07911224A9679D12F70E3B7B4BCD9E
  4. NutnFunny Newcomer, in training Posts: 44

    Broni,

    USA,
    Here is RKill file:

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 03/06/2011 at 19:14:36.
    Operating System: Windows (TM) Vista Home Premium


    Processes terminated by Rkill or while it was running:

    C:\Program Files\Alwil Software\Avast5\defs\11030601\Sf.bin


    Rkill completed on 03/06/2011 at 19:14:56.
  5. NutnFunny Newcomer, in training Posts: 44

    rebooted, still getting redirect to google.com.br
  6. Broni Malware Annihilator Posts: 39,397   +177

    Go Start>Run (Start search in Vista), type in:
    cmd
    Click OK (in Vista and Windows 7, while holding CTRL, and SHIFT, press Enter).

    In Command Prompt window, type in following commands, and hit Enter after each one:
    ipconfig /flushdns
    ipconfig /registerdns
    ipconfig /release
    ipconfig /renew
    net stop "dns client"
    net start "dns client"


    Turn the computer off.

    On your router, you'll find a pinhole marked "Reset".
    Keep pushing the hole, using a pencil, or a paperclip until all lights briefly come off and on.
    NOTE. Simple router disconnecting from a power source will NOT do.
    Restart computer and check for redirections.

    NOTE. You may need to re-check your router security settings, as described HERE
     
  7. NutnFunny Newcomer, in training Posts: 44

    Completed the ipconfig processes and the pc and router reboot.

    still getting redirect to google.com.br
  8. Broni Malware Annihilator Posts: 39,397   +177

  9. NutnFunny Newcomer, in training Posts: 44

    Created new user, still redirect to google.com.br
    pretty sure this is an issue with ISP, I have to have one of the cleanest pc's around.
    problem disappears when using wireless modem from sprint, no redirect, just good old google.
    So in a nut shell google has decided my IP is in Brasil, while Yahoo, MSN know my IP is USA based.
    Thank you for all your help.
    I will work with my ISP: and if no luck submit request to Google to redirect my IP to a USA standing.
    Thanks again.
    Will let you know howit works out.
  10. Broni Malware Annihilator Posts: 39,397   +177

    Keep me posted.
  11. Broni Malware Annihilator Posts: 39,397   +177

    Reopened............
  12. NutnFunny Newcomer, in training Posts: 44

    Hey Broni,
    out of town, but still redirecting google to google.com.br.
    opened an email employment response, virus ware did not pick up on email or pc.
    open to suggestions
  13. Broni Malware Annihilator Posts: 39,397   +177

    Have you had a chance to call your ISP?
  14. NutnFunny Newcomer, in training Posts: 44

    Yes, stated they would check and repair or give me a new ip if required. Same ip.
    I have not yet checked the Sprint wireless modem to see if that will relieve issue.
  15. Broni Malware Annihilator Posts: 39,397   +177

  16. NutnFunny Newcomer, in training Posts: 44

    Broni,
    did the Open DNS, flush dns etc., no luck still a redirect on Google.
    ISP is same ip, no change.

    did notice on google at address bar: about:home
  17. Broni Malware Annihilator Posts: 39,397   +177

    Which browser are we talking about here?
  18. NutnFunny Newcomer, in training Posts: 44

    firefox 4.0
  19. Broni Malware Annihilator Posts: 39,397   +177

  20. NutnFunny Newcomer, in training Posts: 44

    Removed Firefox 4.0
    Rebooted PC
    Uploaded Firefox 4.0 and installed
    Did not import bookmarks
    Did not make Default Browser

    Still Google.com.br
    wow i should have been a hacker.