Hello, I've fell victim to my web searches redirecting me to unwanted pages.
I've gone thru the 8 step virus removal steps, and the redirecting still is happening,
but my browser is loading pages faster now.
I'm using McAfee Antivirus Plus, Internet Explorer 8.
These are the logs from the 8 step process.
Thanks for any help, BigSand
==========
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5806
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/18/2011 7:41:15 PM
mbam-log-2011-02-18 (19-41-15).txt
Scan type: Quick scan
Objects scanned: 151233
Time elapsed: 8 minute(s), 14 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 42
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 31
Files Infected: 124
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\BHO.CSBHO (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\BHO.CSBHO.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometAppUtil.CometUIEvents (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometAppUtil.CometUIEvents.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometIEToolbar.CometToolbar (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometIEToolbar.CometToolbar.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometFrame (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometFrame.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometWindow (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometWindow.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.FileInfo (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.FileInfo.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.System (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.System.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.HorizontalIEBand (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.HorizontalIEBand.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.VerticalIEBand (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.VerticalIEBand.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSEngine (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSEngine.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSHost (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSHost.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.EvHandler (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.EvHandler.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSCollection (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSCollection.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPDispatch (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPDispatch.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPPacket (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPPacket.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Screensavers.com (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cc2k (Adware.Comet) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (Adware.MyWebSearch) -> Value: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (Adware.MyWebSearch) -> Value: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\program files\Comet (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Bin (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Core (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Data (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Install (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\funbutton (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\refbutton (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\relatedsearch (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\screensaver (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\webbutton (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\License (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\LogQueue (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\listeners (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Temp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Update (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\WINDOWS\pragmapaieqqpxpe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Files Infected:
c:\documents and settings\all users\favorites\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\program files\Comet\Bin\csinstall.exe (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Bin\unins.ico (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Data\csres.dat (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1bl.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1br.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1l.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1r.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1t.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1tl.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1tr.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap.html (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap.wav (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap_tb.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\azunins.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap1a.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap1b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap2a.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap2b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap3a.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap3b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\except.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\header.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\pubutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\pubutton_alert.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\pubutton_off.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\scr_adzap.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\sump.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\sys_except.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\zapometer.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\funbutton\funbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\refbutton\refbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\refbutton\refbutton.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\relatedsearch\related.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\relatedsearch\related.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\screensaver\screensaver.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared\autosrch.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared\related.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared\tbproducts.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown\smileytown.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown\smileytown.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown\smileytown.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\cars.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\flights.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\hotels.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\travel.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\travel_context.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\webbutton\webbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\band.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\cnfmgr.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\context.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\controlpanel.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\license.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\logging.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\masterconfig.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\tbmgr.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\toolbar.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\update.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\utillauncher.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\winutil.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\addremove.htm (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\addremove.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\addremove_cc.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\armask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\arskin.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\cc3.ico (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\strip.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\stripend.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\titlelabel_ar.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\title_arui.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\License\adzap.lic (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\messaging.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\settings.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\defaultbuttonmessage.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\message.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\bandmessage.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\band_bubble.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\band_bubble_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\buttonmessage.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\listeners\adzap_0001.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\listeners\travel_0001.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Temp\intro.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_adzap.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_autosearch.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_errorsearch.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_funbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_platform.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_refbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_relatedsearch.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_screensaver.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_searchassist.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_smileytown.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_travel.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_webbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Update\travelbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Update\un_travelbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\WINDOWS\pragmapaieqqpxpe\pragmacfg.ini (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\WINDOWS\pragmapaieqqpxpe\pragmasrcr.dat (Trojan.DNSChanger) -> Quarantined and deleted successfully.
====================
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-02-18 19:58:08
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 ST380011A rev.8.16
Running: pbcu7uul.exe; Driver: C:\DOCUME~1\Tom\LOCALS~1\Temp\kwloapow.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xF84A70E0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xF84A70F4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF84A7120]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF84A70CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF84A70A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF84A70B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xF84A710A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF84A714C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xF84A7136]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T1L0-17 83365422
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 83365422
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 83365422
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-f 83365422
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskST380011A_______________________________8.16____#4a35485635444656202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- EOF - GMER 1.0.15 ----
============================
I've gone thru the 8 step virus removal steps, and the redirecting still is happening,
but my browser is loading pages faster now.
I'm using McAfee Antivirus Plus, Internet Explorer 8.
These are the logs from the 8 step process.
Thanks for any help, BigSand
==========
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5806
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/18/2011 7:41:15 PM
mbam-log-2011-02-18 (19-41-15).txt
Scan type: Quick scan
Objects scanned: 151233
Time elapsed: 8 minute(s), 14 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 42
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 31
Files Infected: 124
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\BHO.CSBHO (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\BHO.CSBHO.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometAppUtil.CometUIEvents (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometAppUtil.CometUIEvents.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometIEToolbar.CometToolbar (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CometIEToolbar.CometToolbar.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometFrame (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometFrame.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometWindow (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.CometWindow.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.FileInfo (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.FileInfo.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.System (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Core.System.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.HorizontalIEBand (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.HorizontalIEBand.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.VerticalIEBand (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSBand.VerticalIEBand.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSEngine (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSEngine.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSHost (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.CSHost.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.EvHandler (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSEng.EvHandler.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSCollection (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSCollection.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPDispatch (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPDispatch.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPPacket (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CSIP.CSIPPacket.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Screensavers.com (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cc2k (Adware.Comet) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (Adware.MyWebSearch) -> Value: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (Adware.MyWebSearch) -> Value: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\program files\Comet (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Bin (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Core (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Data (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Install (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\funbutton (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\refbutton (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\relatedsearch (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\screensaver (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\webbutton (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\License (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\LogQueue (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\listeners (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Temp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Update (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\WINDOWS\pragmapaieqqpxpe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Files Infected:
c:\documents and settings\all users\favorites\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\program files\Comet\Bin\csinstall.exe (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Bin\unins.ico (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Data\csres.dat (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1bl.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1br.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1l.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1r.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1t.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1tl.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\1tr.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap.html (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap.wav (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\adzap_tb.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\azunins.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap1a.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap1b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap2a.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap2b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap3a.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\cap3b.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\except.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\header.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\pubutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\pubutton_alert.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\pubutton_off.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\scr_adzap.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\sump.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\sys_except.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\adzap\zapometer.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\funbutton\funbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\refbutton\refbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\refbutton\refbutton.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\relatedsearch\related.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\relatedsearch\related.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\screensaver\screensaver.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared\autosrch.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared\related.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Shared\tbproducts.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown\smileytown.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown\smileytown.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\smileytown\smileytown.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\cars.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\flights.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\hotels.xsl (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\travel.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\Travel\travel_context.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Products\webbutton\webbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\band.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\cnfmgr.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\context.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\controlpanel.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\license.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\logging.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\masterconfig.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\tbmgr.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\toolbar.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\update.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\utillauncher.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\winutil.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\addremove.htm (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\addremove.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\addremove_cc.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\armask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\arskin.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\cc3.ico (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\strip.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\stripend.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\titlelabel_ar.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\addremove\title_arui.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\License\adzap.lic (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\messaging.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\settings.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_left_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\1line_right_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_left_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\2line_right_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_left_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right_small.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\3line_right_small_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\defaultbuttonmessage.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\Base\message.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\bandmessage.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\band_bubble.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\band_bubble_mask.gif (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\campaigns\AdZap\buttonmessage.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\listeners\adzap_0001.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Services\messaging\listeners\travel_0001.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Temp\intro.js (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_adzap.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_autosearch.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_errorsearch.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_funbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_platform.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_refbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_relatedsearch.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_screensaver.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_searchassist.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_smileytown.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_travel.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\uninstall\un_webbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Update\travelbutton.bmp (Adware.Comet) -> Quarantined and deleted successfully.
c:\program files\Comet\Update\un_travelbutton.xml (Adware.Comet) -> Quarantined and deleted successfully.
c:\WINDOWS\pragmapaieqqpxpe\pragmacfg.ini (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\WINDOWS\pragmapaieqqpxpe\pragmasrcr.dat (Trojan.DNSChanger) -> Quarantined and deleted successfully.
====================
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-02-18 19:58:08
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 ST380011A rev.8.16
Running: pbcu7uul.exe; Driver: C:\DOCUME~1\Tom\LOCALS~1\Temp\kwloapow.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xF84A70E0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xF84A70F4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF84A7120]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF84A70CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF84A70A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF84A70B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xF84A710A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF84A714C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xF84A7136]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T1L0-17 83365422
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 83365422
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 83365422
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-f 83365422
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskST380011A_______________________________8.16____#4a35485635444656202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- EOF - GMER 1.0.15 ----
============================