chads680
2011-08-26, 06:29
This redirect is driving me nuts
I've waited for the DDS to run and produce but 20minutes later, it's not finished.
I apologize for not being the smartest guy in the room. Can someone correct me from here and I'll do my best to follow.
Once again, I apologize
Chad
DDS LOG
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_26
Run by Chad at 22:59:26 on 2011-08-27
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1033 [GMT -5:00]
.
AV: AVG Anti-Virus 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: AVG Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\NETGEAR\WN111v2\WN111V2.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\avgam.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\AVG\AVG10\avgchsvx.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [PCTools FGuard] c:\program files\pc tools security\bdt\FGuard.exe
StartupFolder: c:\docume~1\chad\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wn111v2\WN111V2.exe
mPolicies-system: DisableStatusMessages = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: mswsock.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263321903750
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} - hxxp://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{118B86EC-B03F-4B65-83C2-76FFE7EBEF3C} : DhcpNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: TPSvc - TPSvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-8-27 64512]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-8-27 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-8-27 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-8-27 656320]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 297168]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2011-8-27 233976]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-8-27 101720]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\pc tools security\bdt\BDTUpdateService.exe [2011-8-27 337872]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2151640]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2010-1-12 10384]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2003-7-24 17149]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2008-10-1 57440]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2008-1-1 279680]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [2009-1-14 458752]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys --> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\drivers\szkg.sys --> c:\windows\system32\drivers\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys --> c:\windows\system32\drivers\szkgfs.sys [?]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;"c:\program files\emsisoft anti-malware\a2service.exe" --> c:\program files\emsisoft anti-malware\a2service.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-27 136176]
S3 a2acc;a2acc;\??\c:\program files\emsisoft anti-malware\a2accx86.sys --> c:\program files\emsisoft anti-malware\a2accx86.sys [?]
S3 FXDrv32;FXDrv32;\??\e:\fxdrv32.sys --> e:\FXDrv32.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-27 136176]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2011-8-27 371472]
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2011-8-27 1117144]
.
=============== Created Last 30 ================
.
2011-08-27 23:59:46 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-08-27 22:07:39 -------- d-----w- c:\documents and settings\chad\local settings\application data\Threat Expert
2011-08-27 21:58:08 767952 ----a-w- c:\windows\BDTSupport.dll
2011-08-27 21:58:08 2029520 ----a-w- c:\windows\PCTBDCore.dll
2011-08-27 21:58:08 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-08-27 21:58:08 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-08-27 21:53:19 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-08-27 21:53:19 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-08-27 21:53:17 253096 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-08-27 21:53:10 263888 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-08-27 21:53:10 160576 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-08-27 21:53:05 233976 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-08-27 21:52:58 70664 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-08-27 21:52:50 -------- d-----w- c:\program files\PC Tools Security
2011-08-27 21:52:50 -------- d-----w- c:\program files\common files\PC Tools
2011-08-27 21:50:34 -------- d-----w- c:\documents and settings\all users\application data\PC Tools
2011-08-27 21:50:22 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-08-27 21:47:16 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-08-27 21:47:08 -------- d-----w- c:\program files\Lavasoft
2011-08-27 21:18:37 -------- d--h--w- C:\$AVG
2011-08-27 05:09:33 64512 -c--a-w- c:\windows\system32\dllcache\serial.sys
2011-08-27 05:09:33 64512 ----a-w- c:\windows\system32\drivers\serial.sys
2011-08-27 04:59:08 -------- d-----w- c:\program files\AVAST Software
2011-08-27 04:59:08 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2011-08-27 04:23:08 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-08-27 04:17:32 -------- d-----w- C:\119c99617a9516560b58
2011-08-27 04:17:29 -------- d-----w- C:\a31408ff4fdcf3ee17a024ec
2011-08-27 04:08:41 -------- d-----w- c:\documents and settings\chad\application data\Bandoo
2011-08-27 04:08:34 -------- d-----w- c:\documents and settings\chad\local settings\application data\Ilivid Player
2011-08-27 04:06:52 -------- dc-h--w- c:\documents and settings\all users\application data\{94D867E5-DFF5-4374-ADEE-C3F5BE97F03A}
2011-08-26 04:35:26 -------- d-----w- c:\documents and settings\chad\local settings\application data\Ashampoo
2011-08-26 04:01:00 -------- d-----w- c:\documents and settings\chad\application data\Malwarebytes
2011-08-26 04:00:54 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-08-26 02:56:54 -------- d-----w- c:\documents and settings\all users\application data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-08-26 02:53:45 -------- d-----w- c:\documents and settings\chad\application data\Uniblue
2011-08-26 02:53:43 -------- d-----w- c:\program files\Uniblue
2011-08-26 02:53:31 -------- d-----w- c:\documents and settings\chad\local settings\application data\PackageAware
2011-08-26 02:28:42 -------- d-----w- c:\program files\Frontline Registry Cleaner
2011-08-26 02:26:41 -------- d-----w- c:\windows\system32\XPSViewer
2011-08-26 02:26:25 28160 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-08-26 02:26:01 14048 ------w- c:\windows\system32\spmsg2.dll
2011-08-25 22:54:34 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-08-22 04:46:37 -------- d-----w- c:\program files\RegScrubXP
2011-08-20 14:54:29 -------- d-----w- c:\program files\MSXML 4.0
2011-08-20 14:47:10 -------- d-----w- c:\documents and settings\all users\application data\IObit
2011-08-20 14:45:01 -------- d-----w- c:\documents and settings\chad\application data\IObit
2011-08-20 14:45:00 -------- d-----w- c:\program files\IObit
2011-08-18 17:35:57 -------- d-----w- c:\documents and settings\all users\application data\Tarma Installer
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-08-17 02:29:18 -------- d-----w- c:\documents and settings\chad\application data\AVG
2011-08-17 02:16:03 -------- d-----w- c:\documents and settings\all users\application data\STOPzilla!
2011-08-16 01:37:44 -------- d-----w- c:\program files\iPod
2011-08-16 01:37:42 -------- d-----w- c:\program files\iTunes
2011-08-16 01:37:42 -------- d-----w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-08-10 00:35:22 -------- d-----w- c:\documents and settings\chad\application data\AVG10
2011-08-10 00:33:38 -------- d-----w- c:\windows\system32\drivers\AVG
2011-08-10 00:33:38 -------- d-----w- c:\documents and settings\all users\application data\AVG10
2011-08-10 00:22:55 -------- d--h--w- c:\documents and settings\all users\application data\Common Files
2011-08-10 00:22:46 -------- d-----w- c:\documents and settings\all users\application data\MFAData
2011-08-09 19:21:20 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-09 19:20:58 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
.
==================== Find3M ====================
.
2011-08-16 01:27:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 23:37:00 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 23:37:00 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2006-05-03 17:06:54 163328 --sha-w- c:\windows\system32\flvDX.dll
.
============= FINISH: 23:00:07.12 ===============
Attached is my zip folder
Thanks
Spybot does not detect anything that it cannot delete/fix. Problem is I still have the redirect. I've switched from IE8 to Firefox to Chrome and I still get the same redirect. I've bought AVG and run Spyware Dr free edition. Spyware Dr notices a registry entry of LEGACY_CATCHME and I can't delete it or remove it.
I've waited for the DDS to run and produce but 20minutes later, it's not finished.
I apologize for not being the smartest guy in the room. Can someone correct me from here and I'll do my best to follow.
Once again, I apologize
Chad
DDS LOG
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_26
Run by Chad at 22:59:26 on 2011-08-27
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1033 [GMT -5:00]
.
AV: AVG Anti-Virus 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: AVG Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\NETGEAR\WN111v2\WN111V2.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\avgam.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\AVG\AVG10\avgchsvx.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [PCTools FGuard] c:\program files\pc tools security\bdt\FGuard.exe
StartupFolder: c:\docume~1\chad\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wn111v2\WN111V2.exe
mPolicies-system: DisableStatusMessages = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: mswsock.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263321903750
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} - hxxp://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{118B86EC-B03F-4B65-83C2-76FFE7EBEF3C} : DhcpNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: TPSvc - TPSvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-8-27 64512]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-8-27 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-8-27 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-8-27 656320]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 297168]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2011-8-27 233976]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-8-27 101720]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\pc tools security\bdt\BDTUpdateService.exe [2011-8-27 337872]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2151640]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2010-1-12 10384]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2003-7-24 17149]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2008-10-1 57440]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2008-1-1 279680]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [2009-1-14 458752]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys --> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\drivers\szkg.sys --> c:\windows\system32\drivers\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys --> c:\windows\system32\drivers\szkgfs.sys [?]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;"c:\program files\emsisoft anti-malware\a2service.exe" --> c:\program files\emsisoft anti-malware\a2service.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-27 136176]
S3 a2acc;a2acc;\??\c:\program files\emsisoft anti-malware\a2accx86.sys --> c:\program files\emsisoft anti-malware\a2accx86.sys [?]
S3 FXDrv32;FXDrv32;\??\e:\fxdrv32.sys --> e:\FXDrv32.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-27 136176]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2011-8-27 371472]
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2011-8-27 1117144]
.
=============== Created Last 30 ================
.
2011-08-27 23:59:46 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-08-27 22:07:39 -------- d-----w- c:\documents and settings\chad\local settings\application data\Threat Expert
2011-08-27 21:58:08 767952 ----a-w- c:\windows\BDTSupport.dll
2011-08-27 21:58:08 2029520 ----a-w- c:\windows\PCTBDCore.dll
2011-08-27 21:58:08 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-08-27 21:58:08 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-08-27 21:53:19 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-08-27 21:53:19 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-08-27 21:53:17 253096 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-08-27 21:53:10 263888 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-08-27 21:53:10 160576 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-08-27 21:53:05 233976 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-08-27 21:52:58 70664 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-08-27 21:52:50 -------- d-----w- c:\program files\PC Tools Security
2011-08-27 21:52:50 -------- d-----w- c:\program files\common files\PC Tools
2011-08-27 21:50:34 -------- d-----w- c:\documents and settings\all users\application data\PC Tools
2011-08-27 21:50:22 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-08-27 21:47:16 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-08-27 21:47:08 -------- d-----w- c:\program files\Lavasoft
2011-08-27 21:18:37 -------- d--h--w- C:\$AVG
2011-08-27 05:09:33 64512 -c--a-w- c:\windows\system32\dllcache\serial.sys
2011-08-27 05:09:33 64512 ----a-w- c:\windows\system32\drivers\serial.sys
2011-08-27 04:59:08 -------- d-----w- c:\program files\AVAST Software
2011-08-27 04:59:08 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2011-08-27 04:23:08 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-08-27 04:17:32 -------- d-----w- C:\119c99617a9516560b58
2011-08-27 04:17:29 -------- d-----w- C:\a31408ff4fdcf3ee17a024ec
2011-08-27 04:08:41 -------- d-----w- c:\documents and settings\chad\application data\Bandoo
2011-08-27 04:08:34 -------- d-----w- c:\documents and settings\chad\local settings\application data\Ilivid Player
2011-08-27 04:06:52 -------- dc-h--w- c:\documents and settings\all users\application data\{94D867E5-DFF5-4374-ADEE-C3F5BE97F03A}
2011-08-26 04:35:26 -------- d-----w- c:\documents and settings\chad\local settings\application data\Ashampoo
2011-08-26 04:01:00 -------- d-----w- c:\documents and settings\chad\application data\Malwarebytes
2011-08-26 04:00:54 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-08-26 02:56:54 -------- d-----w- c:\documents and settings\all users\application data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-08-26 02:53:45 -------- d-----w- c:\documents and settings\chad\application data\Uniblue
2011-08-26 02:53:43 -------- d-----w- c:\program files\Uniblue
2011-08-26 02:53:31 -------- d-----w- c:\documents and settings\chad\local settings\application data\PackageAware
2011-08-26 02:28:42 -------- d-----w- c:\program files\Frontline Registry Cleaner
2011-08-26 02:26:41 -------- d-----w- c:\windows\system32\XPSViewer
2011-08-26 02:26:25 28160 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-08-26 02:26:01 14048 ------w- c:\windows\system32\spmsg2.dll
2011-08-25 22:54:34 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-08-22 04:46:37 -------- d-----w- c:\program files\RegScrubXP
2011-08-20 14:54:29 -------- d-----w- c:\program files\MSXML 4.0
2011-08-20 14:47:10 -------- d-----w- c:\documents and settings\all users\application data\IObit
2011-08-20 14:45:01 -------- d-----w- c:\documents and settings\chad\application data\IObit
2011-08-20 14:45:00 -------- d-----w- c:\program files\IObit
2011-08-18 17:35:57 -------- d-----w- c:\documents and settings\all users\application data\Tarma Installer
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-08-17 17:07:05 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-08-17 02:29:18 -------- d-----w- c:\documents and settings\chad\application data\AVG
2011-08-17 02:16:03 -------- d-----w- c:\documents and settings\all users\application data\STOPzilla!
2011-08-16 01:37:44 -------- d-----w- c:\program files\iPod
2011-08-16 01:37:42 -------- d-----w- c:\program files\iTunes
2011-08-16 01:37:42 -------- d-----w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-08-10 00:35:22 -------- d-----w- c:\documents and settings\chad\application data\AVG10
2011-08-10 00:33:38 -------- d-----w- c:\windows\system32\drivers\AVG
2011-08-10 00:33:38 -------- d-----w- c:\documents and settings\all users\application data\AVG10
2011-08-10 00:22:55 -------- d--h--w- c:\documents and settings\all users\application data\Common Files
2011-08-10 00:22:46 -------- d-----w- c:\documents and settings\all users\application data\MFAData
2011-08-09 19:21:20 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-09 19:20:58 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
.
==================== Find3M ====================
.
2011-08-16 01:27:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 23:37:00 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 23:37:00 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2006-05-03 17:06:54 163328 --sha-w- c:\windows\system32\flvDX.dll
.
============= FINISH: 23:00:07.12 ===============
Attached is my zip folder
Thanks
Spybot does not detect anything that it cannot delete/fix. Problem is I still have the redirect. I've switched from IE8 to Firefox to Chrome and I still get the same redirect. I've bought AVG and run Spyware Dr free edition. Spyware Dr notices a registry entry of LEGACY_CATCHME and I can't delete it or remove it.