Cheweys Browser Redirect Issue

Cheweybacca

New member
Hi,

Since Feb 2012 i have noticed certain google search links redirecting me to miscellaneous advertising sites. It appears to happen randomly so i suspect some gremlins are onboard. I use Chrome.

I attach logs etc

Many thanks in advance for any help,
Chewey

DDS log
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11
Run by Gerry at 19:30:46 on 2012-05-09
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1284 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Endpoint Security Client Firewall *Enabled*
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Checkpoint\Endpoint Security\EapConnMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Program Files\Common Files\Check Point\UIFramework\cptray.exe
C:\Program Files\Checkpoint\Endpoint Security\Endpoint Connect\TrGUI.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Checkpoint\Endpoint Security\Endpoint Connect\TracSrvWrapper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Checkpoint\Endpoint Security\IClient.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Documents and Settings\Gerry\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Gerry\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Gerry\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Gerry\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Gerry\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Gerry\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ie/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {7232f4e2-2037-4077-bc83-70aa43f09565} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\gerry\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [TrueCrypt] "c:\program files\truecrypt\TrueCrypt.exe" /q preferences /a logon
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Check Point Endpoint Tray Application] c:\program files\common files\check point\uiframework\cptray.exe
mRun: [Check Point Endpoint Connect] "c:\program files\checkpoint\endpoint security\endpoint connect\TrGUI.exe"
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\gerry\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\gerry\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\gerry\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ciscos~1.lnk - c:\program files\cisco systems\vpn client\vpngui.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc2~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpobnz08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: Video Poker - hxxp://download2.games.yahoo.com/games/clients/y/vpt0_x.cab
DPF: Yahoo! Poker - hxxp://download.games.yahoo.com/games/clients/y/pt3_x.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
DPF: {1230CB21-C88D-11CF-B347-000000000000}
DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} - hxxp://community.webshots.com/html/atx/wsaxcontrol.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://213.94.214.30/vdesk/terminal/f5tunsrv.cab#version=6031,2009,1204,1610
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://213.94.214.30/vdesk/terminal/InstallerControl.cab#version=6031,2009,1204,1613
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab
DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} - hxxps://213.94.214.30/vdesk/terminal/f5InspectionHost.cab#version=6031,2009,1204,1603
DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} - hxxps://213.94.214.30/vdesk/terminal/urTermProxy.cab#version=6020,2008,0514,2337
DPF: {7584c670-2274-4efb-b00b-d6aaba6d3850} - hxxps://213.94.214.30/vdesk/terminal/msrdp.cab#version=5,2,3790,0
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} - hxxp://static.photobox.co.uk/sg/common/uploader_uni.cab
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://213.94.214.30/vdesk/terminal/urxhost.cab#version=6031,2009,1204,1604
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} - hxxps://213.94.214.30/policy/download_binary.php/win32/f5syschk.cab#Version=6031,2010,0125,2111
DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - hxxp://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
TCP: Interfaces\{92E1B20F-0BA1-4722-B920-4CE8C48534CD} : DhcpNameServer = 192.168.1.1
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Notify: igfxcui - igfxsrvc.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32592]
R0 DiMaint;Eicon Maintenance Driver;c:\windows\system32\drivers\disdn\dimaint.sys [2002-12-4 91408]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 295248]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2010-1-18 470920]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 DiCapi;Eicon CAPI 2.0 Driver;c:\windows\system32\drivers\disdn\capi202k.sys [2001-6-12 181168]
R2 DiPort;Eicon Port Driver;c:\windows\system32\drivers\disdn\diport40.sys [2002-10-16 206976]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2010-11-27 398176]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 16720]
R3 DiWan;Eicon Driver for all Diva Client cards;c:\windows\system32\drivers\disdn\Diwan.sys [2002-10-3 911920]
R3 TracSrvWrapper;Check Point Endpoint Connect;c:\program files\checkpoint\endpoint security\endpoint connect\TracSrvWrapper.exe [2010-5-9 3511824]
R3 vna_ap;Check Point Virtual Network Adapter - Apollo;c:\windows\system32\drivers\vnaap.sys [2010-5-9 129304]
S2 gupdate1c9f4b5549515e;Google Update Service (gupdate1c9f4b5549515e);c:\program files\google\update\GoogleUpdate.exe [2009-6-24 133104]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-19 257696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-6-24 133104]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2002-8-29 14336]
S3 NuVision;Hauppauge WinTV USB Pro (PAL I,D/K);c:\windows\system32\drivers\NUVision.sys [2008-2-13 260144]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 BCSWAP;BCSWAP;c:\windows\system32\drivers\BCSwap.sys [2007-1-25 91496]
.
=============== Created Last 30 ================
.
2012-04-19 17:51:09 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-18 15:36:13 -------- d-----w- c:\documents and settings\gerry\application data\Dropbox
.
==================== Find3M ====================
.
2012-05-09 07:51:31 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-11 13:12:06 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 13:10:58 2192640 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 12:35:52 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-06 18:43:20 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-06 18:43:20 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-01 01:25:04 832512 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 01:25:03 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-03-01 01:25:03 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-03-01 01:25:03 17408 ----a-w- c:\windows\system32\corpol.dll
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-16 00:55:32 12872 ----a-w- c:\windows\system32\bootdelete.exe
2012-02-15 11:01:50 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-15 11:01:50 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2003-09-01 12:56:26 235988 ----a-w- c:\program files\Logo - accounting1.exe
2003-08-29 21:06:45 16251072 ----a-w- c:\program files\AdbeRdr60_enu_full.exe
.
============= FINISH: 19:32:17.82 ===============
 
ok. Lets start with tdsskiller for now then go on from there. Actually you can get two downloads, first tdsskiller then the free version of malwarebytes which you can keep and use as a antimalware app.
Use tdsskiller first followed by malwarebytes.

1) Please download TDSS Killer.exe and save it to your desktop
Double click to launch the utility. After it initializes click the start scan button.

Once the scan completes you can click the continue button.

"The utility will automatically select an action (Cure or Delete) for known malcious objects. A suspicious object will be skipped by default."

"After clicking Next, the utility applies selected actions and outputs the result."

"A reboot might require after disinfection."

A report will be found in your Root drive Local Disk (C) as: TDSSKiller.2.7.9.0_05.02.2012_17.32.21_log (name, version#, date, time)
Please post the log report

2) Please download the free version of Malwarebytes to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.

Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click *Remove Selected.*

*A restart of your computer may be required to remove some items. If prompted please restart your computer to complete the fix.*

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Post the log in your reply.

After you run both, cruise around and see what the redirection looks like.
 
Ok Shelf-life,
I'll download those and follow your instructions :thanks:

I'm away for a few days so wont be back to my home machine until next Monday so i'll update this thread then.

Cheers !
Chewey
 
Hi, i'm back again.

First here is the TDSSkiller log. It only ran for a few seconds and appears to have found no threats.


09:55:48.0500 3112 TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
09:55:48.0937 3112 ============================================================
09:55:48.0937 3112 Current date / time: 2012/05/22 09:55:48.0937
09:55:48.0937 3112 SystemInfo:
09:55:48.0937 3112
09:55:48.0937 3112 OS Version: 5.1.2600 ServicePack: 3.0
09:55:48.0937 3112 Product type: Workstation
09:55:48.0937 3112 ComputerName: BRIDS_DELL
09:55:48.0937 3112 UserName: Gerry
09:55:48.0937 3112 Windows directory: C:\WINDOWS
09:55:48.0937 3112 System windows directory: C:\WINDOWS
09:55:48.0937 3112 Processor architecture: Intel x86
09:55:48.0937 3112 Number of processors: 1
09:55:48.0937 3112 Page size: 0x1000
09:55:48.0937 3112 Boot type: Normal boot
09:55:48.0937 3112 ============================================================
09:55:51.0890 3112 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
09:55:51.0890 3112 ============================================================
09:55:51.0890 3112 \Device\Harddisk0\DR0:
09:55:51.0890 3112 MBR partitions:
09:55:51.0890 3112 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xFB04, BlocksNum 0x94EEEB9
09:55:51.0890 3112 ============================================================
09:55:51.0906 3112 Initialize success
09:55:51.0906 3112 ============================================================
09:56:04.0703 3396 ============================================================
09:56:04.0703 3396 Scan started
09:56:04.0703 3396 Mode: Manual;
09:56:04.0703 3396 ============================================================
09:56:04.0750 3396 6to4 - ok
09:56:04.0765 3396 Abiosdsk - ok
09:56:04.0781 3396 abp480n5 - ok
09:56:04.0796 3396 ACPI - ok
09:56:04.0796 3396 ACPIEC - ok
09:56:04.0812 3396 AdobeFlashPlayerUpdateSvc - ok
09:56:04.0828 3396 adpu160m - ok
09:56:04.0843 3396 aeaudio - ok
09:56:04.0859 3396 aec - ok
09:56:04.0859 3396 AFD - ok
09:56:04.0875 3396 AFS2K - ok
09:56:04.0890 3396 agp440 - ok
09:56:04.0906 3396 agpCPQ - ok
09:56:04.0921 3396 Aha154x - ok
09:56:04.0921 3396 aic78u2 - ok
09:56:04.0937 3396 aic78xx - ok
09:56:04.0953 3396 Alerter - ok
09:56:04.0968 3396 ALG - ok
09:56:04.0984 3396 AliIde - ok
09:56:05.0000 3396 alim1541 - ok
09:56:05.0000 3396 amdagp - ok
09:56:05.0015 3396 amsint - ok
09:56:05.0046 3396 Apple Mobile Device - ok
09:56:05.0062 3396 AppMgmt - ok
09:56:05.0062 3396 asc - ok
09:56:05.0078 3396 asc3350p - ok
09:56:05.0093 3396 asc3550 - ok
09:56:05.0125 3396 aspnet_state - ok
09:56:05.0140 3396 AsyncMac - ok
09:56:05.0156 3396 atapi - ok
09:56:05.0171 3396 Atdisk - ok
09:56:05.0187 3396 Atmarpc - ok
09:56:05.0187 3396 AudioSrv - ok
09:56:05.0203 3396 audstub - ok
09:56:05.0218 3396 AVGIDSAgent - ok
09:56:05.0234 3396 AVGIDSDriver - ok
09:56:05.0250 3396 AVGIDSFilter - ok
09:56:05.0250 3396 AVGIDSHX - ok
09:56:05.0265 3396 AVGIDSShim - ok
09:56:05.0281 3396 Avgldx86 - ok
09:56:05.0281 3396 Avgmfx86 - ok
09:56:05.0296 3396 Avgrkx86 - ok
09:56:05.0312 3396 Avgtdix - ok
09:56:05.0328 3396 avgwd - ok
09:56:05.0343 3396 bcm4sbxp - ok
09:56:05.0359 3396 BCSWAP - ok
09:56:05.0359 3396 Beep - ok
09:56:05.0375 3396 BITS - ok
09:56:05.0390 3396 Bonjour Service - ok
09:56:05.0406 3396 Browser - ok
09:56:05.0406 3396 catchme - ok
09:56:05.0421 3396 cbidf - ok
09:56:05.0437 3396 cbidf2k - ok
09:56:05.0453 3396 CCALib8 - ok
09:56:05.0453 3396 CCDECODE - ok
09:56:05.0468 3396 cd20xrnt - ok
09:56:05.0484 3396 Cdaudio - ok
09:56:05.0500 3396 Cdfs - ok
09:56:05.0515 3396 Cdr4_xp - ok
09:56:05.0531 3396 Cdralw2k - ok
09:56:05.0531 3396 Cdrom - ok
09:56:05.0546 3396 cdudf_xp - ok
09:56:05.0562 3396 Changer - ok
09:56:05.0578 3396 CiSvc - ok
09:56:05.0593 3396 ClipSrv - ok
09:56:05.0609 3396 clr_optimization_v2.0.50727_32 - ok
09:56:05.0625 3396 clr_optimization_v4.0.30319_32 - ok
09:56:05.0625 3396 CmdIde - ok
09:56:05.0640 3396 COMSysApp - ok
09:56:05.0656 3396 Cpqarray - ok
09:56:05.0671 3396 CryptSvc - ok
09:56:05.0687 3396 CVirtA - ok
09:56:05.0703 3396 CVPND - ok
09:56:05.0703 3396 CVPNDRVA - ok
09:56:05.0718 3396 dac2w2k - ok
09:56:05.0734 3396 dac960nt - ok
09:56:05.0750 3396 DcomLaunch - ok
09:56:05.0750 3396 Dhcp - ok
09:56:05.0765 3396 DiCapi - ok
09:56:05.0781 3396 DiMaint - ok
09:56:05.0781 3396 DiPort - ok
09:56:05.0796 3396 Disk - ok
09:56:05.0812 3396 DiWan - ok
09:56:05.0828 3396 dmadmin - ok
09:56:05.0843 3396 dmboot - ok
09:56:05.0843 3396 dmio - ok
09:56:05.0859 3396 dmload - ok
09:56:05.0875 3396 dmserver - ok
09:56:05.0890 3396 DMusic - ok
09:56:05.0890 3396 DNE - ok
09:56:05.0906 3396 Dnscache - ok
09:56:05.0937 3396 Dot3svc - ok
09:56:05.0937 3396 dpti2o - ok
09:56:05.0953 3396 drmkaud - ok
09:56:05.0968 3396 dvd_2K - ok
09:56:05.0968 3396 EapHost - ok
09:56:05.0984 3396 EL90XBC - ok
09:56:06.0000 3396 ERSvc - ok
09:56:06.0015 3396 Eventlog - ok
09:56:06.0031 3396 EventSystem - ok
09:56:06.0031 3396 Fastfat - ok
09:56:06.0046 3396 FastUserSwitchingCompatibility - ok
09:56:06.0062 3396 Fdc - ok
09:56:06.0078 3396 Fips - ok
09:56:06.0078 3396 Flpydisk - ok
09:56:06.0109 3396 FltMgr - ok
09:56:06.0109 3396 FontCache3.0.0.0 - ok
09:56:06.0125 3396 Fs_Rec - ok
09:56:06.0140 3396 Ftdisk - ok
09:56:06.0156 3396 GEARAspiWDM - ok
09:56:06.0171 3396 Gpc - ok
09:56:06.0187 3396 gupdate1c9f4b5549515e - ok
09:56:06.0187 3396 gupdatem - ok
09:56:06.0203 3396 helpsvc - ok
09:56:06.0218 3396 HidServ - ok
09:56:06.0234 3396 hkmsvc - ok
09:56:06.0234 3396 hpn - ok
09:56:06.0250 3396 HPZid412 - ok
09:56:06.0265 3396 HPZipr12 - ok
09:56:06.0281 3396 HPZius12 - ok
09:56:06.0296 3396 HTTP - ok
09:56:06.0296 3396 HTTPFilter - ok
09:56:06.0312 3396 i2omgmt - ok
09:56:06.0328 3396 i2omp - ok
09:56:06.0343 3396 i8042prt - ok
09:56:06.0343 3396 i81x - ok
09:56:06.0359 3396 iAimFP0 - ok
09:56:06.0375 3396 iAimFP1 - ok
09:56:06.0390 3396 iAimFP2 - ok
09:56:06.0390 3396 iAimFP3 - ok
09:56:06.0406 3396 iAimFP4 - ok
09:56:06.0421 3396 iAimTV0 - ok
09:56:06.0437 3396 iAimTV1 - ok
09:56:06.0453 3396 iAimTV2 - ok
09:56:06.0453 3396 iAimTV3 - ok
09:56:06.0468 3396 iAimTV4 - ok
09:56:06.0484 3396 ialm - ok
09:56:06.0484 3396 IDriverT - ok
09:56:06.0500 3396 idsvc - ok
09:56:06.0515 3396 Imapi - ok
09:56:06.0531 3396 Imapi Helper - ok
09:56:06.0546 3396 ImapiService - ok
09:56:06.0562 3396 ini910u - ok
09:56:06.0593 3396 IntelIde - ok
09:56:06.0593 3396 intelppm - ok
09:56:06.0609 3396 ip6fw - ok
09:56:06.0625 3396 IpFilterDriver - ok
09:56:06.0640 3396 IpInIp - ok
09:56:06.0656 3396 IpNat - ok
09:56:06.0656 3396 iPod Service - ok
09:56:06.0671 3396 IPSec - ok
09:56:06.0687 3396 IRENUM - ok
09:56:06.0703 3396 isapnp - ok
09:56:06.0718 3396 JavaQuickStarterService - ok
09:56:06.0718 3396 Kbdclass - ok
09:56:06.0734 3396 kmixer - ok
09:56:06.0765 3396 KSecDD - ok
09:56:06.0781 3396 lanmanserver - ok
09:56:06.0796 3396 lanmanworkstation - ok
09:56:06.0812 3396 lbrtfdc - ok
09:56:06.0828 3396 LmHosts - ok
09:56:06.0843 3396 MDM - ok
09:56:06.0859 3396 Messenger - ok
09:56:06.0875 3396 mmc_2K - ok
09:56:06.0890 3396 mnmdd - ok
09:56:06.0890 3396 mnmsrvc - ok
09:56:06.0906 3396 Modem - ok
09:56:06.0921 3396 Mouclass - ok
09:56:06.0937 3396 MountMgr - ok
09:56:06.0937 3396 mraid35x - ok
09:56:06.0953 3396 MRxDAV - ok
09:56:06.0968 3396 MRxSmb - ok
09:56:06.0984 3396 MSDTC - ok
09:56:07.0000 3396 Msfs - ok
09:56:07.0015 3396 MSIServer - ok
09:56:07.0031 3396 MSKSSRV - ok
09:56:07.0031 3396 MSPCLOCK - ok
09:56:07.0046 3396 MSPQM - ok
09:56:07.0062 3396 mssmbios - ok
09:56:07.0078 3396 MSTEE - ok
09:56:07.0109 3396 Mup - ok
09:56:07.0109 3396 NABTSFEC - ok
09:56:07.0109 3396 napagent - ok
09:56:07.0125 3396 NDIS - ok
09:56:07.0140 3396 NdisIP - ok
09:56:07.0156 3396 NdisTapi - ok
09:56:07.0156 3396 Ndisuio - ok
09:56:07.0171 3396 NdisWan - ok
09:56:07.0187 3396 NDProxy - ok
09:56:07.0203 3396 NetBIOS - ok
09:56:07.0203 3396 NetBT - ok
09:56:07.0218 3396 NetDDE - ok
09:56:07.0234 3396 NetDDEdsdm - ok
09:56:07.0250 3396 Netlogon - ok
09:56:07.0250 3396 Netman - ok
09:56:07.0265 3396 NetTcpPortSharing - ok
09:56:07.0281 3396 Nla - ok
09:56:07.0296 3396 nosGetPlusHelper - ok
09:56:07.0312 3396 Npfs - ok
09:56:07.0328 3396 Ntfs - ok
09:56:07.0343 3396 NtLmSsp - ok
09:56:07.0343 3396 NtmsSvc - ok
09:56:07.0359 3396 Null - ok
09:56:07.0375 3396 NuVision - ok
09:56:07.0390 3396 nv - ok
09:56:07.0406 3396 NwlnkFlt - ok
09:56:07.0406 3396 NwlnkFwd - ok
09:56:07.0421 3396 omci - ok
09:56:07.0437 3396 P3 - ok
09:56:07.0453 3396 Parport - ok
09:56:07.0453 3396 PartMgr - ok
09:56:07.0468 3396 ParVdm - ok
09:56:07.0484 3396 PCI - ok
09:56:07.0500 3396 PCIDump - ok
09:56:07.0500 3396 PCIIde - ok
09:56:07.0515 3396 Pcmcia - ok
09:56:07.0531 3396 pcouffin - ok
09:56:07.0546 3396 PDCOMP - ok
09:56:07.0562 3396 PDFRAME - ok
09:56:07.0578 3396 PDRELI - ok
09:56:07.0593 3396 PDRFRAME - ok
09:56:07.0593 3396 perc2 - ok
09:56:07.0609 3396 perc2hib - ok
09:56:07.0656 3396 PlugPlay - ok
09:56:07.0656 3396 PMBDeviceInfoProvider - ok
09:56:07.0671 3396 Pml Driver HPZ12 - ok
09:56:07.0687 3396 PolicyAgent - ok
09:56:07.0703 3396 PptpMiniport - ok
09:56:07.0718 3396 Processor - ok
09:56:07.0718 3396 ProtectedStorage - ok
09:56:07.0734 3396 PSched - ok
09:56:07.0750 3396 Ptilink - ok
09:56:07.0765 3396 pwd_2k - ok
09:56:07.0781 3396 PxHelp20 - ok
09:56:07.0796 3396 ql1080 - ok
09:56:07.0812 3396 Ql10wnt - ok
09:56:07.0812 3396 ql12160 - ok
09:56:07.0828 3396 ql1240 - ok
09:56:07.0843 3396 ql1280 - ok
09:56:07.0859 3396 RasAcd - ok
09:56:07.0875 3396 RasAuto - ok
09:56:07.0875 3396 Rasl2tp - ok
09:56:07.0890 3396 RasMan - ok
09:56:07.0906 3396 RasPppoe - ok
09:56:07.0921 3396 Raspti - ok
09:56:07.0937 3396 Rdbss - ok
09:56:07.0953 3396 RDPCDD - ok
09:56:07.0968 3396 rdpdr - ok
09:56:08.0000 3396 RDPWD - ok
09:56:08.0000 3396 RDSessMgr - ok
09:56:08.0015 3396 redbook - ok
09:56:08.0031 3396 RemoteAccess - ok
09:56:08.0046 3396 RemoteRegistry - ok
09:56:08.0062 3396 RpcLocator - ok
09:56:08.0078 3396 RpcSs - ok
09:56:08.0078 3396 RSVP - ok
09:56:08.0093 3396 SamSs - ok
09:56:08.0109 3396 SCardSvr - ok
09:56:08.0125 3396 Schedule - ok
09:56:08.0140 3396 Secdrv - ok
09:56:08.0156 3396 seclogon - ok
09:56:08.0171 3396 SENS - ok
09:56:08.0187 3396 serenum - ok
09:56:08.0187 3396 Serial - ok
09:56:08.0234 3396 Sfloppy - ok
09:56:08.0250 3396 SharedAccess - ok
09:56:08.0265 3396 ShellHWDetection - ok
09:56:08.0281 3396 Simbad - ok
09:56:08.0296 3396 sisagp - ok
09:56:08.0296 3396 SLIP - ok
09:56:08.0328 3396 smwdm - ok
09:56:08.0343 3396 Sparrow - ok
09:56:08.0359 3396 splitter - ok
09:56:08.0375 3396 Spooler - ok
09:56:08.0375 3396 sr - ok
09:56:08.0390 3396 srservice - ok
09:56:08.0406 3396 Srv - ok
09:56:08.0421 3396 SSDPSRV - ok
09:56:08.0437 3396 stisvc - ok
09:56:08.0437 3396 streamip - ok
09:56:08.0453 3396 swenum - ok
09:56:08.0468 3396 swmidi - ok
09:56:08.0468 3396 SwPrv - ok
09:56:08.0500 3396 symc810 - ok
09:56:08.0515 3396 symc8xx - ok
09:56:08.0515 3396 sym_hi - ok
09:56:08.0531 3396 sym_u3 - ok
09:56:08.0546 3396 sysaudio - ok
09:56:08.0562 3396 SysmonLog - ok
09:56:08.0578 3396 TapiSrv - ok
09:56:08.0593 3396 Tcpip - ok
09:56:08.0609 3396 Tcpip6 - ok
09:56:08.0625 3396 TDPIPE - ok
09:56:08.0625 3396 TDTCP - ok
09:56:08.0640 3396 TermDD - ok
09:56:08.0656 3396 TermService - ok
09:56:08.0671 3396 Themes - ok
09:56:08.0687 3396 TlntSvr - ok
09:56:08.0687 3396 TosIde - ok
09:56:08.0703 3396 TracSrvWrapper - ok
09:56:08.0718 3396 TrkWks - ok
09:56:08.0718 3396 truecrypt - ok
09:56:08.0750 3396 tunmp - ok
09:56:08.0765 3396 UdfReadr_xp - ok
09:56:08.0765 3396 Udfs - ok
09:56:08.0781 3396 ultra - ok
09:56:08.0796 3396 Update - ok
09:56:08.0812 3396 upnphost - ok
09:56:08.0828 3396 UPS - ok
09:56:08.0843 3396 USBAAPL - ok
09:56:08.0859 3396 usbccgp - ok
09:56:08.0875 3396 usbehci - ok
09:56:08.0875 3396 usbhub - ok
09:56:08.0890 3396 usbprint - ok
09:56:08.0906 3396 usbscan - ok
09:56:08.0921 3396 USBSTOR - ok
09:56:08.0937 3396 usbuhci - ok
09:56:08.0953 3396 VgaSave - ok
09:56:08.0953 3396 viaagp - ok
09:56:08.0968 3396 ViaIde - ok
09:56:08.0984 3396 vna_ap - ok
09:56:09.0000 3396 VolSnap - ok
09:56:09.0000 3396 vsdatant - ok
09:56:09.0015 3396 vsmon - ok
09:56:09.0031 3396 VSS - ok
09:56:09.0046 3396 w32time - ok
09:56:09.0078 3396 Wanarp - ok
09:56:09.0093 3396 WDICA - ok
09:56:09.0093 3396 wdmaud - ok
09:56:09.0109 3396 WebClient - ok
09:56:09.0140 3396 winmgmt - ok
09:56:09.0203 3396 WmdmPmSN - ok
09:56:09.0218 3396 Wmi - ok
09:56:09.0250 3396 WmiApSrv - ok
09:56:09.0265 3396 WMPNetworkSvc - ok
09:56:09.0265 3396 WPFFontCache_v0400 - ok
09:56:09.0343 3396 wscsvc - ok
09:56:09.0359 3396 WSTCODEC - ok
09:56:09.0375 3396 wuauserv - ok
09:56:09.0390 3396 WudfPf - ok
09:56:09.0406 3396 WudfRd - ok
09:56:09.0421 3396 WudfSvc - ok
09:56:09.0421 3396 WZCSVC - ok
09:56:09.0437 3396 xmlprov - ok
09:56:09.0484 3396 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
09:56:09.0515 3396 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
09:56:09.0546 3396 MBR (0x1B8) (ef2eec94b0e09a39d077d3e01a352d8f) \Device\Harddisk0\DR0
09:56:10.0078 3396 \Device\Harddisk0\DR0 - ok
09:56:10.0093 3396 Boot (0x1200) (cf03cf63873571b28db5bed637f3053c) \Device\Harddisk0\DR0\Partition0
09:56:10.0093 3396 \Device\Harddisk0\DR0\Partition0 - ok
09:56:10.0109 3396 ============================================================
09:56:10.0109 3396 Scan finished
09:56:10.0109 3396 ============================================================
09:56:10.0156 3784 Detected object count: 0
09:56:10.0156 3784 Actual detected object count: 0
 
Still waiting for malawarebytes scan to finish so i will post other observations.

When i went googled malawarebytes and clicked the site i got redirected a few times. I got in the 3rd time.

Also sometimes google searchs comes back with "unusual activity Captcha" to fill in :confused:

Malawarebytes scan still motoring along :rockon:
 
Malawarebytes scan has finished and doesnt appear to have picked up anything.


Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.05.22.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.11
Gerry :: BRIDS_DELL [administrator]

22/05/2012 10:17:42
mbam-log-2012-05-22 (10-17-42).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 361800
Time elapsed: 2 hour(s), 29 minute(s), 38 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 
ok. Thats good news. Follow this to clean out your java cache. Ive never used chrome so follow this link to clear temp files unless you already know how to do it. Cruise around and see if any redirection happens.
You can also check out the free version of CCleaner which will do this and more for you.
 
More feedback. I have has some broweser redirection since i posted the malawarebytes log.

I then followed your java and chrome cleardown steps. Also downloaded ccleaner latest version and ran that. Will monitor to see if these latest steps help. Do i need to do anything else ?

Cheers
 
You can get another download to use, its called combofix. There is a guide to read first. Read through the guide then apply the directions on your own machine. Post the log. I wont be back online for 18 hrs or so.

Guide to using Combofix
 
I ran the combofix job. Log below. I disabled AVG for 15 min per instructions but combofix ran longer, thus avg windows appeared to allow or quarantine combofix files. I allowed both. Just thought i mention it. Here is mumbo jumbo log :D:
Thanks again Shelf



ComboFix 12-05-24.02 - Gerry 24/05/2012 18:13:12.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1474 [GMT 1:00]
Running from: c:\documents and settings\Gerry\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Endpoint Security Client Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\DirectCDUserNameD.txt
c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
c:\documents and settings\Brid\WINDOWS
c:\documents and settings\Gerry\WINDOWS
c:\progra~1\TAXMAG~1\TAXMag~1.exe
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\SETC4.tmp
c:\windows\system32\SETC7.tmp
c:\windows\system32\SETD3.tmp
c:\windows\system32\SETE0.tmp
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2012-04-24 to 2012-05-24 )))))))))))))))))))))))))))))))
.
.
2012-05-12 00:13 . 2012-05-12 00:13 -------- d-----w- c:\documents and settings\Gerry\Application Data\Auslogics
2012-05-12 00:13 . 2012-05-12 00:13 -------- d-----w- c:\program files\Auslogics
2012-05-09 18:28 . 2012-05-09 18:28 -------- d-----w- c:\program files\ERUNT
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-09 07:51 . 2012-04-19 17:51 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-09 07:51 . 2011-05-29 22:21 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-19 03:50 . 2012-04-19 03:50 24896 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2012-04-11 13:12 . 2002-08-29 04:00 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 13:10 . 1979-12-31 23:00 2192640 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 12:35 . 1979-12-31 23:00 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-04 14:56 . 2008-12-11 12:58 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-19 04:17 . 2011-02-10 06:54 301248 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2012-03-06 18:43 . 2012-03-06 18:43 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-06 18:43 . 2010-04-25 22:04 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-01 01:25 . 2006-02-24 13:26 832512 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 01:25 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-03-01 01:25 . 2002-08-29 04:00 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-03-01 01:25 . 2002-08-29 04:00 17408 ----a-w- c:\windows\system32\corpol.dll
2012-02-29 14:10 . 2002-08-29 04:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2002-08-29 04:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2003-09-01 12:56 . 2003-09-01 12:56 235988 ----a-w- c:\program files\Logo - accounting1.exe
2003-08-29 21:06 . 2003-08-29 20:31 16251072 ----a-w- c:\program files\AdbeRdr60_enu_full.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Gerry\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Gerry\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Gerry\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Gerry\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrueCrypt"="c:\program files\TrueCrypt\TrueCrypt.exe" [2010-11-27 1496528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2012-02-23 59240]
"Check Point Endpoint Tray Application"="c:\program files\Common Files\Check Point\UIFramework\cptray.exe" [2010-05-19 70144]
"Check Point Endpoint Connect"="c:\program files\Checkpoint\Endpoint Security\Endpoint Connect\TrGUI.exe" [2010-05-09 624136]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-04 296056]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Gerry\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Gerry\Application Data\Dropbox\bin\Dropbox.exe [2012-2-15 24246216]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2006-5-18 1454143]
hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-6 323646]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\TunnelServer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Documents and Settings\\Gerry\\My Documents\\Downloads\\T-RSMXP\\RapidShare Manager for XP\\RapidShareManager.exe"=
"c:\\Documents and Settings\\Gerry\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Checkpoint\\Endpoint Security\\Endpoint Connect\\TracSrvWrapper.exe"=
"c:\\Program Files\\Checkpoint\\Endpoint Security\\Endpoint Connect\\TrGUI.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\SYSTEM32\DRIVERS\avgidshx.sys [19/04/2012 04:50 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [19/01/2011 04:32 31952]
R0 DiMaint;Eicon Maintenance Driver;c:\windows\SYSTEM32\DRIVERS\DISDN\dimaint.sys [04/12/2002 14:49 91408]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [07/01/2011 06:41 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [10/02/2011 07:54 301248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [30/04/2012 09:44 5106744]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [14/02/2012 04:53 193288]
R2 DiCapi;Eicon CAPI 2.0 Driver;c:\windows\SYSTEM32\DRIVERS\DISDN\capi202k.sys [12/06/2001 14:27 181168]
R2 DiPort;Eicon Port Driver;c:\windows\SYSTEM32\DRIVERS\DISDN\diport40.sys [16/10/2002 15:32 206976]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [27/11/2010 01:55 398176]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\SYSTEM32\DRIVERS\avgidsdriverx.sys [23/12/2011 13:32 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\SYSTEM32\DRIVERS\avgidsfilterx.sys [23/12/2011 13:32 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\SYSTEM32\DRIVERS\avgidsshimx.sys [23/12/2011 13:32 17232]
R3 DiWan;Eicon Driver for all Diva Client cards;c:\windows\SYSTEM32\DRIVERS\DISDN\Diwan.sys [03/10/2002 16:35 911920]
R3 vna_ap;Check Point Virtual Network Adapter - Apollo;c:\windows\SYSTEM32\DRIVERS\vnaap.sys [09/05/2010 20:11 129304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S2 gupdate1c9f4b5549515e;Google Update Service (gupdate1c9f4b5549515e);c:\program files\Google\Update\GoogleUpdate.exe [24/06/2009 11:17 133104]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe [19/04/2012 18:51 257696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [24/06/2009 11:17 133104]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [29/08/2002 05:00 14336]
S3 NuVision;Hauppauge WinTV USB Pro (PAL I,D/K);c:\windows\SYSTEM32\DRIVERS\NUVision.sys [13/02/2008 16:13 260144]
S3 pcouffin;VSO Software pcouffin;c:\windows\SYSTEM32\DRIVERS\pcouffin.sys [07/07/2007 12:17 47360]
S3 TracSrvWrapper;Check Point Endpoint Connect;c:\program files\Checkpoint\Endpoint Security\Endpoint Connect\TracSrvWrapper.exe [09/05/2010 20:11 3511824]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
S4 BCSWAP;BCSWAP;c:\windows\SYSTEM32\DRIVERS\BCSwap.sys [25/01/2007 15:54 91496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 07:51]
.
2012-05-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 17:57]
.
2003-12-01 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 2200 series5E771253C1676EBED677BF361FDFC537825E15B8062102495.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-24 10:17]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-24 10:17]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3836196526-914930832-50539439-1006Core.job
- c:\documents and settings\Brid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-19 23:26]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3836196526-914930832-50539439-1006UA.job
- c:\documents and settings\Brid\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-19 23:26]
.
2012-05-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3836196526-914930832-50539439-1007Core.job
- c:\documents and settings\Gerry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-24 10:08]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3836196526-914930832-50539439-1007UA.job
- c:\documents and settings\Gerry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-24 10:08]
.
2012-05-24 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3836196526-914930832-50539439-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 16:14]
.
2012-05-24 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3836196526-914930832-50539439-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 16:14]
.
2012-04-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3836196526-914930832-50539439-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 16:14]
.
2012-05-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3836196526-914930832-50539439-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 16:14]
.
2003-08-06 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-07-29 08:04]
.
2012-05-24 c:\windows\Tasks\User_Feed_Synchronization-{F5622167-D928-44CB-8ABA-F40AB5B55F88}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ie/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\AVG\AVG2012\avgdtiex.dll
TCP: DhcpNameServer = 192.168.1.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
BHO-{7232f4e2-2037-4077-bc83-70aa43f09565} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-24 18:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
Completion time: 2012-05-24 18:35:24
ComboFix-quarantined-files.txt 2012-05-24 17:35
ComboFix2.txt 2008-12-17 02:49
.
Pre-Run: 9,015,369,728 bytes free
Post-Run: 9,426,395,136 bytes free
.
- - End Of File - - 4401D6D684F9FD7EB7CA8848F4026AA1
 
Hi Shelf,

Unfortunately the redirection still remains and may have got worse.
I googled bbc sport and clicked the link to it.
I got redirected to Sites like worldpcgames, wall2go, wall2gosetup.exe got downloaded as well.

What next ?

Chewey
 
Getting worse. Another download to get:

Please download aswmbr.exe to your desktop.

Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
On completion of the scan click save log, save it to your desktop and post in your next reply
 
Ok Shelf - It asked me did i want to download AVASTS latest virus definitions and to run avasts virus scanner. I said No as i already run AVG. I then did a scan which produced the following. Should i have said yes before running below ?

Here it is anyways and thanks again for your assistance


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-05-28 20:57:52
-----------------------------
20:57:52.218 OS Version: Windows 5.1.2600 Service Pack 3
20:57:52.218 Number of processors: 1 586 0x207
20:57:52.218 ComputerName: BRIDS_DELL UserName: Gerry
20:57:53.515 Initialize success
20:58:33.171 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
20:58:33.171 Disk 0 Vendor: IC35L090AVV207-0 V23OA66A Size: 76293MB BusType: 3
20:58:33.203 Disk 0 MBR read successfully
20:58:33.203 Disk 0 MBR scan
20:58:33.203 Disk 0 unknown MBR code
20:58:33.203 Disk 0 Partition 1 00 DE Dell Utility 31 MB offset 63
20:58:33.218 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS 76253 MB offset 64260
20:58:33.218 Disk 0 scanning sectors +156232125
20:58:33.281 Disk 0 scanning C:\WINDOWS\system32\drivers
20:58:33.281 Service scanning
20:58:34.000 Service ACPI C:\WINDOWS\System32\DRIVERS\ACPI.sys **LOCKED** 32
20:59:20.531 Service vsdatant C:\WINDOWS\System32\vsdatant.sys **LOCKED** 32
20:59:23.453 Modules scanning
20:59:24.093 Disk 0 trace - called modules:
20:59:24.625 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys >>UNKNOWN [0x8a80f151]<<
20:59:24.625 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a9ddab8]
20:59:24.625 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa59d98]
20:59:24.625 Scan finished successfully
20:59:41.984 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Gerry\My Documents\Downloads\MBR.dat"
20:59:42.000 The log file has been saved successfully to "C:\Documents and Settings\Gerry\My Documents\Downloads\aswMBR.txt"
 
You did the right thing. The downloads are for if you are running AVAST.

Try this with chrome; Export or backup your bookmarks. Then uninstall chrome via the add/remove programs panel. If asked if you want to remove settings and/or user data select yes. After the uninstall reboot machine then reinstall chrome and cruise around and see how it goes.
 
Ok i have done that and things seem to be stable while google searching within chrome. My mrs prefers Internet explorer so do i need to uninstall -reinstall IE as well ? I have done some google searchs within IE as well and all seems good.

I seem to remember the chrome desktop icon was renamed a while back. I thought nothing of it and renamed it back to chrome. In hindsight this was probably caused by the infection. Is it possible that i was running a rogue version of chrome all along and the reinstall restored the correct version ? The uninstall today didnt remove the desktop item as well.

Anyways so far so good but i'll keep monitoring.

Thanks again shelf.
 
ok good. Keep cruising around and make sure all is good. No need to uninstall IE.
A rouge version of Chrome? Hard to say. You can delete that chrome.exe from your desktop.
This type of redirect can happen with IE and Firefox also, not sure of how the redirection actually works though without having any supportive malware on the machine itself. Totally removing then reinstalling the browser clears it up. Usually I expect to see more malware show up in logs with redirection going on.
 
Back
Top