Hello,
I have gotten the Claro Search redirect infection on my laptop. It takes over both Chrome and IE8.
I have read the "BEFORE You POST" section.
I ran SpyBot yesterday (twice) and it detected and removed Claro and Babylon but Claro is still there.
Here is the top of the log from yesterday's first SpyBot scan
Search results from Spybot - Search & Destroy
11/26/2012 3:58:11 PM
Scan took 00:18:33.
363 items found.
Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done)
C:\ProgramData\Babylon\
Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done)
C:\Users\johnc\AppData\Roaming\Babylon\
Directory.subfile=C:\Users\johnc\AppData\Roaming\Babylon\log_file.txt
Directory.subfile.size=8708
Directory.subfile.md5=147F0BF1BE261D172DB6EC6B36612A46
Directory.subfile.filedate=1353956505
Directory.subfile.filedatetext=2012-11-26 12:01:45
Claro.Toolbar: [SBI $47170986] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\claro.claroappCore
Here are the results from the second scan
Search results from Spybot - Search & Destroy
11/26/2012 4:16:48 PM
Scan took 00:13:23.
14 items found.
DoubleClick: [SBI $8E73A7FB] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)
MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-8915387-2129677417-1971066577-7837\Software\Microsoft\DirectInput\MostRecentApplication\Name
Registry Backup - DONE!
DDS Log
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.3.1
Run by JohnC at 16:32:50 on 2012-11-26
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3262.1503 [GMT -7:00]
.
AV: Symantec Endpoint Protection.cloud *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Symantec Endpoint Protection.cloud *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Symantec Endpoint Protection.cloud *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\IDT\WDM\STacSV.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
C:\Program Files\Druva\inSync\inSyncCPHwnet.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Druva\inSync\inSync.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\20.1.0.24\ccSvcHst.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\20.1.0.24\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\RightFax\FaxCtrl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Druva\inSync\inSyncGUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Druva\inSync\inSyncUSyncer.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Windows\system32\vssvc.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Symantec.cloud\PlatformAgent\ccSvcHst.exe
C:\Program Files\Symantec.cloud\AntiVirus\AVAgent.exe
C:\Program Files\Symantec.cloud\PlatformAgent\PAUI.exe
c:\program files\symantec.cloud\antivirus\ssDVAgent.exe
C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\20.1.0.24\ccSvcHst.exe
C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
C:\Windows\system32\schtasks.exe
C:\Windows\system32\conhost.exe
C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
C:\PROGRA~1\TIGERT~1\HOLIDA~1\HOLIDA~1.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\program files\coupon companion\coupon companion-bg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://my.yahoo.com/;_ylc=X3oDMTB1bTdjdnNyBF9TAzI3MTk0ODEEbG5rA215BHRpZANUcnZsU21wbA--
BHO: Coupon Companion: {11111111-1111-1111-1111-110011441193} - c:\program files\coupon companion\Coupon Companion.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\CoIEPlg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\ips\IPSBHO.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\oracle\javafx 2.0 runtime\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\CoIEPlg.dll
uRun: [Google Update] "c:\users\johnc\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [GoogleRdrNotify] "c:\program files\yonizaf\grain google reader notifier\GoogleReaderNotifier.exe"
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe
mRun: [IMSS] "c:\program files\intel\intel(r) management engine components\imss\PIconStartup.exe"
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe
mRun: [USCService] c:\program files\dell\dell controlpoint\security manager\BcmDeviceAndTaskStatusService.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [RightFAX Print-to-Fax Driver] c:\program files\rightfax\FaxCtrl.exe
mRun: [CaddieSyncConduit] c:\program files\skygolf\caddiesync express\CaddieSyncExpress.exe
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [SymantecPaui] "c:\program files\symantec.cloud\platformagent\PAUI.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Druva inSync] c:\program files\druva\insync\inSyncGUI.exe -l en
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\johnc\appdata\roaming\micros~1\windows\startm~1\programs\startup\holida~1.lnk - c:\program files\tiger technologies\holiday lights\Holiday Lights.exe
StartupFolder: c:\users\johnc\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\johnc\appdata\roaming\micros~1\windows\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\tdmnot~1.lnk - c:\program files\wave systems corp\trusted drive manager\TdmNotify.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.3.0/GarminAxControl_32.CAB
DPF: {01614D85-E2FC-40AC-BAB5-24CE29E94DB4} - hxxp://jpcfishcam.dyndns.org:1024/img/Viewer.cab
DPF: {174793AA-EAE2-4188-AFA5-064BE26901B1} - hxxp://www.digitalgsp.com/xvr/CXRMS_1,1,0,1.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://isecure.spectralogic.com/dana-cached/sc/JuniperSetupClient.cab
TCP: NameServer = 192.168.200.70 192.168.200.71
TCP: Interfaces\{8735282F-B28C-4E68-A87B-0934AB3765E6} : DHCPNameServer = 192.168.200.70 192.168.200.71
TCP: Interfaces\{D08F5DBC-3172-41D1-81C8-54C76756A629} : DHCPNameServer = 192.168.200.70 192.168.200.71
TCP: Interfaces\{D08F5DBC-3172-41D1-81C8-54C76756A629}\3427F677C656976416D696C697 : DHCPNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{D1EA2FC0-4CD4-4335-9279-27AA7301D965} : DHCPNameServer = 192.168.200.70 192.168.200.71
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Authentication Packages = msv1_0 wvauth
.
============= SERVICES / DRIVERS ===============
.
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [2010-9-30 17072]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1401000.018\SymDS.sys [2012-10-15 368288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1401000.018\SymEFA.sys [2012-10-15 926880]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_20.1.0.24\definitions\bashdefs\20121106.001\BHDrvx86.sys [2012-10-23 995488]
R1 ccSet_Cloud;CC Standalone Settings Manager;c:\windows\system32\drivers\symantec.cloud\ccSetx86.sys [2012-8-31 132768]
R1 ccSet_NIS;Endpoint Protection.cloud Settings Manager;c:\windows\system32\drivers\nis\1401000.018\ccSetx86.sys [2012-10-15 134304]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_20.1.0.24\definitions\ipsdefs\20121123.001\IDSvix86.sys [2012-11-26 386720]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1401000.018\Ironx86.sys [2012-10-15 175264]
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\nis\1401000.018\symnets.sys [2012-10-15 338592]
R2 AESTFilters;Andrea ST Filters Service;c:\program files\idt\wdm\AEstSrv.exe [2010-9-30 81920]
R2 Browser Manager;Browser Manager;c:\programdata\browser manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe [2012-11-26 2402840]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2009-11-20 278304]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2010-3-23 812448]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2010-3-23 27040]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2010-2-8 386928]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2010-9-30 13336]
R2 InstallFilterService;FF Install Filter Service;c:\program files\stmicroelectronics\accelerometerp11\InstallFilterService.exe [2010-9-30 60928]
R2 inSyncCPHService;Druva inSync Client Service;c:\program files\druva\insync\inSyncCPHwnet.exe [2012-9-14 171008]
R2 NIS;Endpoint Protection.cloud;c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\ccSvcHst.exe [2012-10-15 143928]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2010-8-25 59904]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-11-26 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-11-26 1369624]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-11-26 168384]
R2 SsPaAdm;Symantec.cloud Cloud Agent;c:\program files\symantec.cloud\platformagent\ccSvcHst.exe [2012-8-31 138272]
R2 ssSpnAv;Symantec.cloud Endpoint Protection;c:\program files\symantec.cloud\antivirus\AVAgent.exe [2012-10-15 409040]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\intel\intel(r) management engine components\uns\UNS.exe [2010-9-30 2533400]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2010-9-30 42672]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2010-8-25 33832]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k6232.sys [2010-8-25 224424]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-8-10 106656]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\drivers\NETw5s32.sys [2009-9-15 6114816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-11-20 113152]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 CAATT;AT&T Con App Svc;c:\program files\at&t\communication manager\ConAppsSvc.exe [2008-11-20 125440]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2008-2-18 106624]
S3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2008-2-8 59648]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2011-12-28 132480]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2011-12-28 269824]
S3 rimspci;rimspci;c:\windows\system32\drivers\rimspe86.sys [2010-8-25 48640]
S3 rixdpcie;rixdpcie;c:\windows\system32\drivers\rixdpe86.sys [2010-8-25 38912]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-20 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-10-12 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2012-11-26 22:38:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-11-26 22:37:54 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-11-26 22:37:50 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-11-26 22:36:43 -------- d-----w- c:\users\johnc\appdata\local\Programs
2012-11-26 19:01:45 37888 ----a-w- c:\windows\system32\Holiday Lights.scr
2012-11-26 19:01:37 -------- d-----w- c:\program files\Tiger Technologies
2012-11-26 19:01:33 -------- d-----w- c:\users\johnc\appdata\roaming\Claro
2012-11-26 19:01:32 -------- d-----w- c:\windows\system32\searchplugins
2012-11-26 19:01:32 -------- d-----w- c:\windows\system32\Extensions
2012-11-26 19:01:28 -------- d-----w- c:\users\johnc\appdata\local\Coupon Companion
2012-11-26 19:01:28 -------- d-----w- c:\programdata\Browser Manager
2012-11-26 19:01:23 -------- d-----w- c:\program files\Coupon Companion
2012-11-15 10:49:20 -------- d-----w- c:\users\johnc\inSync Share
2012-11-14 14:53:15 78336 ----a-w- c:\windows\system32\synceng.dll
2012-11-14 14:53:14 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-11-07 18:00:16 -------- d-----w- C:\inSync4
2012-11-07 18:00:13 -------- d-----w- c:\program files\Druva
.
==================== Find3M ====================
.
2012-11-15 14:43:03 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-15 14:43:03 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-15 14:17:33 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-09-14 18:28:53 2048 ----a-w- c:\windows\system32\tzres.dll
2012-08-31 19:57:38 132768 ----a-r- c:\windows\system32\drivers\symantec.cloud\ccSetx86.sys
2012-08-30 17:12:02 3968880 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- c:\windows\system32\ntoskrnl.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: TOSHIBA_ rev.LH00 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: >>UNKNOWN [0x83E12000]<< >>UNKNOWN [0x8D59B000]<< >>UNKNOWN [0x8D58A000]<< >>UNKNOWN [0x8D7F7000]<< >>UNKNOWN [0x8CC9A000]<< >>UNKNOWN [0x84225000]<< >>UNKNOWN [0x8CE28000]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x83E48BC5] -> \Device\Harddisk0\DR0[0x8921F418]
\Driver\Disk[0x8921D550] -> IRP_MJ_CREATE -> 0x8D59F39F
3 [0x8D59F59E] -> ntkrnlpa!IofCallDriver[0x83E48BC5] -> [0x8921F970]
\Driver\stdflt[0x891C76E8] -> IRP_MJ_CREATE -> 0x8D7F752E
5 [0x8D7F870C] -> ntkrnlpa!IofCallDriver[0x83E48BC5] -> [0x8767EA50]
\Driver\ACPI[0x868B6030] -> IRP_MJ_CREATE -> 0x8CCA34CC
7 [0x8CCA33D4] -> ntkrnlpa!IofCallDriver[0x83E48BC5] -> \Device\Ide\IAAStorageDevice-1[0x87262028]
\Driver\iaStor[0x8767CF38] -> IRP_MJ_CREATE -> 0x8CE4EE36
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:51:06.50 ===============
aswMBR LOG
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-11-27 07:43:39
-----------------------------
07:43:39.668 OS Version: Windows 6.1.7601 Service Pack 1
07:43:39.668 Number of processors: 8 586 0x1E05
07:43:39.668 ComputerName: JOHNCROWLEY1 UserName: JohnC
07:44:11.540 Initialize success
07:44:19.418 AVAST engine defs: 12112601
07:44:24.660 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
07:44:24.675 Disk 0 Vendor: TOSHIBA_ LH00 Size: 476940MB BusType: 8
07:44:25.159 Disk 0 MBR read successfully
07:44:25.175 Disk 0 MBR scan
07:44:25.190 Disk 0 Windows VISTA default MBR code
07:44:25.190 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
07:44:25.206 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 30021 MB offset 81920
07:44:25.237 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 446870 MB offset 61577145
07:44:25.253 Disk 0 scanning sectors +976768065
07:44:25.331 Disk 0 scanning C:\Windows\system32\drivers
07:44:37.265 Service scanning
07:45:08.279 Modules scanning
07:45:16.095 Disk 0 trace - called modules:
07:45:16.126 ntkrnlpa.exe CLASSPNP.SYS disk.sys stdfltn.sys ACPI.sys halmacpi.dll iaStor.sys
07:45:16.469 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89220030]
07:45:16.469 3 CLASSPNP.SYS[8d59459e] -> nt!IofCallDriver -> [0x8921f780]
07:45:16.485 5 stdfltn.sys[8d7c570c] -> nt!IofCallDriver -> [0x872c0908]
07:45:16.500 7 ACPI.sys[8cca93d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x872c6028]
07:45:19.027 AVAST engine scan C:\Windows
07:45:22.304 AVAST engine scan C:\Windows\system32
07:48:22.423 AVAST engine scan C:\Windows\system32\drivers
07:48:39.677 AVAST engine scan C:\Users\johnc
08:02:28.285 AVAST engine scan C:\ProgramData
08:03:24.570 Scan finished successfully
08:04:53.101 Disk 0 MBR has been saved successfully to "C:\Users\johnc\Desktop\MBR.dat"
08:04:53.132 The log file has been saved successfully to "C:\Users\johnc\Desktop\aswMBR.txt"
Thanks in advance for your help.
John
I have gotten the Claro Search redirect infection on my laptop. It takes over both Chrome and IE8.
I have read the "BEFORE You POST" section.
I ran SpyBot yesterday (twice) and it detected and removed Claro and Babylon but Claro is still there.
Here is the top of the log from yesterday's first SpyBot scan
Search results from Spybot - Search & Destroy
11/26/2012 3:58:11 PM
Scan took 00:18:33.
363 items found.
Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done)
C:\ProgramData\Babylon\
Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done)
C:\Users\johnc\AppData\Roaming\Babylon\
Directory.subfile=C:\Users\johnc\AppData\Roaming\Babylon\log_file.txt
Directory.subfile.size=8708
Directory.subfile.md5=147F0BF1BE261D172DB6EC6B36612A46
Directory.subfile.filedate=1353956505
Directory.subfile.filedatetext=2012-11-26 12:01:45
Claro.Toolbar: [SBI $47170986] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\claro.claroappCore
Here are the results from the second scan
Search results from Spybot - Search & Destroy
11/26/2012 4:16:48 PM
Scan took 00:13:23.
14 items found.
DoubleClick: [SBI $8E73A7FB] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)
MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-8915387-2129677417-1971066577-7837\Software\Microsoft\DirectInput\MostRecentApplication\Name
Registry Backup - DONE!
DDS Log
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.3.1
Run by JohnC at 16:32:50 on 2012-11-26
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3262.1503 [GMT -7:00]
.
AV: Symantec Endpoint Protection.cloud *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Symantec Endpoint Protection.cloud *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Symantec Endpoint Protection.cloud *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\IDT\WDM\STacSV.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
C:\Program Files\Druva\inSync\inSyncCPHwnet.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Druva\inSync\inSync.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\20.1.0.24\ccSvcHst.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\20.1.0.24\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\RightFax\FaxCtrl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Druva\inSync\inSyncGUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Druva\inSync\inSyncUSyncer.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Windows\system32\vssvc.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Symantec.cloud\PlatformAgent\ccSvcHst.exe
C:\Program Files\Symantec.cloud\AntiVirus\AVAgent.exe
C:\Program Files\Symantec.cloud\PlatformAgent\PAUI.exe
c:\program files\symantec.cloud\antivirus\ssDVAgent.exe
C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\20.1.0.24\ccSvcHst.exe
C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
C:\Windows\system32\schtasks.exe
C:\Windows\system32\conhost.exe
C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
C:\PROGRA~1\TIGERT~1\HOLIDA~1\HOLIDA~1.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\program files\coupon companion\coupon companion-bg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://my.yahoo.com/;_ylc=X3oDMTB1bTdjdnNyBF9TAzI3MTk0ODEEbG5rA215BHRpZANUcnZsU21wbA--
BHO: Coupon Companion: {11111111-1111-1111-1111-110011441193} - c:\program files\coupon companion\Coupon Companion.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\CoIEPlg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\ips\IPSBHO.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\oracle\javafx 2.0 runtime\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\CoIEPlg.dll
uRun: [Google Update] "c:\users\johnc\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [GoogleRdrNotify] "c:\program files\yonizaf\grain google reader notifier\GoogleReaderNotifier.exe"
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe
mRun: [IMSS] "c:\program files\intel\intel(r) management engine components\imss\PIconStartup.exe"
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe
mRun: [USCService] c:\program files\dell\dell controlpoint\security manager\BcmDeviceAndTaskStatusService.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [RightFAX Print-to-Fax Driver] c:\program files\rightfax\FaxCtrl.exe
mRun: [CaddieSyncConduit] c:\program files\skygolf\caddiesync express\CaddieSyncExpress.exe
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [SymantecPaui] "c:\program files\symantec.cloud\platformagent\PAUI.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Druva inSync] c:\program files\druva\insync\inSyncGUI.exe -l en
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\johnc\appdata\roaming\micros~1\windows\startm~1\programs\startup\holida~1.lnk - c:\program files\tiger technologies\holiday lights\Holiday Lights.exe
StartupFolder: c:\users\johnc\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\johnc\appdata\roaming\micros~1\windows\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\tdmnot~1.lnk - c:\program files\wave systems corp\trusted drive manager\TdmNotify.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.3.0/GarminAxControl_32.CAB
DPF: {01614D85-E2FC-40AC-BAB5-24CE29E94DB4} - hxxp://jpcfishcam.dyndns.org:1024/img/Viewer.cab
DPF: {174793AA-EAE2-4188-AFA5-064BE26901B1} - hxxp://www.digitalgsp.com/xvr/CXRMS_1,1,0,1.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://isecure.spectralogic.com/dana-cached/sc/JuniperSetupClient.cab
TCP: NameServer = 192.168.200.70 192.168.200.71
TCP: Interfaces\{8735282F-B28C-4E68-A87B-0934AB3765E6} : DHCPNameServer = 192.168.200.70 192.168.200.71
TCP: Interfaces\{D08F5DBC-3172-41D1-81C8-54C76756A629} : DHCPNameServer = 192.168.200.70 192.168.200.71
TCP: Interfaces\{D08F5DBC-3172-41D1-81C8-54C76756A629}\3427F677C656976416D696C697 : DHCPNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{D1EA2FC0-4CD4-4335-9279-27AA7301D965} : DHCPNameServer = 192.168.200.70 192.168.200.71
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Authentication Packages = msv1_0 wvauth
.
============= SERVICES / DRIVERS ===============
.
R0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\drivers\stdfltn.sys [2010-9-30 17072]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1401000.018\SymDS.sys [2012-10-15 368288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1401000.018\SymEFA.sys [2012-10-15 926880]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_20.1.0.24\definitions\bashdefs\20121106.001\BHDrvx86.sys [2012-10-23 995488]
R1 ccSet_Cloud;CC Standalone Settings Manager;c:\windows\system32\drivers\symantec.cloud\ccSetx86.sys [2012-8-31 132768]
R1 ccSet_NIS;Endpoint Protection.cloud Settings Manager;c:\windows\system32\drivers\nis\1401000.018\ccSetx86.sys [2012-10-15 134304]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_20.1.0.24\definitions\ipsdefs\20121123.001\IDSvix86.sys [2012-11-26 386720]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1401000.018\Ironx86.sys [2012-10-15 175264]
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\nis\1401000.018\symnets.sys [2012-10-15 338592]
R2 AESTFilters;Andrea ST Filters Service;c:\program files\idt\wdm\AEstSrv.exe [2010-9-30 81920]
R2 Browser Manager;Browser Manager;c:\programdata\browser manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe [2012-11-26 2402840]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2009-11-20 278304]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2010-3-23 812448]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2010-3-23 27040]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2010-2-8 386928]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2010-9-30 13336]
R2 InstallFilterService;FF Install Filter Service;c:\program files\stmicroelectronics\accelerometerp11\InstallFilterService.exe [2010-9-30 60928]
R2 inSyncCPHService;Druva inSync Client Service;c:\program files\druva\insync\inSyncCPHwnet.exe [2012-9-14 171008]
R2 NIS;Endpoint Protection.cloud;c:\program files\symantec.cloud\endpointprotectionagent\engine\20.1.0.24\ccSvcHst.exe [2012-10-15 143928]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2010-8-25 59904]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-11-26 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-11-26 1369624]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-11-26 168384]
R2 SsPaAdm;Symantec.cloud Cloud Agent;c:\program files\symantec.cloud\platformagent\ccSvcHst.exe [2012-8-31 138272]
R2 ssSpnAv;Symantec.cloud Endpoint Protection;c:\program files\symantec.cloud\antivirus\AVAgent.exe [2012-10-15 409040]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\intel\intel(r) management engine components\uns\UNS.exe [2010-9-30 2533400]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2010-9-30 42672]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2010-8-25 33832]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k6232.sys [2010-8-25 224424]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-8-10 106656]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\drivers\NETw5s32.sys [2009-9-15 6114816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-11-20 113152]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 CAATT;AT&T Con App Svc;c:\program files\at&t\communication manager\ConAppsSvc.exe [2008-11-20 125440]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2008-2-18 106624]
S3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2008-2-8 59648]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2011-12-28 132480]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2011-12-28 269824]
S3 rimspci;rimspci;c:\windows\system32\drivers\rimspe86.sys [2010-8-25 48640]
S3 rixdpcie;rixdpcie;c:\windows\system32\drivers\rixdpe86.sys [2010-8-25 38912]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-20 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-10-12 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2012-11-26 22:38:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-11-26 22:37:54 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-11-26 22:37:50 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-11-26 22:36:43 -------- d-----w- c:\users\johnc\appdata\local\Programs
2012-11-26 19:01:45 37888 ----a-w- c:\windows\system32\Holiday Lights.scr
2012-11-26 19:01:37 -------- d-----w- c:\program files\Tiger Technologies
2012-11-26 19:01:33 -------- d-----w- c:\users\johnc\appdata\roaming\Claro
2012-11-26 19:01:32 -------- d-----w- c:\windows\system32\searchplugins
2012-11-26 19:01:32 -------- d-----w- c:\windows\system32\Extensions
2012-11-26 19:01:28 -------- d-----w- c:\users\johnc\appdata\local\Coupon Companion
2012-11-26 19:01:28 -------- d-----w- c:\programdata\Browser Manager
2012-11-26 19:01:23 -------- d-----w- c:\program files\Coupon Companion
2012-11-15 10:49:20 -------- d-----w- c:\users\johnc\inSync Share
2012-11-14 14:53:15 78336 ----a-w- c:\windows\system32\synceng.dll
2012-11-14 14:53:14 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-11-07 18:00:16 -------- d-----w- C:\inSync4
2012-11-07 18:00:13 -------- d-----w- c:\program files\Druva
.
==================== Find3M ====================
.
2012-11-15 14:43:03 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-15 14:43:03 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-15 14:17:33 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-09-14 18:28:53 2048 ----a-w- c:\windows\system32\tzres.dll
2012-08-31 19:57:38 132768 ----a-r- c:\windows\system32\drivers\symantec.cloud\ccSetx86.sys
2012-08-30 17:12:02 3968880 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- c:\windows\system32\ntoskrnl.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: TOSHIBA_ rev.LH00 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: >>UNKNOWN [0x83E12000]<< >>UNKNOWN [0x8D59B000]<< >>UNKNOWN [0x8D58A000]<< >>UNKNOWN [0x8D7F7000]<< >>UNKNOWN [0x8CC9A000]<< >>UNKNOWN [0x84225000]<< >>UNKNOWN [0x8CE28000]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x83E48BC5] -> \Device\Harddisk0\DR0[0x8921F418]
\Driver\Disk[0x8921D550] -> IRP_MJ_CREATE -> 0x8D59F39F
3 [0x8D59F59E] -> ntkrnlpa!IofCallDriver[0x83E48BC5] -> [0x8921F970]
\Driver\stdflt[0x891C76E8] -> IRP_MJ_CREATE -> 0x8D7F752E
5 [0x8D7F870C] -> ntkrnlpa!IofCallDriver[0x83E48BC5] -> [0x8767EA50]
\Driver\ACPI[0x868B6030] -> IRP_MJ_CREATE -> 0x8CCA34CC
7 [0x8CCA33D4] -> ntkrnlpa!IofCallDriver[0x83E48BC5] -> \Device\Ide\IAAStorageDevice-1[0x87262028]
\Driver\iaStor[0x8767CF38] -> IRP_MJ_CREATE -> 0x8CE4EE36
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:51:06.50 ===============
aswMBR LOG
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-11-27 07:43:39
-----------------------------
07:43:39.668 OS Version: Windows 6.1.7601 Service Pack 1
07:43:39.668 Number of processors: 8 586 0x1E05
07:43:39.668 ComputerName: JOHNCROWLEY1 UserName: JohnC
07:44:11.540 Initialize success
07:44:19.418 AVAST engine defs: 12112601
07:44:24.660 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
07:44:24.675 Disk 0 Vendor: TOSHIBA_ LH00 Size: 476940MB BusType: 8
07:44:25.159 Disk 0 MBR read successfully
07:44:25.175 Disk 0 MBR scan
07:44:25.190 Disk 0 Windows VISTA default MBR code
07:44:25.190 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
07:44:25.206 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 30021 MB offset 81920
07:44:25.237 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 446870 MB offset 61577145
07:44:25.253 Disk 0 scanning sectors +976768065
07:44:25.331 Disk 0 scanning C:\Windows\system32\drivers
07:44:37.265 Service scanning
07:45:08.279 Modules scanning
07:45:16.095 Disk 0 trace - called modules:
07:45:16.126 ntkrnlpa.exe CLASSPNP.SYS disk.sys stdfltn.sys ACPI.sys halmacpi.dll iaStor.sys
07:45:16.469 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89220030]
07:45:16.469 3 CLASSPNP.SYS[8d59459e] -> nt!IofCallDriver -> [0x8921f780]
07:45:16.485 5 stdfltn.sys[8d7c570c] -> nt!IofCallDriver -> [0x872c0908]
07:45:16.500 7 ACPI.sys[8cca93d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x872c6028]
07:45:19.027 AVAST engine scan C:\Windows
07:45:22.304 AVAST engine scan C:\Windows\system32
07:48:22.423 AVAST engine scan C:\Windows\system32\drivers
07:48:39.677 AVAST engine scan C:\Users\johnc
08:02:28.285 AVAST engine scan C:\ProgramData
08:03:24.570 Scan finished successfully
08:04:53.101 Disk 0 MBR has been saved successfully to "C:\Users\johnc\Desktop\MBR.dat"
08:04:53.132 The log file has been saved successfully to "C:\Users\johnc\Desktop\aswMBR.txt"
Thanks in advance for your help.
John