I have used Spybot, Malwarebytes Anti-malware, and Lavasoft Ad-aware, and I have not been able to get rid of the infection.
When I attempt to click on google search results, the browser is redirected.
The DDS report follows; thank you for your help!
-----------------------------------------------------------
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Admin at 1:07:23.78 on Sat 03/26/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1326 [GMT -7:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: ZoneAlarm Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS.0\system32\Ati2evxx.exe
C:\WINDOWS.0\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS.0\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS.0\Explorer.EXE
C:\WINDOWS.0\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\gearsec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS.0\system32\lkads.exe
C:\WINDOWS.0\system32\lktsrv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS.0\system32\nisvcloc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS.0\system32\tcpsvcs.exe
C:\WINDOWS.0\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS.0\System32\svchost.exe -k HTTPFilter
C:\WINDOWS.0\system32\msiexec.exe
C:\WINDOWS.0\System32\svchost.exe -k netsvcs
C:\TMP\ose00001.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\My Documents\Downloads\dds.com
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mURLSearchHooks: H - No File
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0401.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: ZoneAlarm Spy Blocker Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0401.0\npwinext.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows.0\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\admin\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IgfxTray] c:\windows.0\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows.0\system32\hkcmd.exe
mRun: [AtiPTA] atiptaxx.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0401.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [NI Background Service] c:\program files\national instruments\shared\update service\BackgroundService.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAQQBFAEEAWQAtAFQAMwBMAFUARQAtAE4ATAAzAEQAQQAtAEMAQgBVAEsASAAtAEoARgA3AE0AOQA"&"inst=NwA3AC0AMQAwADAAMwA2ADQAOQAyADQALQBCAEEAKwAxAC0ASwBWADMAKwA3AC0AWABMACsAMQAtAFQAMgAtAEIANAAtAEYATAArADkALQBYAE8AMwA2ACsAMQAtAEYAOQBNADcAQwArADUALQBGADkATQAxADAAQgArADEA"&"prod=90"&"ver=9.0.872
dRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
dRunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoSMHelp = 1 (0x1)
dPolicies-explorer: StartMenuLogoff = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
Trusted Zone: uno.edu\cas
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows.0\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\j13l6xiy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=ZUGO&form=ZGAADF&q=
FF - plugin: c:\documents and settings\admin\application data\move networks\plugins\npqmp071701000002.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\admin\application data\Move Networks
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows.0\system32\drivers\Lbd.sys [2011-3-24 64512]
R1 vsdatant;vsdatant;c:\windows.0\system32\vsdatant.sys [2009-3-27 532224]
R2 gearsec;gearsec;c:\windows.0\system32\gearsec.exe [2005-11-30 58952]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-3-22 1405384]
R2 vsmon;TrueVector Internet Monitor;c:\windows.0\system32\zonelabs\vsmon.exe -service --> c:\windows.0\system32\zonelabs\vsmon.exe -service [?]
R3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;c:\windows.0\system32\drivers\WMP300Nv1.sys [2010-3-21 822400]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows.0\system32\drivers\avgtdix.sys --> c:\windows.0\system32\drivers\avgtdix.sys [?]
S2 SSPORT;SSPORT;\??\c:\windows.0\system32\drivers\ssport.sys --> c:\windows.0\system32\drivers\SSPORT.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-3-22 15232]
S3 NMUSB;NMUSB;c:\windows.0\system32\drivers\Nmusb.sys [2010-7-9 25056]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-3-27 464264]
S4 WMP300NSvc;WMP300NSvc;c:\program files\linksys\wmp300n\WLService.exe [2010-7-12 53307]
.
=============== Created Last 30 ================
.
2011-03-26 06:34:24 -------- d-----w- c:\program files\ESET
2011-03-26 06:30:18 73728 ----a-w- c:\windows.0\system32\javacpl.cpl
2011-03-24 20:16:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-24 20:16:00 -------- d-----w- c:\docume~1\alluse~1.0\applic~1\Spybot - Search & Destroy
2011-03-24 17:11:26 16432 ----a-w- c:\windows.0\system32\lsdelete.exe
2011-03-24 16:52:56 64512 ----a-w- c:\windows.0\system32\drivers\Lbd.sys
2011-03-24 16:52:20 98392 ----a-w- c:\windows.0\system32\drivers\SBREDrv.sys
2011-03-24 16:49:52 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\Sunbelt Software
2011-03-24 16:46:42 -------- dc-h--w- c:\docume~1\alluse~1.0\applic~1\{FE41BDC7-CD33-4350-8A15-26EFBE20A0FE}
2011-03-24 16:46:20 -------- d-----w- c:\program files\Lavasoft
2011-03-23 18:09:21 -------- d-----w- C:\OutputFolder
2011-03-23 18:07:35 921600 ----a-w- c:\windows.0\system32\vorbisenc.dll
2011-03-23 18:07:35 45056 ----a-w- c:\windows.0\system32\ogg.dll
2011-03-23 18:07:35 237568 ----a-w- c:\windows.0\system32\OggDS.dll
2011-03-23 18:07:35 188416 ----a-w- c:\windows.0\system32\vorbis.dll
2011-03-23 18:07:34 28672 ----a-w- c:\windows.0\system32\AVEQT.dll
2011-03-23 18:07:34 129024 ----a-w- c:\windows.0\system32\AVERM.dll
2011-03-23 18:07:33 -------- d-----w- c:\program files\Ultra Mobile 3GP Video Converter
2011-03-23 17:53:32 -------- d-----w- c:\program files\Search Toolbar
2011-03-23 17:53:26 -------- d-----w- c:\program files\YTD Setup
2011-03-23 06:50:29 -------- d-----w- c:\program files\Windows Media Connect 2
2011-03-17 16:32:53 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\uTorrentBar
2011-03-17 16:30:33 -------- d-----w- c:\program files\Conduit
2011-03-17 16:30:05 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\TMP
2011-03-14 16:30:59 5632 ----a-w- c:\windows.0\system32\dllcache\kbda1.dll
2011-03-14 06:27:57 -------- d-----w- c:\documents and settings\all users.windows.0\Microsoft
2011-03-14 06:23:59 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-03-14 06:23:48 -------- d-----w- c:\windows.0\SHELLNEW
2011-03-14 01:04:39 -------- d-----w- c:\docume~1\alluse~1.0\applic~1\Virtualized Applications
2011-03-13 23:47:05 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\SoftGrid Client
2011-03-13 23:47:03 -------- d-----w- c:\docume~1\admin\applic~1\SoftGrid Client
2011-03-13 23:42:36 221184 ----a-w- c:\windows.0\system32\wmpns.dll
2011-03-13 23:42:12 -------- d-----w- c:\windows.0\system32\wbem\snmp
2011-03-13 23:42:11 -------- d-----w- c:\windows.0\system32\xircom
2011-03-13 23:24:53 46592 ------w- c:\windows.0\system32\drivers\irbus.sys
2011-03-13 23:22:15 19456 ----a-w- c:\windows.0\system32\dllcache\agt0401.dll
2011-03-13 23:21:54 19456 ----a-w- c:\windows.0\system32\dllcache\agt040d.dll
2011-03-13 23:18:19 56623 ------w- c:\windows.0\system32\drivers\ati1btxx.sys
2011-03-13 23:17:08 19569 ----a-w- c:\windows.0\002825_.tmp
2011-03-13 21:28:10 30512 ----a-w- c:\windows.0\system32\spool\prtprocs\w32x86\mdippr.dll
2011-03-13 21:28:10 30512 ----a-w- c:\windows.0\system32\mdimon.dll
2011-03-13 21:27:57 33104 ----a-w- c:\windows.0\system32\spool\prtprocs\w32x86\msonpppr.dll
2011-03-13 21:27:56 32592 ----a-w- c:\windows.0\system32\msonpmon.dll
2011-03-13 21:14:20 -------- d-----w- c:\docume~1\admin\applic~1\TP
.
==================== Find3M ====================
.
2011-03-26 06:29:58 472808 ----a-w- c:\windows.0\system32\deployJava1.dll
2011-02-24 19:14:21 398760 ----a-r- c:\windows.0\system32\cpnprt2.cid
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD2500YD-01NVB1 rev.10.02E01 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-e
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A7A9439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a7af7d0]; MOV EAX, [0x8a7af84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37C5] -> \Device\Harddisk0\DR0[0x8A806AB8]
3 CLASSPNP[0xF7637FD7] -> nt!IofCallDriver[0x804E37C5] -> [0x8A725B58]
\Driver\atapi[0x8A7953D0] -> IRP_MJ_CREATE -> 0x8A7A9439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskWDC_WD2500YD-01NVB1_____________________10.02E01#5&31f0d48e&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A7A927F
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 1:08:48.79 ===============
When I attempt to click on google search results, the browser is redirected.
The DDS report follows; thank you for your help!
-----------------------------------------------------------
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Admin at 1:07:23.78 on Sat 03/26/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1326 [GMT -7:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: ZoneAlarm Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS.0\system32\Ati2evxx.exe
C:\WINDOWS.0\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS.0\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS.0\Explorer.EXE
C:\WINDOWS.0\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\gearsec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS.0\system32\lkads.exe
C:\WINDOWS.0\system32\lktsrv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS.0\system32\nisvcloc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS.0\system32\tcpsvcs.exe
C:\WINDOWS.0\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS.0\System32\svchost.exe -k HTTPFilter
C:\WINDOWS.0\system32\msiexec.exe
C:\WINDOWS.0\System32\svchost.exe -k netsvcs
C:\TMP\ose00001.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\My Documents\Downloads\dds.com
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mURLSearchHooks: H - No File
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0401.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: ZoneAlarm Spy Blocker Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0401.0\npwinext.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows.0\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\admin\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IgfxTray] c:\windows.0\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows.0\system32\hkcmd.exe
mRun: [AtiPTA] atiptaxx.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0401.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [NI Background Service] c:\program files\national instruments\shared\update service\BackgroundService.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAQQBFAEEAWQAtAFQAMwBMAFUARQAtAE4ATAAzAEQAQQAtAEMAQgBVAEsASAAtAEoARgA3AE0AOQA"&"inst=NwA3AC0AMQAwADAAMwA2ADQAOQAyADQALQBCAEEAKwAxAC0ASwBWADMAKwA3AC0AWABMACsAMQAtAFQAMgAtAEIANAAtAEYATAArADkALQBYAE8AMwA2ACsAMQAtAEYAOQBNADcAQwArADUALQBGADkATQAxADAAQgArADEA"&"prod=90"&"ver=9.0.872
dRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
dRunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoSMHelp = 1 (0x1)
dPolicies-explorer: StartMenuLogoff = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
Trusted Zone: uno.edu\cas
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows.0\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\j13l6xiy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=ZUGO&form=ZGAADF&q=
FF - plugin: c:\documents and settings\admin\application data\move networks\plugins\npqmp071701000002.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\admin\application data\Move Networks
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows.0\system32\drivers\Lbd.sys [2011-3-24 64512]
R1 vsdatant;vsdatant;c:\windows.0\system32\vsdatant.sys [2009-3-27 532224]
R2 gearsec;gearsec;c:\windows.0\system32\gearsec.exe [2005-11-30 58952]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-3-22 1405384]
R2 vsmon;TrueVector Internet Monitor;c:\windows.0\system32\zonelabs\vsmon.exe -service --> c:\windows.0\system32\zonelabs\vsmon.exe -service [?]
R3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;c:\windows.0\system32\drivers\WMP300Nv1.sys [2010-3-21 822400]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows.0\system32\drivers\avgtdix.sys --> c:\windows.0\system32\drivers\avgtdix.sys [?]
S2 SSPORT;SSPORT;\??\c:\windows.0\system32\drivers\ssport.sys --> c:\windows.0\system32\drivers\SSPORT.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-3-22 15232]
S3 NMUSB;NMUSB;c:\windows.0\system32\drivers\Nmusb.sys [2010-7-9 25056]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-3-27 464264]
S4 WMP300NSvc;WMP300NSvc;c:\program files\linksys\wmp300n\WLService.exe [2010-7-12 53307]
.
=============== Created Last 30 ================
.
2011-03-26 06:34:24 -------- d-----w- c:\program files\ESET
2011-03-26 06:30:18 73728 ----a-w- c:\windows.0\system32\javacpl.cpl
2011-03-24 20:16:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-24 20:16:00 -------- d-----w- c:\docume~1\alluse~1.0\applic~1\Spybot - Search & Destroy
2011-03-24 17:11:26 16432 ----a-w- c:\windows.0\system32\lsdelete.exe
2011-03-24 16:52:56 64512 ----a-w- c:\windows.0\system32\drivers\Lbd.sys
2011-03-24 16:52:20 98392 ----a-w- c:\windows.0\system32\drivers\SBREDrv.sys
2011-03-24 16:49:52 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\Sunbelt Software
2011-03-24 16:46:42 -------- dc-h--w- c:\docume~1\alluse~1.0\applic~1\{FE41BDC7-CD33-4350-8A15-26EFBE20A0FE}
2011-03-24 16:46:20 -------- d-----w- c:\program files\Lavasoft
2011-03-23 18:09:21 -------- d-----w- C:\OutputFolder
2011-03-23 18:07:35 921600 ----a-w- c:\windows.0\system32\vorbisenc.dll
2011-03-23 18:07:35 45056 ----a-w- c:\windows.0\system32\ogg.dll
2011-03-23 18:07:35 237568 ----a-w- c:\windows.0\system32\OggDS.dll
2011-03-23 18:07:35 188416 ----a-w- c:\windows.0\system32\vorbis.dll
2011-03-23 18:07:34 28672 ----a-w- c:\windows.0\system32\AVEQT.dll
2011-03-23 18:07:34 129024 ----a-w- c:\windows.0\system32\AVERM.dll
2011-03-23 18:07:33 -------- d-----w- c:\program files\Ultra Mobile 3GP Video Converter
2011-03-23 17:53:32 -------- d-----w- c:\program files\Search Toolbar
2011-03-23 17:53:26 -------- d-----w- c:\program files\YTD Setup
2011-03-23 06:50:29 -------- d-----w- c:\program files\Windows Media Connect 2
2011-03-17 16:32:53 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\uTorrentBar
2011-03-17 16:30:33 -------- d-----w- c:\program files\Conduit
2011-03-17 16:30:05 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\TMP
2011-03-14 16:30:59 5632 ----a-w- c:\windows.0\system32\dllcache\kbda1.dll
2011-03-14 06:27:57 -------- d-----w- c:\documents and settings\all users.windows.0\Microsoft
2011-03-14 06:23:59 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-03-14 06:23:48 -------- d-----w- c:\windows.0\SHELLNEW
2011-03-14 01:04:39 -------- d-----w- c:\docume~1\alluse~1.0\applic~1\Virtualized Applications
2011-03-13 23:47:05 -------- d-----w- c:\docume~1\admin\locals~1\applic~1\SoftGrid Client
2011-03-13 23:47:03 -------- d-----w- c:\docume~1\admin\applic~1\SoftGrid Client
2011-03-13 23:42:36 221184 ----a-w- c:\windows.0\system32\wmpns.dll
2011-03-13 23:42:12 -------- d-----w- c:\windows.0\system32\wbem\snmp
2011-03-13 23:42:11 -------- d-----w- c:\windows.0\system32\xircom
2011-03-13 23:24:53 46592 ------w- c:\windows.0\system32\drivers\irbus.sys
2011-03-13 23:22:15 19456 ----a-w- c:\windows.0\system32\dllcache\agt0401.dll
2011-03-13 23:21:54 19456 ----a-w- c:\windows.0\system32\dllcache\agt040d.dll
2011-03-13 23:18:19 56623 ------w- c:\windows.0\system32\drivers\ati1btxx.sys
2011-03-13 23:17:08 19569 ----a-w- c:\windows.0\002825_.tmp
2011-03-13 21:28:10 30512 ----a-w- c:\windows.0\system32\spool\prtprocs\w32x86\mdippr.dll
2011-03-13 21:28:10 30512 ----a-w- c:\windows.0\system32\mdimon.dll
2011-03-13 21:27:57 33104 ----a-w- c:\windows.0\system32\spool\prtprocs\w32x86\msonpppr.dll
2011-03-13 21:27:56 32592 ----a-w- c:\windows.0\system32\msonpmon.dll
2011-03-13 21:14:20 -------- d-----w- c:\docume~1\admin\applic~1\TP
.
==================== Find3M ====================
.
2011-03-26 06:29:58 472808 ----a-w- c:\windows.0\system32\deployJava1.dll
2011-02-24 19:14:21 398760 ----a-r- c:\windows.0\system32\cpnprt2.cid
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD2500YD-01NVB1 rev.10.02E01 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-e
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A7A9439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a7af7d0]; MOV EAX, [0x8a7af84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37C5] -> \Device\Harddisk0\DR0[0x8A806AB8]
3 CLASSPNP[0xF7637FD7] -> nt!IofCallDriver[0x804E37C5] -> [0x8A725B58]
\Driver\atapi[0x8A7953D0] -> IRP_MJ_CREATE -> 0x8A7A9439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskWDC_WD2500YD-01NVB1_____________________10.02E01#5&31f0d48e&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A7A927F
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 1:08:48.79 ===============