Hello,
I have a very annoying little malware hiding somewhere in my computer that hijacks any link I click on and redirects me to advertisement sites. The initial redirect is to yafraudcheckonline.com which bounces me to some other site. It will always randomly open a new window and take me to sites while I'm online. Avast! doesn't even show there's an infection, nor does MalwareBytes. I've read a post from someone with the same problem but they were running Windows7 and I'm using XP Media Center Edition. I have a MBRCheck log ready as well, here's the DDS
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 16:31:29.04 on Wed 03/09/2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.406 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled*
FW: AVG Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\NETGEAR\WN111v2\WN111V2.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\HP_Administrator\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com?o=14196&l=dis
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\celebrity toolbar\tbhelper.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\celebrity toolbar\tbcore3.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\drop down deals\YontooIEClient.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Celebrity Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\celebrity toolbar\tbcore3.dll
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [VX3000] c:\windows\vVX3000.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
dRun: [CE8SIIFGSU] c:\windows\temp\Kdh.exe
dRun: [fmdvugru] c:\windows\temp\rtohdowlp\msnuebbhmof.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wn111v2\WN111V2.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: {B836BCE7-53A9-4AC1-B21C-BC44A2B2BDC2} = 192.168.100.11,192.168.100.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 nwprovau
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\hp_adm~1\applic~1\mozilla\firefox\profiles\h1fnazoe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-2-18 357968]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-2-18 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-2-18 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-2-18 40384]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2003-7-24 17149]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2008-10-1 57440]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [2009-1-14 458752]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2008-12-13 133104]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-4-16 36608]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\netgear\wn111v2\jswpsapi.exe [2008-2-27 360547]
.
=============== Created Last 30 ================
.
2011-03-01 06:14:52 -------- d-----w- c:\docume~1\hp_adm~1\locals~1\applic~1\SecondLife
2011-03-01 06:14:05 -------- d-----w- c:\program files\SecondLifeViewer2
2011-02-25 20:57:25 -------- d-----w- c:\program files\Drop Down Deals
2011-02-25 20:57:23 -------- d-----w- c:\docume~1\alluse~1\applic~1\Tarma Installer
2011-02-18 16:43:56 -------- d-----w- c:\program files\Yontoo Layers Client
2011-02-18 07:38:08 57408 ----a-w- c:\windows\system32\drivers\wsimd.sys
2011-02-18 07:37:56 -------- d-----w- c:\program files\Atheros
2011-02-18 07:21:37 357968 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-18 07:21:09 38848 ----a-w- c:\windows\avastSS.scr
2011-02-18 07:20:48 -------- d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2011-02-18 06:40:20 -------- d-----w- c:\program files\Perfect Uninstaller
.
==================== Find3M ====================
.
2011-01-21 14:44:37 439296 ------w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 17:26:00 730112 ------w- c:\windows\system32\lsasrv.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3200820AS rev.3.AHG -> Harddisk0\DR0 -> \Device\Ide\IdePort2 P2T0L0-e
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8615F5DC]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x861657b8]; MOV EAX, [0x86165834]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x86099AB8]
3 CLASSPNP[0xF7610FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000080[0x861E0F18]
5 ACPI[0xF7487620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x860C8940]
\Driver\atapi[0x86126F38] -> IRP_MJ_CREATE -> 0x8615F5DC
kernel: MBR read successfully
_asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; REP MOVSB ; JMP FAR 0x7a0:0x5c; }
detected disk devices:
\Device\Ide\IdeDeviceP2T0L0-e -> \??\IDE#DiskST3200820AS_____________________________3.AHG___#5&320f6b24&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8615F422
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:32:58.82 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/27/2010 6:30:06 AM
System Uptime: 3/9/2011 3:37:38 AM (13 hours ago)
.
Motherboard: ASUSTek Computer INC. | | Pyrite
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket AM2 | 2004/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 177 GiB total, 103.242 GiB free.
D: is FIXED (FAT32) - 9 GiB total, 0.575 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 466 GiB total, 458.037 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0001
Manufacturer: AVG Technologies
Name: WAN Miniport (IPX) - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0001
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0002
Manufacturer: AVG Technologies
Name: Microsoft TV/Video Connection - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0002
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0003
Manufacturer: AVG Technologies
Name: NVIDIA nForce Networking Controller - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0003
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0004
Manufacturer: AVG Technologies
Name: WAN Miniport (IP) - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0004
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0005
Manufacturer: AVG Technologies
Name: HP EN1207D-TX PCI 10/100 Fast Ethernet Adapter - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0005
Service: Avgfwdx
.
==== System Restore Points ===================
.
RP382: 12/9/2010 5:54:05 PM - System Checkpoint
RP383: 12/10/2010 6:42:29 PM - System Checkpoint
RP384: 12/11/2010 7:38:51 PM - System Checkpoint
RP385: 12/12/2010 8:38:51 PM - System Checkpoint
RP386: 12/13/2010 9:38:51 PM - System Checkpoint
RP387: 12/14/2010 10:45:36 PM - System Checkpoint
RP388: 12/15/2010 11:38:53 PM - System Checkpoint
RP389: 12/16/2010 3:00:26 AM - Software Distribution Service 3.0
RP390: 12/17/2010 3:11:29 AM - System Checkpoint
RP391: 12/18/2010 4:49:57 AM - System Checkpoint
RP392: 12/19/2010 5:29:23 AM - System Checkpoint
RP393: 12/20/2010 5:46:19 AM - System Checkpoint
RP394: 12/21/2010 6:54:59 AM - System Checkpoint
RP395: 12/22/2010 7:28:23 AM - System Checkpoint
RP396: 12/23/2010 8:25:10 AM - System Checkpoint
RP397: 12/24/2010 9:25:11 AM - System Checkpoint
RP398: 12/25/2010 10:26:15 AM - System Checkpoint
RP399: 12/26/2010 11:26:15 AM - System Checkpoint
RP400: 12/27/2010 12:25:12 PM - System Checkpoint
RP401: 12/28/2010 4:37:50 PM - System Checkpoint
RP402: 12/29/2010 5:51:05 PM - System Checkpoint
RP403: 12/30/2010 6:24:38 PM - System Checkpoint
RP404: 12/31/2010 7:12:23 PM - System Checkpoint
RP405: 1/2/2011 6:13:29 AM - System Checkpoint
RP406: 1/3/2011 7:12:23 AM - System Checkpoint
RP407: 1/4/2011 8:12:24 AM - System Checkpoint
RP408: 1/5/2011 9:12:23 AM - System Checkpoint
RP409: 1/6/2011 9:29:35 AM - System Checkpoint
RP410: 1/7/2011 10:19:52 AM - System Checkpoint
RP411: 1/8/2011 10:20:59 AM - System Checkpoint
RP412: 1/9/2011 11:19:52 AM - System Checkpoint
RP413: 1/10/2011 11:30:05 AM - System Checkpoint
RP414: 1/11/2011 12:44:53 PM - System Checkpoint
RP415: 1/12/2011 1:30:05 PM - System Checkpoint
RP416: 1/12/2011 2:02:35 PM - Software Distribution Service 3.0
RP417: 1/13/2011 2:45:57 PM - System Checkpoint
RP418: 1/14/2011 3:33:42 PM - System Checkpoint
RP419: 1/15/2011 4:52:02 PM - System Checkpoint
RP420: 1/16/2011 5:46:57 PM - System Checkpoint
RP421: 1/17/2011 7:41:20 PM - System Checkpoint
RP422: 1/18/2011 8:03:27 PM - System Checkpoint
RP423: 1/19/2011 8:32:28 PM - System Checkpoint
RP424: 1/20/2011 9:32:28 PM - System Checkpoint
RP425: 1/21/2011 9:57:39 PM - System Checkpoint
RP426: 1/23/2011 11:26:40 PM - System Checkpoint
RP427: 1/25/2011 1:17:27 AM - System Checkpoint
RP428: 1/26/2011 1:58:13 AM - System Checkpoint
RP429: 1/27/2011 4:12:49 AM - System Checkpoint
RP430: 1/28/2011 4:58:13 AM - System Checkpoint
RP431: 1/29/2011 5:09:13 AM - System Checkpoint
RP432: 1/30/2011 5:55:48 AM - System Checkpoint
RP433: 1/31/2011 6:55:47 AM - System Checkpoint
RP434: 2/1/2011 7:55:47 AM - System Checkpoint
RP435: 2/2/2011 8:55:47 AM - System Checkpoint
RP436: 2/3/2011 10:05:56 AM - System Checkpoint
RP437: 2/4/2011 11:05:54 AM - System Checkpoint
RP438: 2/5/2011 12:05:54 PM - System Checkpoint
RP439: 2/6/2011 1:05:53 PM - System Checkpoint
RP440: 2/7/2011 1:48:18 PM - System Checkpoint
RP441: 2/8/2011 2:25:40 PM - System Checkpoint
RP442: 2/9/2011 3:25:41 PM - System Checkpoint
RP443: 2/9/2011 9:19:13 PM - Software Distribution Service 3.0
RP444: 2/10/2011 10:11:05 PM - System Checkpoint
RP445: 2/11/2011 11:10:58 PM - System Checkpoint
RP446: 2/13/2011 12:10:57 AM - System Checkpoint
RP447: 2/14/2011 12:56:02 AM - System Checkpoint
RP448: 2/15/2011 2:29:17 PM - System Checkpoint
RP449: 2/16/2011 4:43:14 PM - System Checkpoint
RP450: 2/17/2011 6:19:06 PM - System Checkpoint
RP451: 2/18/2011 12:40:35 AM - Installed AVG 2011
RP452: 2/18/2011 12:40:42 AM - Removed AVG 2011
RP453: 2/18/2011 1:10:40 AM - Removed AVG 2011
RP454: 2/18/2011 1:31:36 AM - Installed AVG 2011
RP455: 2/18/2011 1:34:32 AM - Installed AVG 2011
RP456: 2/18/2011 1:34:38 AM - Removed AVG 2011
RP457: 2/18/2011 2:20:48 AM - avast! Pro Antivirus Setup
RP458: 2/18/2011 2:32:24 AM - Configured RangeMax Wireless-N USB Adapter WN111v2
RP459: 2/18/2011 2:37:10 AM - Installed RangeMax Wireless-N USB Adapter WN111v2
RP460: 2/19/2011 5:37:59 AM - System Checkpoint
RP461: 2/20/2011 6:31:18 AM - System Checkpoint
RP462: 2/21/2011 7:02:52 AM - System Checkpoint
RP463: 2/22/2011 7:03:49 AM - System Checkpoint
RP464: 2/23/2011 7:08:25 AM - System Checkpoint
RP465: 2/24/2011 7:55:26 AM - System Checkpoint
RP466: 2/25/2011 7:57:54 AM - System Checkpoint
RP467: 2/26/2011 8:29:33 AM - System Checkpoint
RP468: 2/27/2011 8:41:53 AM - System Checkpoint
RP469: 2/28/2011 8:54:17 AM - System Checkpoint
RP470: 3/1/2011 8:58:04 AM - System Checkpoint
RP471: 3/2/2011 9:48:32 AM - System Checkpoint
RP472: 3/3/2011 10:21:51 AM - System Checkpoint
RP473: 3/4/2011 10:55:54 AM - System Checkpoint
RP474: 3/5/2011 11:55:54 AM - System Checkpoint
RP475: 3/6/2011 12:55:54 PM - System Checkpoint
RP476: 3/7/2011 4:00:37 PM - System Checkpoint
RP477: 3/8/2011 6:27:08 PM - System Checkpoint
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader 7.0.5
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Apple Application Support
Apple Software Update
avast! Pro Antivirus
AVG PC Tuneup 2011
CamStudio
Codec Pack - All In 1 6.0.3.0
Connect
Data Fax SoftModem with SmartCP
Destinations
DeviceManagementQFolder
Enhanced Multimedia Keyboard Solution
Fraps (remove only)
FrostWire 4.21.3
gBurner
Google Earth
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Player 10 (KB903157)
HP Boot Optimizer
HP DigitalMedia Archive
HP DVD Play 2.1
HP Imaging Device Functions 7.0
HP Photosmart for Media Center PC
HP Update
HP Web Helper
HPPhotoSmartExpress
HpSdpAppCoreApp
J2SE Runtime Environment 5.0 Update 6
Java Auto Updater
Java(TM) 6 Update 22
kuler
LightScribe 1.4.105.1
Macromedia Flash Player 8
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Corporation
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft LifeCam
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.13)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NVIDIA Drivers
Otto
PC Connectivity Solution
PDF Settings CS4
Perfect Uninstaller v6.3.3.8
Photoshop Camera Raw
PokerStars
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
RangeMax Wireless-N USB Adapter WN111v2
Realtek High Definition Audio Driver
ROCKIT PRO DJ 4.0
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
SamsungConnectivityCableDriver
SecondLifeViewer2 (remove only)
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Segoe UI
Sierra Utilities
Skype™ 4.1
Sonic Express Labeler
Suite Shared Configuration CS4
Unload
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office Outlook 2007 (KB2412171)
Update for Outlook 2007 Junk Email Filter (KB2492475)
Updates from HP (remove only)
VLC media player 1.1.4
WebFldrs XP
WildTangent Web Driver
Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WN111v2
Yahoo! Toolbar for Internet Explorer
.
==== Event Viewer Messages From Past Week ========
.
3/7/2011 3:06:33 AM, error: Service Control Manager [7022] - The MSCamSvc service hung on starting.
3/7/2011 3:05:12 AM, error: Service Control Manager [7024] - The Routing and Remote Access service terminated with service-specific error 2 (0x2).
3/7/2011 3:05:11 AM, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found.
3/7/2011 3:05:10 AM, error: RemoteAccess [20103] - Unable to load C:\WINDOWS\System32\iprtrmgr.dll.
3/7/2011 12:50:45 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
3/7/2011 12:48:45 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
3/7/2011 1:34:39 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/4/2011 3:54:11 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
3/4/2011 3:54:11 AM, error: Service Control Manager [7022] - The Automatic Updates service hung on starting.
3/3/2011 7:21:11 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 30469A072EFC has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
I have a very annoying little malware hiding somewhere in my computer that hijacks any link I click on and redirects me to advertisement sites. The initial redirect is to yafraudcheckonline.com which bounces me to some other site. It will always randomly open a new window and take me to sites while I'm online. Avast! doesn't even show there's an infection, nor does MalwareBytes. I've read a post from someone with the same problem but they were running Windows7 and I'm using XP Media Center Edition. I have a MBRCheck log ready as well, here's the DDS
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 16:31:29.04 on Wed 03/09/2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.406 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled*
FW: AVG Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\NETGEAR\WN111v2\WN111V2.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\HP_Administrator\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com?o=14196&l=dis
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\celebrity toolbar\tbhelper.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\celebrity toolbar\tbcore3.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\drop down deals\YontooIEClient.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Celebrity Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\celebrity toolbar\tbcore3.dll
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [VX3000] c:\windows\vVX3000.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
dRun: [CE8SIIFGSU] c:\windows\temp\Kdh.exe
dRun: [fmdvugru] c:\windows\temp\rtohdowlp\msnuebbhmof.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wn111v2\WN111V2.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: {B836BCE7-53A9-4AC1-B21C-BC44A2B2BDC2} = 192.168.100.11,192.168.100.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 nwprovau
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\hp_adm~1\applic~1\mozilla\firefox\profiles\h1fnazoe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-2-18 357968]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-2-18 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-2-18 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-2-18 40384]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2003-7-24 17149]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2008-10-1 57440]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [2009-1-14 458752]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2008-12-13 133104]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-4-16 36608]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\netgear\wn111v2\jswpsapi.exe [2008-2-27 360547]
.
=============== Created Last 30 ================
.
2011-03-01 06:14:52 -------- d-----w- c:\docume~1\hp_adm~1\locals~1\applic~1\SecondLife
2011-03-01 06:14:05 -------- d-----w- c:\program files\SecondLifeViewer2
2011-02-25 20:57:25 -------- d-----w- c:\program files\Drop Down Deals
2011-02-25 20:57:23 -------- d-----w- c:\docume~1\alluse~1\applic~1\Tarma Installer
2011-02-18 16:43:56 -------- d-----w- c:\program files\Yontoo Layers Client
2011-02-18 07:38:08 57408 ----a-w- c:\windows\system32\drivers\wsimd.sys
2011-02-18 07:37:56 -------- d-----w- c:\program files\Atheros
2011-02-18 07:21:37 357968 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-18 07:21:09 38848 ----a-w- c:\windows\avastSS.scr
2011-02-18 07:20:48 -------- d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2011-02-18 06:40:20 -------- d-----w- c:\program files\Perfect Uninstaller
.
==================== Find3M ====================
.
2011-01-21 14:44:37 439296 ------w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 17:26:00 730112 ------w- c:\windows\system32\lsasrv.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3200820AS rev.3.AHG -> Harddisk0\DR0 -> \Device\Ide\IdePort2 P2T0L0-e
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8615F5DC]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x861657b8]; MOV EAX, [0x86165834]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x86099AB8]
3 CLASSPNP[0xF7610FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000080[0x861E0F18]
5 ACPI[0xF7487620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x860C8940]
\Driver\atapi[0x86126F38] -> IRP_MJ_CREATE -> 0x8615F5DC
kernel: MBR read successfully
_asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; REP MOVSB ; JMP FAR 0x7a0:0x5c; }
detected disk devices:
\Device\Ide\IdeDeviceP2T0L0-e -> \??\IDE#DiskST3200820AS_____________________________3.AHG___#5&320f6b24&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8615F422
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:32:58.82 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/27/2010 6:30:06 AM
System Uptime: 3/9/2011 3:37:38 AM (13 hours ago)
.
Motherboard: ASUSTek Computer INC. | | Pyrite
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket AM2 | 2004/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 177 GiB total, 103.242 GiB free.
D: is FIXED (FAT32) - 9 GiB total, 0.575 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 466 GiB total, 458.037 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0001
Manufacturer: AVG Technologies
Name: WAN Miniport (IPX) - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0001
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0002
Manufacturer: AVG Technologies
Name: Microsoft TV/Video Connection - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0002
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0003
Manufacturer: AVG Technologies
Name: NVIDIA nForce Networking Controller - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0003
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0004
Manufacturer: AVG Technologies
Name: WAN Miniport (IP) - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0004
Service: Avgfwdx
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: AVG miniport driver
Device ID: ROOT\GR_AVGFWMP\0005
Manufacturer: AVG Technologies
Name: HP EN1207D-TX PCI 10/100 Fast Ethernet Adapter - AVG miniport driver
PNP Device ID: ROOT\GR_AVGFWMP\0005
Service: Avgfwdx
.
==== System Restore Points ===================
.
RP382: 12/9/2010 5:54:05 PM - System Checkpoint
RP383: 12/10/2010 6:42:29 PM - System Checkpoint
RP384: 12/11/2010 7:38:51 PM - System Checkpoint
RP385: 12/12/2010 8:38:51 PM - System Checkpoint
RP386: 12/13/2010 9:38:51 PM - System Checkpoint
RP387: 12/14/2010 10:45:36 PM - System Checkpoint
RP388: 12/15/2010 11:38:53 PM - System Checkpoint
RP389: 12/16/2010 3:00:26 AM - Software Distribution Service 3.0
RP390: 12/17/2010 3:11:29 AM - System Checkpoint
RP391: 12/18/2010 4:49:57 AM - System Checkpoint
RP392: 12/19/2010 5:29:23 AM - System Checkpoint
RP393: 12/20/2010 5:46:19 AM - System Checkpoint
RP394: 12/21/2010 6:54:59 AM - System Checkpoint
RP395: 12/22/2010 7:28:23 AM - System Checkpoint
RP396: 12/23/2010 8:25:10 AM - System Checkpoint
RP397: 12/24/2010 9:25:11 AM - System Checkpoint
RP398: 12/25/2010 10:26:15 AM - System Checkpoint
RP399: 12/26/2010 11:26:15 AM - System Checkpoint
RP400: 12/27/2010 12:25:12 PM - System Checkpoint
RP401: 12/28/2010 4:37:50 PM - System Checkpoint
RP402: 12/29/2010 5:51:05 PM - System Checkpoint
RP403: 12/30/2010 6:24:38 PM - System Checkpoint
RP404: 12/31/2010 7:12:23 PM - System Checkpoint
RP405: 1/2/2011 6:13:29 AM - System Checkpoint
RP406: 1/3/2011 7:12:23 AM - System Checkpoint
RP407: 1/4/2011 8:12:24 AM - System Checkpoint
RP408: 1/5/2011 9:12:23 AM - System Checkpoint
RP409: 1/6/2011 9:29:35 AM - System Checkpoint
RP410: 1/7/2011 10:19:52 AM - System Checkpoint
RP411: 1/8/2011 10:20:59 AM - System Checkpoint
RP412: 1/9/2011 11:19:52 AM - System Checkpoint
RP413: 1/10/2011 11:30:05 AM - System Checkpoint
RP414: 1/11/2011 12:44:53 PM - System Checkpoint
RP415: 1/12/2011 1:30:05 PM - System Checkpoint
RP416: 1/12/2011 2:02:35 PM - Software Distribution Service 3.0
RP417: 1/13/2011 2:45:57 PM - System Checkpoint
RP418: 1/14/2011 3:33:42 PM - System Checkpoint
RP419: 1/15/2011 4:52:02 PM - System Checkpoint
RP420: 1/16/2011 5:46:57 PM - System Checkpoint
RP421: 1/17/2011 7:41:20 PM - System Checkpoint
RP422: 1/18/2011 8:03:27 PM - System Checkpoint
RP423: 1/19/2011 8:32:28 PM - System Checkpoint
RP424: 1/20/2011 9:32:28 PM - System Checkpoint
RP425: 1/21/2011 9:57:39 PM - System Checkpoint
RP426: 1/23/2011 11:26:40 PM - System Checkpoint
RP427: 1/25/2011 1:17:27 AM - System Checkpoint
RP428: 1/26/2011 1:58:13 AM - System Checkpoint
RP429: 1/27/2011 4:12:49 AM - System Checkpoint
RP430: 1/28/2011 4:58:13 AM - System Checkpoint
RP431: 1/29/2011 5:09:13 AM - System Checkpoint
RP432: 1/30/2011 5:55:48 AM - System Checkpoint
RP433: 1/31/2011 6:55:47 AM - System Checkpoint
RP434: 2/1/2011 7:55:47 AM - System Checkpoint
RP435: 2/2/2011 8:55:47 AM - System Checkpoint
RP436: 2/3/2011 10:05:56 AM - System Checkpoint
RP437: 2/4/2011 11:05:54 AM - System Checkpoint
RP438: 2/5/2011 12:05:54 PM - System Checkpoint
RP439: 2/6/2011 1:05:53 PM - System Checkpoint
RP440: 2/7/2011 1:48:18 PM - System Checkpoint
RP441: 2/8/2011 2:25:40 PM - System Checkpoint
RP442: 2/9/2011 3:25:41 PM - System Checkpoint
RP443: 2/9/2011 9:19:13 PM - Software Distribution Service 3.0
RP444: 2/10/2011 10:11:05 PM - System Checkpoint
RP445: 2/11/2011 11:10:58 PM - System Checkpoint
RP446: 2/13/2011 12:10:57 AM - System Checkpoint
RP447: 2/14/2011 12:56:02 AM - System Checkpoint
RP448: 2/15/2011 2:29:17 PM - System Checkpoint
RP449: 2/16/2011 4:43:14 PM - System Checkpoint
RP450: 2/17/2011 6:19:06 PM - System Checkpoint
RP451: 2/18/2011 12:40:35 AM - Installed AVG 2011
RP452: 2/18/2011 12:40:42 AM - Removed AVG 2011
RP453: 2/18/2011 1:10:40 AM - Removed AVG 2011
RP454: 2/18/2011 1:31:36 AM - Installed AVG 2011
RP455: 2/18/2011 1:34:32 AM - Installed AVG 2011
RP456: 2/18/2011 1:34:38 AM - Removed AVG 2011
RP457: 2/18/2011 2:20:48 AM - avast! Pro Antivirus Setup
RP458: 2/18/2011 2:32:24 AM - Configured RangeMax Wireless-N USB Adapter WN111v2
RP459: 2/18/2011 2:37:10 AM - Installed RangeMax Wireless-N USB Adapter WN111v2
RP460: 2/19/2011 5:37:59 AM - System Checkpoint
RP461: 2/20/2011 6:31:18 AM - System Checkpoint
RP462: 2/21/2011 7:02:52 AM - System Checkpoint
RP463: 2/22/2011 7:03:49 AM - System Checkpoint
RP464: 2/23/2011 7:08:25 AM - System Checkpoint
RP465: 2/24/2011 7:55:26 AM - System Checkpoint
RP466: 2/25/2011 7:57:54 AM - System Checkpoint
RP467: 2/26/2011 8:29:33 AM - System Checkpoint
RP468: 2/27/2011 8:41:53 AM - System Checkpoint
RP469: 2/28/2011 8:54:17 AM - System Checkpoint
RP470: 3/1/2011 8:58:04 AM - System Checkpoint
RP471: 3/2/2011 9:48:32 AM - System Checkpoint
RP472: 3/3/2011 10:21:51 AM - System Checkpoint
RP473: 3/4/2011 10:55:54 AM - System Checkpoint
RP474: 3/5/2011 11:55:54 AM - System Checkpoint
RP475: 3/6/2011 12:55:54 PM - System Checkpoint
RP476: 3/7/2011 4:00:37 PM - System Checkpoint
RP477: 3/8/2011 6:27:08 PM - System Checkpoint
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader 7.0.5
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Apple Application Support
Apple Software Update
avast! Pro Antivirus
AVG PC Tuneup 2011
CamStudio
Codec Pack - All In 1 6.0.3.0
Connect
Data Fax SoftModem with SmartCP
Destinations
DeviceManagementQFolder
Enhanced Multimedia Keyboard Solution
Fraps (remove only)
FrostWire 4.21.3
gBurner
Google Earth
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Player 10 (KB903157)
HP Boot Optimizer
HP DigitalMedia Archive
HP DVD Play 2.1
HP Imaging Device Functions 7.0
HP Photosmart for Media Center PC
HP Update
HP Web Helper
HPPhotoSmartExpress
HpSdpAppCoreApp
J2SE Runtime Environment 5.0 Update 6
Java Auto Updater
Java(TM) 6 Update 22
kuler
LightScribe 1.4.105.1
Macromedia Flash Player 8
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Corporation
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft LifeCam
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.13)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NVIDIA Drivers
Otto
PC Connectivity Solution
PDF Settings CS4
Perfect Uninstaller v6.3.3.8
Photoshop Camera Raw
PokerStars
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
RangeMax Wireless-N USB Adapter WN111v2
Realtek High Definition Audio Driver
ROCKIT PRO DJ 4.0
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
SamsungConnectivityCableDriver
SecondLifeViewer2 (remove only)
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Segoe UI
Sierra Utilities
Skype™ 4.1
Sonic Express Labeler
Suite Shared Configuration CS4
Unload
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office Outlook 2007 (KB2412171)
Update for Outlook 2007 Junk Email Filter (KB2492475)
Updates from HP (remove only)
VLC media player 1.1.4
WebFldrs XP
WildTangent Web Driver
Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WN111v2
Yahoo! Toolbar for Internet Explorer
.
==== Event Viewer Messages From Past Week ========
.
3/7/2011 3:06:33 AM, error: Service Control Manager [7022] - The MSCamSvc service hung on starting.
3/7/2011 3:05:12 AM, error: Service Control Manager [7024] - The Routing and Remote Access service terminated with service-specific error 2 (0x2).
3/7/2011 3:05:11 AM, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found.
3/7/2011 3:05:10 AM, error: RemoteAccess [20103] - Unable to load C:\WINDOWS\System32\iprtrmgr.dll.
3/7/2011 12:50:45 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
3/7/2011 12:48:45 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
3/7/2011 1:34:39 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/4/2011 3:54:11 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
3/4/2011 3:54:11 AM, error: Service Control Manager [7022] - The Automatic Updates service hung on starting.
3/3/2011 7:21:11 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 30469A072EFC has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
textbox. Do not include the word Code
.


