I ran Spyware Doctor, Registry Mechanic, Malwarebytes, Super Anti Spyware. I tried installing TDSS and Combofix, but they would not install. Went into safe mode with networking and ran all the above. I also cleared java cache, firefox cache, IE cache, all browser histories, cookies, etc. I got the hidden icons returned and program files are visible. Radio has seemed to stop playing - I found that when it started an IEXPLORE.EXE system process would start and I would shut it down to stop the radio. Hasn't come on since yesterday.
So the issue I have left is the browser hijacking in both firefox and ie. Can you check the logs to see if I have rootkit causing the issues?
.
DDS (Ver_2011-06-03.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Dan Moon at 14:50:26 on 2011-06-09
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3544.2481 [GMT -7:00]
.
AV: Spyware Doctor with AntiVirus *Disabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\drivers\audio\r215959\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
svchost.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\DellTPad\HidFind.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\32788R22FWJFW\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\32788R22FWJFW\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://en.wikipedia.org/wiki/Main_Page
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [OpenDNS Updater] "c:\program files\opendns updater\OpenDNSUpdater.exe" /autostart
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 5.0\apdproxy.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: DhcpNameServer = 10.0.0.1
TCP: Interfaces\{B4663D70-DAE4-442E-BC2E-637285DABAF4} : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{B5B3D094-D145-4AF3-9F3C-9EF72C16CC7E} : DhcpNameServer = 10.0.0.1
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\dan moon\application data\mozilla\firefox\profiles\pugcmp9n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://en.wikipedia.org/wiki/
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZRxdm71968US&ptb=Jjl0gnNPHBLNBfCHWMdNoA&ind=2011022421&ptnrS=ZRxdm71968US&si=&n=77ddc455&psa=&st=kwd&searchfor=
FF - plugin: c:\documents and settings\dan moon\application data\mozilla\firefox\profiles\pugcmp9n.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-12-15 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-6-7 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-6-7 656320]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-6-7 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-6-7 69392]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-12-15 251560]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2011-6-7 233976]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 MotoHelper;MotoHelper Service;c:\program files\motorola\motohelper\MotoHelperService.exe [2010-9-7 202048]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2011-6-8 632792]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-12-14 113024]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2009-12-14 160256]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-6-7 33552]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664]
S3 AMBFilt;Creative AMB Service;c:\windows\system32\drivers\AMBFilt.sys [2009-12-14 1656960]
S3 cpuz132;cpuz132;\??\c:\docume~1\danmoo~1\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\danmoo~1\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-1-24 39984]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys --> c:\windows\system32\drivers\motusbdevice.sys [?]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2009-12-15 70664]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-12-15 371472]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-12-15 1117144]
S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]
S4 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc --> RUNDLL32.EXE ykx32coinst,serviceStartProc [?]
.
=============== Created Last 30 ================
.
2011-06-09 20:55:56 98816 ----a-w- c:\windows\sed.exe
2011-06-09 20:55:56 518144 ----a-w- c:\windows\SWREG.exe
2011-06-09 20:55:56 256512 ----a-w- c:\windows\PEV.exe
2011-06-09 20:55:56 208896 ----a-w- c:\windows\MBR.exe
2011-06-09 20:55:46 -------- d-s---w- C:\ComboFix
2011-06-09 20:12:40 -------- d-----w- c:\documents and settings\dan moon\application data\SUPERAntiSpyware.com
2011-06-09 20:12:40 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2011-06-09 20:12:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-09 17:44:10 726528 ----a-w- c:\windows\system32\SET61.tmp
2011-06-09 17:44:10 420864 ----a-w- c:\windows\system32\SET60.tmp
2011-06-09 07:28:41 -------- d-----w- C:\_OTM
2011-06-09 07:09:34 4778 ----a-w- c:\windows\system32\tmp.reg
2011-06-09 03:22:04 -------- d-sh--w- c:\documents and settings\dan moon\IECompatCache
2011-06-08 18:34:18 -------- d-sh--w- c:\documents and settings\dan moon\PrivacIE
2011-06-08 18:33:10 -------- d-sh--w- c:\documents and settings\dan moon\IETldCache
2011-06-08 18:16:51 -------- d-----w- c:\windows\ie8updates
2011-06-08 18:14:50 -------- dc----w- c:\windows\ie8
2011-06-08 18:11:21 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-06-08 18:11:17 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-06-08 18:11:17 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-06-08 18:11:16 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-06-08 18:11:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-06-08 18:11:15 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-06-08 18:11:15 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-06-08 18:11:13 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-06-08 17:25:52 -------- d-----w- c:\documents and settings\dan moon\application data\PCTools
2011-06-08 17:15:51 -------- d-----w- c:\program files\Registrar Lite
2011-06-08 07:41:21 -------- d-----w- c:\documents and settings\dan moon\application data\Registry Mechanic
2011-06-08 07:35:40 880640 ----a-w- c:\windows\system32\UniBox10.ocx
2011-06-08 07:35:40 658432 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2011-06-08 07:35:40 37336 ----a-w- c:\windows\system32\CleanMFT32.exe
2011-06-08 07:35:40 212992 ----a-w- c:\windows\system32\UniBoxVB12.ocx
2011-06-08 07:35:40 1101824 ----a-w- c:\windows\system32\UniBox210.ocx
2011-06-08 05:47:37 69392 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2011-06-08 05:47:37 51984 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2011-06-08 05:47:37 33552 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2011-06-08 05:47:03 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-06-08 05:47:03 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-06-08 05:46:57 233976 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-06-08 04:52:30 -------- d-s---w- c:\documents and settings\dan moon\UserData
2011-06-08 04:51:15 388096 ----a-r- c:\documents and settings\dan moon\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-06-08 04:51:14 -------- d-----w- c:\program files\Trend Micro
2011-06-08 00:31:54 -------- d-----w- c:\documents and settings\all users\application data\MFAData
2011-05-29 20:03:16 -------- d-----w- c:\program files\Zero G Registry
2011-05-29 20:03:16 -------- d-----w- c:\program files\Edusoft Grader
2011-05-29 20:02:59 -------- d-----w- c:\documents and settings\dan moon\InstallAnywhere
.
==================== Find3M ====================
.
2011-05-29 16:11:30 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-11 20:35:32 160576 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-05-11 16:55:10 263888 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-05-06 20:28:38 70664 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-05-06 20:26:34 251560 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
.
============= FINISH: 14:51:49.25 ===============
Attached File(s)
-
attach.txt (21.55K)
Number of downloads: 2 -
ark.txt (14.33K)
Number of downloads: 3

Help


Back to top












