I've run TDSSKiller, Malwarebytes, Defogger, and have a HijackThis log.
When I first ran Malwarebytes, this is what came up:
21:59:08 MESSAGE Protection started successfully
21:59:13 MESSAGE IP Protection started successfully
22:53:27 DETECTION C:\Documents and Settings\jhorn\Local Settings\Application Data\TCPIPUser.dll Trojan.Tracur.VGen QUARANTINE
22:53:27 DETECTION C:\Documents and Settings\jhorn\Local Settings\Application Data\TCPIPUser.dll Trojan.Tracur.VGen DENY
22:53:28 ERROR Quarantine failed: DeleteFile failed with error code 5
22:53:28 DETECTION C:\Documents and Settings\jhorn\Local Settings\Application Data\TCPIPUser.dll Trojan.Tracur.VGen DENY
22:53:28 DETECTION C:\Documents and Settings\jhorn\Local Settings\Application Data\TCPIPUser.dll Trojan.Tracur.VGen DENY
23:03:29 MESSAGE Protection started successfully
23:03:34 MESSAGE IP Protection started successfully
When it couldn't quarantine the viruses, I deleted them (and then later read that I shouldn't have done that). The intensity of the issues died down after running TDSSkiller and Malwarebytes, but the redirects didn't stop completely, so I'm pretty sure something is still lurking around.
Here is the DDS log:
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Run by jhorn at 20:01:32 on 2011-10-11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3572.2523 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\AESTFltr.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\WINDOWS\OA001Mon.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Documents and Settings\jhorn\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\jhorn\local settings\application data\google\update\GoogleUpdate.exe" /c
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10v_Plugin.exe -update plugin
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [OA001Mon] c:\windows\OA001Mon.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AirPort Base Station Agent] "c:\program files\airport\APAgent.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\jhorn\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\jhorn\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{176130bc-99a1-41fe-a78b-56045e33ad70}\Icon3E5562ED7.ico
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 68.87.68.166 68.87.74.166
TCP: Interfaces\{4B4CAE43-1EBC-4772-AD43-DEF7233693CE} : DhcpNameServer = 68.87.68.166 68.87.74.166
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\jhorn\application data\mozilla\firefox\profiles\mu66kuok.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\jhorn\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\jhorn\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R1 MpKsl3effa407;MpKsl3effa407;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d665c00c-b614-47d9-b330-21474f74db74}\MpKsl3effa407.sys [2011-10-10 28752]
R1 MpKsl6a688dcf;MpKsl6a688dcf;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ee29560-13f2-4a25-8894-32021ad41076}\mpksl6a688dcf.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ee29560-13f2-4a25-8894-32021ad41076}\MpKsl6a688dcf.sys [?]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2009-12-17 812448]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2009-12-17 27040]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-9-28 366152]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-12-7 112512]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2009-11-24 33832]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2010-1-14 240344]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-9-28 22216]
R3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [2010-11-4 134144]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2010-11-4 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2010-11-4 281472]
S1 MpKsl14e4f1d0;MpKsl14e4f1d0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e0d813f9-c612-487e-86bf-3b3b9667c429}\mpksl14e4f1d0.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e0d813f9-c612-487e-86bf-3b3b9667c429}\MpKsl14e4f1d0.sys [?]
S1 MpKsl2e1018c3;MpKsl2e1018c3;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{002b9d51-5a2f-456a-8494-e1caf33df12d}\mpksl2e1018c3.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{002b9d51-5a2f-456a-8494-e1caf33df12d}\MpKsl2e1018c3.sys [?]
S1 MpKsl3e3de825;MpKsl3e3de825;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9b098e40-67b9-4e49-9045-9b8227478251}\mpksl3e3de825.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9b098e40-67b9-4e49-9045-9b8227478251}\MpKsl3e3de825.sys [?]
S1 MpKsl47a9687a;MpKsl47a9687a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0846cebb-7d92-4a19-9e36-cd8e9401558e}\mpksl47a9687a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0846cebb-7d92-4a19-9e36-cd8e9401558e}\MpKsl47a9687a.sys [?]
S1 MpKsl61ef084d;MpKsl61ef084d;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1a4281bb-dcd2-403d-a30e-bc9e4d491e84}\mpksl61ef084d.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1a4281bb-dcd2-403d-a30e-bc9e4d491e84}\MpKsl61ef084d.sys [?]
S1 MpKsl721664b7;MpKsl721664b7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ec86cabf-031c-4e07-900d-dffb1a30dcb6}\mpksl721664b7.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ec86cabf-031c-4e07-900d-dffb1a30dcb6}\MpKsl721664b7.sys [?]
S1 MpKsl78507b8b;MpKsl78507b8b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e0d813f9-c612-487e-86bf-3b3b9667c429}\mpksl78507b8b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e0d813f9-c612-487e-86bf-3b3b9667c429}\MpKsl78507b8b.sys [?]
S1 MpKsl7cf7998f;MpKsl7cf7998f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d1414648-2145-4afa-ba51-94b61d835d36}\mpksl7cf7998f.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d1414648-2145-4afa-ba51-94b61d835d36}\MpKsl7cf7998f.sys [?]
S1 MpKsl88e7b36c;MpKsl88e7b36c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cc3ac682-ad51-4067-b2a2-520a74e706e5}\mpksl88e7b36c.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cc3ac682-ad51-4067-b2a2-520a74e706e5}\MpKsl88e7b36c.sys [?]
S1 MpKsl8d93b6ce;MpKsl8d93b6ce;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cc3ac682-ad51-4067-b2a2-520a74e706e5}\mpksl8d93b6ce.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cc3ac682-ad51-4067-b2a2-520a74e706e5}\MpKsl8d93b6ce.sys [?]
S1 MpKsl9d762d6b;MpKsl9d762d6b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5f90dddf-9032-4359-a49f-b0b47be0725e}\mpksl9d762d6b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5f90dddf-9032-4359-a49f-b0b47be0725e}\MpKsl9d762d6b.sys [?]
S1 MpKslbe1e30d8;MpKslbe1e30d8;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{eac010bf-f5fa-491b-8ec8-54db20ffc9f3}\mpkslbe1e30d8.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{eac010bf-f5fa-491b-8ec8-54db20ffc9f3}\MpKslbe1e30d8.sys [?]
S1 MpKslc0e4d2ca;MpKslc0e4d2ca;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5f90dddf-9032-4359-a49f-b0b47be0725e}\mpkslc0e4d2ca.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5f90dddf-9032-4359-a49f-b0b47be0725e}\MpKslc0e4d2ca.sys [?]
S1 MpKslc5232ab4;MpKslc5232ab4;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9b098e40-67b9-4e49-9045-9b8227478251}\mpkslc5232ab4.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9b098e40-67b9-4e49-9045-9b8227478251}\MpKslc5232ab4.sys [?]
S1 MpKslc5c7e2d6;MpKslc5c7e2d6;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ff256e02-7c29-4a0e-ab4c-2e068a6dedae}\mpkslc5c7e2d6.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ff256e02-7c29-4a0e-ab4c-2e068a6dedae}\MpKslc5c7e2d6.sys [?]
S1 MpKslcb037ada;MpKslcb037ada;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{93653165-3638-4fa3-b44d-6c31f159c74d}\mpkslcb037ada.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{93653165-3638-4fa3-b44d-6c31f159c74d}\MpKslcb037ada.sys [?]
S1 MpKsle0daac5c;MpKsle0daac5c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{73c50e9a-e223-4504-b4e8-e60509974954}\mpksle0daac5c.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{73c50e9a-e223-4504-b4e8-e60509974954}\MpKsle0daac5c.sys [?]
S1 MpKsle6804e11;MpKsle6804e11;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b5bd2271-041f-4667-8120-9c8f7ecbc400}\mpksle6804e11.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b5bd2271-041f-4667-8120-9c8f7ecbc400}\MpKsle6804e11.sys [?]
S1 MpKsle9d733fc;MpKsle9d733fc;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5f90dddf-9032-4359-a49f-b0b47be0725e}\mpksle9d733fc.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5f90dddf-9032-4359-a49f-b0b47be0725e}\MpKsle9d733fc.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-5 136176]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2011-8-24 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-5 136176]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-12-14 108032]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
.
=============== Created Last 30 ================
.
2011-10-10 23:43:51 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d665c00c-b614-47d9-b330-21474f74db74}\MpKsl3effa407.sys
2011-10-10 23:43:42 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d665c00c-b614-47d9-b330-21474f74db74}\offreg.dll
2011-10-10 23:43:39 7269712 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d665c00c-b614-47d9-b330-21474f74db74}\mpengine.dll
2011-10-04 00:41:54 388096 ----a-r- c:\documents and settings\jhorn\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-10-04 00:41:53 -------- d-----w- c:\program files\Trend Micro
2011-09-29 01:57:02 -------- d-----w- c:\documents and settings\jhorn\application data\Malwarebytes
2011-09-29 01:56:46 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-09-29 01:56:42 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-29 01:56:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-09-29 01:52:23 -------- d-----w- c:\program files\CCleaner
2011-09-28 02:06:56 -------- d-----w- C:\TDSSKiller_Quarantine
2011-09-28 01:49:50 0 ---ha-w- c:\documents and settings\jhorn\nsfuqwqxun.tmp
.
==================== Find3M ====================
.
2011-09-09 09:12:13 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-08-17 17:50:16 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
============= FINISH: 20:02:21.20 ===============
And here is the GMER log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-11 20:53:56
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-7 WDC_WD1600BJKT-75F4T0 rev.11.01A11
Running: pbn6l1dl.exe; Driver: C:\DOCUME~1\jhorn\LOCALS~1\Temp\ufldypow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB75D5380, 0x3D26E5, 0xE8000020]
init C:\WINDOWS\system32\Drivers\OA001Afx.sys entry point in "init" section [0xB5A10D50]
? C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5EE29560-13F2-4A25-8894-32021AD41076}\MpKsl6a688dcf.sys The system cannot find the file specified. !
? C:\DOCUME~1\jhorn\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[178488] USER32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 1069E349 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[178488] USER32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 1069E2DB C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[178488] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 104589A7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[178488] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 10458F65 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[179748] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 0143FAE0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Processes - GMER 1.0.15 ----
Process hidden process (*** hidden *** ) 20344
Process hidden process (*** hidden *** ) 47416
Process hidden process (*** hidden *** ) 48676
Process hidden process (*** hidden *** ) 50700
Process hidden process (*** hidden *** ) 52948
Process hidden process (*** hidden *** ) 53096
---- EOF - GMER 1.0.15 ----
Attached File(s)
-
attach.zip (3.74K)
Number of downloads: 0 -
ark.zip (990bytes)
Number of downloads: 0
This post has been edited by Orange Blossom: 13 October 2011 - 01:20 PM
Reason for edit: Deactivated links. ~ OB

Help
This topic is locked

Back to top













