This is a follow-up topic from a previous post -
http://www.bleepingcomputer.com/forums/topic440263.html/page__gopid__2575214#entry2575214
Summary: Google redirect virus - hasn't been removed with TDSSKiller or Malwarebytes.
Below is the DDS log -
##############################
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7600.16385
Run by Jason at 21:42:15 on 2012-01-29
Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.1013.205 [GMT -8:00]
.
AV: Norton Internet Security Netbook Edition *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security Netbook Edition *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Internet Security Netbook Edition *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Jason\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jason\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jason\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jason\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jason\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\windows\system32\igfxext.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\hkcmd.exe
C:\windows\system32\igfxtray.exe
C:\windows\system32\igfxpers.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://samsung.msn.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - c:\program files\startnow toolbar\Toolbar32.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: DealPly: {a6174f27-1fff-e1d6-a93f-ba48ad5dd448} - c:\program files\dealply\DealPlyIE.dll
BHO: W2PBrowser Class: {aa609d72-8482-4076-8991-8cdae5b93bcb} - c:\program files\samsung anyweb print\W2PBrowser.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
TB: @c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - c:\program files\startnow toolbar\Toolbar32.dll
uRun: [Google Update] "c:\users\jason\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [StartNowToolbarHelper] "c:\program files\startnow toolbar\ToolbarHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\srspre~1.lnk - c:\windows\installer\{e5cf6b9c-3abe-43c9-9413-ad5ffc98f049}\NewShortcut4_E9C83B3EDF9141A39DA5EC05C79BBB91.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - c:\program files\samsung anyweb print\W2PBrowser.dll
LSP: mswsock.dll
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{C93209A4-207B-4AAF-A702-33895185D1EC} : DhcpNameServer = 10.60.25.7 10.60.25.6 10.208.11.83
TCP: Interfaces\{E82CFA94-3BFC-4716-84E7-CB3A3C3B3287} : DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{E82CFA94-3BFC-4716-84E7-CB3A3C3B3287}\058696C6A70234F666665656 : DhcpNameServer = 10.128.128.128
TCP: Interfaces\{E82CFA94-3BFC-4716-84E7-CB3A3C3B3287}\2456C6B696E6F5E413F575962756C6563737F5334463733483 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{E82CFA94-3BFC-4716-84E7-CB3A3C3B3287}\2556460225F636B60234F666665656 : DhcpNameServer = 208.201.224.11 208.201.224.33 206.13.28.12
TCP: Interfaces\{E82CFA94-3BFC-4716-84E7-CB3A3C3B3287}\2556460225F636B60234F6666656560223 : DhcpNameServer = 208.201.224.11 208.201.224.33 206.13.28.12
TCP: Interfaces\{E82CFA94-3BFC-4716-84E7-CB3A3C3B3287}\3547566756E6370234275656B602355726162757 : DhcpNameServer = 10.230.80.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-9-14 10752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-10-20 821664]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-1-28 652872]
R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2010-9-14 508264]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2011-2-9 297000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2011-2-9 33320]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-1-28 20464]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-9-14 577384]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-9-14 194408]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-9-14 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-9-14 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2010-9-14 219496]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-7-8 322336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 CTMFLT;Oracleorahomemanagementserver;c:\windows\system32\svchost.exe -k netsvcs [2009-7-13 20992]
S2 mclserviceatl;Vcommmgr;c:\windows\system32\svchost.exe -k netsvcs [2009-7-13 20992]
S2 symantecantibotshim;Pdlnepkt;c:\windows\system32\svchost.exe -k netsvcs [2009-7-13 20992]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-2-9 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-1-28 40776]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [2011-2-9 131888]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== Created Last 30 ================
.
2012-01-28 16:52:00 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-01-28 16:03:04 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-28 16:03:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-28 05:30:49 -------- d-----w- C:\TDSSKiller_Quarantine
2012-01-28 04:04:47 74240 ----a-w- c:\windows\system32\drivers\tdx.sys
2012-01-28 02:46:01 23624 ----a-w- c:\windows\system32\drivers\hitmanpro36.sys
2012-01-28 02:45:57 -------- d-----w- c:\program files\HitmanPro
2012-01-28 02:45:08 -------- d-----w- c:\programdata\HitmanPro
2012-01-28 02:14:40 -------- d-----w- c:\users\jason\appdata\roaming\Malwarebytes
2012-01-28 02:14:21 -------- d-----w- c:\programdata\Malwarebytes
2012-01-28 01:22:07 -------- d-----w- c:\users\jason\appdata\local\NPE
2012-01-27 14:01:06 -------- d-----w- c:\users\jason\appdata\local\Symantec
2012-01-21 16:35:57 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-01-21 16:16:18 0 --sha-w- c:\windows\system32\dds_log_trash.cmd
2012-01-21 16:15:31 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-21 16:14:52 -------- d-sh--w- c:\users\jason\appdata\local\ca017659
2012-01-18 03:55:57 6823496 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{7a31954a-1174-4f33-9e15-74ba95ba65ef}\mpengine.dll
2012-01-12 13:45:58 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-12 13:45:58 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-12 13:45:58 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-12 13:45:58 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-12 13:45:58 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-12 13:45:57 99840 ----a-w- c:\windows\system32\sspicli.dll
2012-01-12 13:45:57 314368 ----a-w- c:\windows\system32\webio.dll
2012-01-12 13:45:57 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-12 13:45:57 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-12 13:45:57 15360 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-12 03:26:16 1288984 ----a-w- c:\windows\system32\ntdll.dll
2012-01-12 03:26:10 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-12 03:26:03 1328640 ----a-w- c:\windows\system32\quartz.dll
2012-01-12 03:26:02 514560 ----a-w- c:\windows\system32\qdvd.dll
.
==================== Find3M ====================
.
2012-01-28 05:25:26 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-11-24 04:23:31 2340352 ----a-w- c:\windows\system32\win32k.sys
2011-11-15 22:29:56 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-11-05 04:35:50 981504 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 04:34:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-05 04:30:11 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 03:28:41 386048 ----a-w- c:\windows\system32\html.iec
2011-11-05 02:55:38 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 21:43:45.17 ===============
###########################################
Attached is the DDS Attach log file. I'll attach the GMER log (Ark.txt) in a separate post.
Thanks!
Attached File(s)
-
Attach.txt (27.27K)
Number of downloads: 2

Help
This topic is locked

Back to top












