When I search for something and the results come up, then I click on one of the links it brings up an ad page. If I go back and click on the link again it takes me to the page I wanted.
So I looked at my running processes and saw 2 suspicious entries.
I started running anti virus programs.
I have Adaware, Kaspersky, Spy Sweeper, Spy bot search and Destroy, CC cleaner, Windows washer. And I even tried Online Virus scanner from Trend Micro.
The last thing I tried was malwarebytes ant malware program.
It removed the Trojan but iam still getting re directed when I search on google.
here is dds log:
DDS (Version 1.1.0) - NTFSx86
Run by Myles at 16:53:19.64 on Sat 01/03/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1451 [GMT -5:00]
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
FW: Webroot Internet Security Essentials *disabled*
FW: Kaspersky Anti-Virus *disabled*
============== Running Processes ===============
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Sygate\SPF\smc.exe
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\RAM Idle\RAM_XP.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Myles\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061207
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061207
uInternet Settings,ProxyServer = 195.175.37.70:8080
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe"
mRun: [ehTray] "c:\windows\ehome\ehtray.exe"
mRun: [DMXLauncher] "c:\program files\dell\media experience\DMXLauncher.exe"
mRun: [SigmatelSysTrayApp] "c:\windows\stsystra.exe"
mRun: [DLA] "c:\windows\system32\dla\DLACTRLW.EXE"
mRun: [ISUSPM Startup] "c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SmcService] "c:\progra~1\sygate\spf\smc.exe" -startgui
mRun: [RAM Idle Professional] "c:\program files\ram idle\RAM_XP.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe"
mRun: [type32] "c:\program files\microsoft intellitype pro\type32.exe"
mRun: [amd_dc_opt] "c:\program files\amd\dual-core optimizer\amd_dc_opt.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe"
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.09\RivaTuner.exe" /S
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray
StartupFolder: c:\docume~1\myles\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\SCIEPlgn.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Notify: klogon - c:\windows\system32\klogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\myles\applic~1\mozilla\firefox\profiles\5zxmr4i1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\myles\application data\mozilla\firefox\profiles\5zxmr4i1.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\download manager\npfpdlm.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPStreamPlug.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - HiddenExtension: XUL Cache: {F4F3582D-2C95-4674-9C2E-673F72048A1F} - c:\documents and settings\myles\local settings\application data\{F4F3582D-2C95-4674-9C2E-673F72048A1F}
============= SERVICES / DRIVERS ===============
R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2007-10-31 112144]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-11-12 29808]
R1 klif;Klif;c:\windows\system32\drivers\klif.sys [2007-12-28 195344]
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [2007-8-25 33824]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-12-13 24592]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R4 hnmwrlspkt;HomeNet Manager Wireless Protocol;c:\windows\system32\drivers\hnm_wrls_pkt.sys [2006-7-14 13824]
R4 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-12-5 935208]
R4 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2008-11-12 3667312]
R4 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2008-12-2 1086840]
R4 wsppkt;Wireless Security Protocol;c:\windows\system32\drivers\wsp_pkt.sys [2006-7-14 13696]
S4 AVP;Kaspersky Anti-Virus 7.0;c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe [2008-2-8 227856]
============== File Associations ===============
vbefile\shell\open2\command=%SystemRoot%\System32\CScript.exe "%1" %*
vbsfile\shell\open2\command=%SystemRoot%\System32\CScript.exe "%1" %*
jsefile\shell\open2\command=%SystemRoot%\System32\CScript.exe "%1" %*
=============== Created Last 30 ================
2009-01-03 07:12 <DIR> --d----- C:\VundoFix Backups
2008-12-29 21:47 69 a------- c:\windows\NeroDigital.ini
2008-12-29 19:38 <DIR> --d----- c:\docume~1\myles\applic~1\Malwarebytes
2008-12-29 19:37 15,504 a------- c:\windows\system32\drivers\mbam.sys
2008-12-29 19:37 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 19:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2008-12-29 19:37 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2008-12-28 18:56 4,767 a------- c:\windows\Irremote.ini
2008-12-28 18:35 <DIR> --d----- c:\program files\Nero
2008-12-28 00:09 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2008-12-28 00:08 <DIR> --d----- c:\documents and settings\myles\.housecall6.6
2008-12-27 03:49 <DIR> --d----- c:\program files\YASAMP4Converter
2008-12-12 07:27 391,168 a------- c:\windows\UnInstallExposed.exe
2008-12-12 07:27 <DIR> --d----- c:\program files\Red Dragon Software
2008-12-12 03:27 133,120 a------- c:\windows\ifiwenuqave.dll
2008-12-09 04:22 <DIR> --d----- c:\program files\Microsoft Games for Windows - LIVE
2008-12-09 03:44 <DIR> --d----- c:\program files\Rockstar Games
2008-12-08 20:26 205,151 a------- c:\windows\system32\nvapps.xml
2008-12-08 20:26 453,152 a------- c:\windows\system32\nvudisp.exe
2008-12-08 20:26 18,696 a------- c:\windows\system32\nvdisp.nvu
2008-12-08 20:26 <DIR> --d----- c:\windows\nview
2008-12-08 20:25 453,152 a------- c:\windows\system32\NVUNINST.EXE
2008-12-04 16:54 7,552 a------- c:\windows\system32\drivers\SONYPVU1.SYS
2008-12-04 16:54 7,552 a------- c:\windows\system32\dllcache\sonypvu1.sys
2008-12-04 16:54 26,368 a------- c:\windows\system32\dllcache\usbstor.sys
==================== Find3M ====================
2009-01-03 16:53 1,768,480 a--sh--- c:\windows\system32\drivers\fidbox2.dat
2009-01-03 16:52 85,216,800 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-01-03 00:43 139,152 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-01-03 00:43 111,928 a------- c:\windows\system32\PnkBstrB.exe
2008-12-30 02:16 1,132,172 a--sh--- c:\windows\system32\drivers\fidbox.idx
2008-12-30 02:16 166,100 a--sh--- c:\windows\system32\drivers\fidbox2.idx
2008-12-13 01:40 3,593,216 a------- c:\windows\system32\dllcache\mshtml.dll
2008-12-02 14:39 164 a------- C:\install.dat
2008-11-20 15:44 42,320 a------- c:\windows\system32\xfcodec.dll
2008-11-18 22:39 413,696 a------- c:\windows\system32\wrap_oal.dll
2008-11-18 22:39 110,592 a------- c:\windows\system32\OpenAL32.dll
2008-11-17 03:37 107,888 a------- c:\windows\system32\CmdLineExt.dll
2008-11-13 17:11 1,553,272 a------- c:\windows\WRSetup.dll
2008-11-13 03:03 22,328 ac------ c:\docume~1\myles\applic~1\PnkBstrK.sys
2008-11-13 03:02 682,280 a------- c:\windows\system32\pbsvc.exe
2008-11-12 16:02 170,608 a------- c:\windows\system32\drivers\ssidrv.sys
2008-11-12 16:02 29,808 a------- c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 16:02 23,152 a------- c:\windows\system32\drivers\sshrmd.sys
2008-11-12 11:55 88,263 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-10-28 17:41 14,303,392 a------- c:\windows\system32\xlive.dll
2008-10-28 17:41 13,643,936 a------- c:\windows\system32\xlivefnt.dll
2008-10-26 23:53 66,872 a------- c:\windows\system32\PnkBstrA.exe
2008-10-24 06:21 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 07:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-23 07:36 286,720 -------- c:\windows\system32\dllcache\gdi32.dll
2008-10-16 14:13 1,809,944 a------- c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 14:13 202,776 a------- c:\windows\system32\dllcache\wuweb.dll
2008-10-16 14:12 323,608 a------- c:\windows\system32\dllcache\wucltui.dll
2008-10-16 14:12 561,688 a------- c:\windows\system32\dllcache\wuapi.dll
2008-10-16 14:09 92,696 a------- c:\windows\system32\dllcache\cdm.dll
2008-10-16 14:09 51,224 a------- c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 14:08 34,328 a------- c:\windows\system32\dllcache\wups.dll
2008-10-16 08:11 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 08:11 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 11:34 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2008-10-15 02:06 633,632 -------- c:\windows\system32\dllcache\iexplore.exe
2008-10-15 02:04 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2006-12-14 04:21 88 ---shr-- c:\windows\system32\2604239F3E.sys
2006-12-14 04:21 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys
============= FINISH: 16:54:04.75 ===============