My problem is that I think I have a trojan injector and also have the feeling someone is monitoring me.
When I click on google searches I get redirected to other sites. I updated AVG8 and it warned me of 2 "redirect.htm" but I still have this problem with clickfraudmanager.
Here is my dds log, I will also attach my attach log as instructed
DDS (Ver_09-02-01.01) - NTFSx86
Run by Ich at 7:26:46,65 on 07.02.2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.49.1031.18.3327.2786 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
============== Running Processes ===============
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programme\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\imapi.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
svchost.exe
C:\Programme\AVG\AVG8\avgui.exe
C:\Dokumente und Einstellungen\Ich\Desktop\dds.scr
============== Pseudo HJT Report ===============
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\dokumente und einstellungen\ich\edvga.exe \s,c:\windows\system32\vmware-ufad.exe,c:\windows\system32\ndetect.exe,c:\windows\system32\gcc.exe,
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Ad-Watch] c:\programme\lavasoft\ad-aware\AAWTray.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [phkxlrwm.exe] c:\windows\phkxlrwm.exe
dRun: [ntmxoeic.exe] c:\windows\ntmxoeic.exe
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programme\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233490236750
TCP: {F71F21AC-B140-45E6-954F-97E065A15438} = 213.191.74.19 62.109.123.197
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programme\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\dokume~1\ich\anwend~1\mozilla\firefox\profiles\u8kpssef.default\
FF - component: c:\programme\avg\avg8\firefox\components\avgssff.dll
---- FIREFOX POLICIES ----
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("network.protocol-handler.warn-external.veoh", false);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-1 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-2-1 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-2-1 27656]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-1 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-2-1 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-2-1 298264]
S0 rzaoyh;rzaoyh;c:\windows\system32\drivers\suoiqnl.sys --> c:\windows\system32\drivers\suoIqnl.sys [?]
S1 ethdcied;ethdcied;c:\windows\system32\drivers\ethdcied.sys --> c:\windows\system32\drivers\ethdcied.sys [?]
S1 ethdfduc;ethdfduc;c:\windows\system32\drivers\ethdfduc.sys --> c:\windows\system32\drivers\ethdfduc.sys [?]
S1 ethdywdv;ethdywdv;c:\windows\system32\drivers\ethdywdv.sys [2009-2-6 137408]
S1 ethgekle;ethgekle;c:\windows\system32\drivers\ethgekle.sys --> c:\windows\system32\drivers\ethgekle.sys [?]
S1 ethhodop;ethhodop;c:\windows\system32\drivers\ethhodop.sys --> c:\windows\system32\drivers\ethhodop.sys [?]
S1 ethjgkrv;ethjgkrv;c:\windows\system32\drivers\ethjgkrv.sys --> c:\windows\system32\drivers\ethjgkrv.sys [?]
S1 ethlzkap;ethlzkap;c:\windows\system32\drivers\ethlzkap.sys --> c:\windows\system32\drivers\ethlzkap.sys [?]
S1 ethqninv;ethqninv;c:\windows\system32\drivers\ethqninv.sys --> c:\windows\system32\drivers\ethqninv.sys [?]
S1 ethubnua;ethubnua;c:\windows\system32\drivers\ethubnua.sys --> c:\windows\system32\drivers\ethubnua.sys [?]
S1 ethvhcam;ethvhcam;c:\windows\system32\drivers\ethvhcam.sys --> c:\windows\system32\drivers\ethvhcam.sys [?]
S1 ethxtfgr;ethxtfgr;c:\windows\system32\drivers\ethxtfgr.sys --> c:\windows\system32\drivers\ethxtfgr.sys [?]
S1 ethzewzx;ethzewzx;c:\windows\system32\drivers\ethzewzx.sys --> c:\windows\system32\drivers\ethzewzx.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programme\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S3 yncylqgq;yncylqgq;\??\c:\windows\system32\drivers\yncylqgq.sys --> c:\windows\system32\drivers\yncylqgq.sys [?]
=============== Created Last 30 ================
2009-02-06 07:52 137,408 a------- c:\windows\system32\drivers\ethdywdv.sys
2009-02-06 07:52 67,585 a------- c:\windows\system32\6.tmp
2009-02-06 07:52 23,553 a------- c:\windows\system32\5.tmp
2009-02-06 07:52 3,584 a------- c:\windows\ntmxoeic.exe
2009-02-06 07:52 162,756 a------- c:\windows\system32\4.tmp
2009-02-06 07:52 168 a------- c:\windows\system32\3.tmp
2009-02-06 07:25 14,130 a------- c:\windows\system32\20.tmp
2009-02-06 07:25 67,585 a------- c:\windows\system32\1F.tmp
2009-02-06 07:25 23,553 a------- c:\windows\system32\1E.tmp
2009-02-06 07:25 168 a------- c:\windows\system32\1C.tmp
2009-02-06 07:23 0 a------- c:\windows\system32\1A.tmp
2009-02-06 07:23 0 a------- c:\windows\system32\19.tmp
2009-02-06 07:23 0 a------- c:\windows\system32\18.tmp
2009-02-06 07:23 168 a------- c:\windows\system32\15.tmp
2009-02-06 07:21 0 a------- c:\windows\system32\12.tmp
2009-02-06 07:21 0 a------- c:\windows\system32\11.tmp
2009-02-06 07:21 0 a------- c:\windows\system32\10.tmp
2009-02-06 07:19 32,768 a---h--- c:\dokumente und einstellungen\ich\edvga.exe
2009-02-06 06:47 67,585 a------- c:\windows\system32\16.tmp
2009-02-06 06:46 168 a------- c:\windows\system32\13.tmp
2009-02-06 06:15 32,768 a---h--- c:\dokumente und einstellungen\ich\sdvny.exe
2009-02-06 06:10 32,768 a---h--- c:\dokumente und einstellungen\ich\vch.exe
2009-02-06 06:09
2009-02-06 05:46
2009-02-06 05:26 32,768 a---h--- c:\dokumente und einstellungen\ich\mqiyed.exe
2009-02-06 05:26 66,560 ----h--- c:\windows\system32\secupdat.dat
2009-02-06 04:29 54,272 ac------ c:\windows\system32\dllcache\migisol.exe
2009-02-06 04:29 22,528 ac------ c:\windows\system32\dllcache\dcomcnfg.exe
2009-02-01 23:31 192,307 a------- C:\wubildr
2009-02-01 23:31 8,192 a------- C:\wubildr.mbr
2009-02-01 23:12 15,688 a------- c:\windows\system32\lsdelete.exe
2009-02-01 23:09 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-01 23:04
2009-02-01 23:04
2009-02-01 22:40
2009-02-01 22:01 1 a------- c:\windows\system32\uniq.tll
2009-02-01 22:01 43,520 a------- c:\windows\system32\303374.exe
2009-02-01 21:41
2009-02-01 13:36
2009-02-01 13:36 334,792 a------- c:\windows\system32\_AxShlEx.dll
2009-02-01 13:35 348,160 a------- c:\windows\system32\MSVCR71.dll
2009-02-01 13:33 499,712 a------- c:\windows\system32\msvcp71.dll
2009-02-01 13:32 273,024 -c------ c:\windows\system32\dllcache\bthport.sys
2009-02-01 13:32 273,024 -------- c:\windows\system32\drivers\bthport.sys
2009-02-01 13:31 2,138,624 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-01 13:31 2,182,656 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-01 13:31 2,060,032 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-01 13:31 2,018,304 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-01 13:29 453,632 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-02-01 13:27
2009-02-01 13:14
2009-02-01 13:14
2009-02-01 13:11 31,768 a------- c:\windows\system32\wucltui.dll.mui
2009-02-01 13:11 27,672 a------- c:\windows\system32\wuaucpl.cpl.mui
2009-02-01 13:11 27,672 a------- c:\windows\system32\wuapi.dll.mui
2009-02-01 13:11 18,968 a------- c:\windows\system32\wuaueng.dll.mui
2009-02-01 13:11
2009-02-01 13:09
2009-02-01 13:07
2009-02-01 13:07
2009-02-01 11:20
2009-02-01 11:18 325,128 a------- c:\windows\system32\drivers\avgldx86.sys
2009-02-01 11:18 107,272 a------- c:\windows\system32\drivers\avgtdix.sys
2009-02-01 11:18 10,520 a------- c:\windows\system32\avgrsstx.dll
2009-02-01 11:18
2009-02-01 11:12
2009-02-01 11:12
2009-02-01 11:06
2009-02-01 09:38
2009-02-01 08:44
2009-02-01 03:50
2009-02-01 03:20
2009-02-01 03:20
2009-02-01 03:18
2009-02-01 03:18
2009-02-01 03:16
2009-02-01 03:14 717,296 a------- c:\windows\system32\drivers\sptd.sys
2009-02-01 03:14
2009-02-01 02:47
2009-02-01 02:47
2009-02-01 02:46 206,793 a------- c:\windows\system32\nvapps.nvb
2009-02-01 02:46
2009-02-01 02:46
2009-02-01 02:22
2009-02-01 02:22 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-01 02:22 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-01 02:22
2009-02-01 02:22
2009-02-01 02:14
2009-02-01 02:07 13,646 a------- c:\windows\system32\wpa.bak
2009-02-01 02:05 261 a------- c:\windows\system32\$winnt$.inf
2009-02-01 01:53
2009-02-01 01:40
2009-02-01 01:25
2009-02-01 01:25
2009-02-01 01:25
2009-02-01 01:25
2009-02-01 01:25
2009-02-01 01:25
2009-02-01 01:25
2009-02-01 01:25
2009-02-01 01:21
2009-02-01 01:21
2009-02-01 01:20
2009-02-01 01:19
2009-02-01 01:19
2009-02-01 01:18
2009-02-01 01:18
2009-02-01 01:18
2009-02-01 01:17
2009-02-01 01:10
2009-02-01 01:10
2009-02-01 01:09
2009-02-01 01:09
2009-02-01 01:09
2009-02-01 01:09
2009-02-01 01:07
==================== Find3M ====================
2009-02-07 07:24 105,564 a------- c:\windows\pchealth\helpctr\config\cache\Personal_32_1031.dat
2009-02-07 07:24 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-02-01 02:00 316,924 a------- c:\windows\system32\perfh007.dat
2009-02-01 02:00 48,354 a------- c:\windows\system32\perfc007.dat
2009-02-01 01:53 335,872 a------- c:\windows\HideWin.exe
2009-02-01 01:19 21,740 a------- c:\windows\system32\emptyregdb.dat
2009-01-07 11:28 453,152 a------- c:\windows\system32\nvuninst.exe
2008-12-11 12:57 333,184 a------- c:\windows\system32\drivers\srv.sys
2008-12-10 09:45 70,936 a------- c:\windows\system32\PhysXLoader.dll
2008-12-04 09:28 24,344 a------- c:\windows\system32\PhysXDevice.dll
2008-11-26 08:55 288,024 a------- c:\windows\system32\PhysXCplUI.exe
2008-11-25 08:38 288,024 a------- c:\windows\system32\PhysXCompatCplUI.exe
============= FINISH: 7:27:03,50 ===============