First time poster here. I have tried for a week to fix this and now its time for expert intercession.
It appears both IE and Firefox are hijacked and redirected to find-for-you-service.com.
Additionally, I believe I have something nasty in c:\windows\system32\drivers\xwoarh.sys
All research points to something nasty. I cannot remove, rename or otherwise delete the file, locks up the entire computer when it gets poked.
I have tried all manner of AV scanners and nothing seems to run to completion. They all stop at the system 32 drivers folder. You may evidence of multiple AV software installs and removals.
I cannot run root repeal for the same reason.
the dds log follows.
DDS (Ver_09-09-29.01) - NTFSx86
Run by cliff at 1:05:38.45 on Mon 10/12/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2389 [GMT -4:00]
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqnrs08.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\cliff.ECT\Desktop\dds.pif
============== Pseudo HJT Report ===============
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = https://www.google.com/a/eandctech.com/Serv...t<mplcache=2
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: microsoft.com\update
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255047923843
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1254797198875
DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} - hxxp://www.trimble.com/datatransfer/v147/isetupml.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - hxxp://www.installengine.com/engine/isetup.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\cliff.ect\applic~1\mozilla\firefox\profiles\fh1tl68k.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\cliff.ect\local settings\application data\google\update\1.2.131.11\npGoogleOneClick5.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [2008-10-14 86552]
R2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2009-10-5 582992]
R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2009-10-5 206608]
S0 cerc6;cerc6; [x]
S1 fd415861;fd415861;c:\windows\system32\drivers\fd415861.sys --> c:\windows\system32\drivers\fd415861.sys [?]
S2 xwoarh;xwoarh;c:\windows\system32\drivers\xwoarh.sys [2009-10-5 175616]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [2008-10-14 24876]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2009-10-5 206608]
S3 TrmbTS;TrimbleTS Driver (TrmbTS.sys);c:\windows\system32\drivers\TrmbTS.sys [2007-4-4 29184]
S3 TRMUSB5K;Trimble USB GPS Driver;c:\windows\system32\drivers\TRMUSB5K.SYS [2007-4-4 9881]
S4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-11-16 1174152]
=============== Created Last 30 ================
2009-10-12 00:49 3,250 a------- c:\windows\system32\wbem\Outlook_01ca4af75d8ded57.mof
2009-10-11 17:45 <DIR> --d----- c:\docume~1\cliff.ect\applic~1\Office Genuine Advantage
2009-10-10 13:42 <DIR> --d----- c:\program files\G Data
2009-10-10 09:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg9
2009-10-10 08:27 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-10-09 19:15 <DIR> --d----- c:\docume~1\cliff.ect\applic~1\Uniblue
2009-10-09 18:56 2,066,432 -c------ c:\windows\system32\dllcache\mstscax.dll
2009-10-09 18:55 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-09 18:55 2,066,048 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2009-10-09 18:55 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-09 18:55 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-09 18:55 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-10-09 18:55 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-10-09 18:01 28,288 ac------ c:\windows\system32\dllcache\xjis.nls
2009-10-09 18:01 156,672 ac------ c:\windows\system32\dllcache\winzm.ime
2009-10-09 18:01 156,672 ac------ c:\windows\system32\dllcache\winsp.ime
2009-10-09 18:01 156,672 ac------ c:\windows\system32\dllcache\winpy.ime
2009-10-09 18:01 79,360 ac------ c:\windows\system32\dllcache\winar30.ime
2009-10-09 18:01 72,704 ac------ c:\windows\system32\dllcache\wingb.ime
2009-10-09 18:01 65,536 ac------ c:\windows\system32\dllcache\winime.ime
2009-10-09 17:59 92,160 ac------ c:\windows\system32\dllcache\evntwin.exe
2009-10-09 17:57 488 a---hr-- c:\windows\system32\logonui.exe.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\WindowsShell.Manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\wuaucpl.cpl.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\sapi.cpl.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\nwc.cpl.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\ncpa.cpl.manifest
2009-10-09 16:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PCDr
2009-10-09 16:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC-Doctor
2009-10-09 16:08 <DIR> --d----- c:\program files\Dell Support Center
2009-10-09 16:08 <DIR> --d----- c:\program files\common files\supportsoft
2009-10-08 21:35 171 a------- c:\windows\system32\conf.xml
2009-10-08 21:31 <DIR> --d----- c:\windows\system32\NtmsData
2009-10-08 20:13 520,192 -------- c:\windows\system32\ati2sgag.exe
2009-10-08 19:36 16,535 a----r-- c:\windows\SET72.tmp
2009-10-08 19:36 1,088,840 a----r-- c:\windows\SET66.tmp
2009-10-08 19:36 1,296,669 a----r-- c:\windows\SET63.tmp
2009-10-08 18:51 4,444 a------- c:\windows\system32\pid.PNF
2009-10-08 18:50 7,334 ac------ c:\windows\system32\dllcache\wmerrenu.cat
2009-10-08 18:50 16,535 a----r-- c:\windows\SETDF.tmp
2009-10-08 18:50 1,088,840 a----r-- c:\windows\SETD3.tmp
2009-10-08 18:50 1,296,669 a----r-- c:\windows\SETD0.tmp
2009-10-08 18:50 4,754 a------- c:\windows\setupapi.old
2009-10-08 18:17 <DIR> --d----- c:\program files\CCleaner
2009-10-08 18:11 389,120 a------- c:\windows\system32\CF27903.exe
2009-10-08 17:17 <DIR> a-dshr-- C:\cmdcons
2009-10-08 14:42 <DIR> --d----- c:\windows\Dell
2009-10-08 13:05 <DIR> --d----- c:\docume~1\cliff.ect\applic~1\Malwarebytes
2009-10-08 09:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-07 18:17 <DIR> --d----- c:\documents and settings\cliff.ect\.scribus
2009-10-07 18:17 <DIR> --d----- c:\program files\Scribus 1.3.3.13
2009-10-06 20:32 68,976 a------- c:\windows\system32\drivers\GRD.sys
2009-10-06 20:32 51,784 a------- c:\windows\system32\drivers\GDTdiIcpt.sys
2009-10-06 20:28 53,320 a------- c:\windows\system32\drivers\MiniIcpt.sys
2009-10-06 20:27 27,720 a------- c:\windows\system32\drivers\GDBehave.sys
2009-10-06 20:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\G DATA
2009-10-06 14:07 <DIR> --d----- c:\windows\system32\Dell
2009-10-06 13:46 262,144 a------- c:\windows\system32\default_user_class.dat
2009-10-06 12:41 <DIR> --d----- c:\program files\ACW
2009-10-06 11:40 195,440 -------- c:\windows\system32\MpSigStub.exe
2009-10-05 22:06 <DIR> --d----- c:\program files\UPHClean
2009-10-05 21:54 <DIR> --d----- c:\program files\Windows Installer Clean Up
2009-10-05 21:33 <DIR> --d----- C:\2d684e3926d475e8cc30ab71296d
2009-10-05 19:55 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-10-05 19:55 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-10-05 16:11 206,608 a------- c:\windows\system32\drivers\TMPassthru.sys
2009-10-05 16:11 <DIR> --d----- c:\program files\Trend Micro
2009-10-05 15:27 <DIR> --d----- C:\53d46bf1f8fdf3b8c93a324a
2009-10-05 15:22 <DIR> --dsh--- c:\documents and settings\cliff.ect\IECompatCache
2009-10-05 15:13 <DIR> --d-h--- c:\windows\system32\GroupPolicy
2009-10-05 15:07 <DIR> --d----- c:\documents and settings\cliff.ect\.housecall6.6
2009-10-05 10:33 175,616 a--s---- c:\windows\system32\drivers\xwoarh.sys
2009-10-03 22:19 96,072 a---h--- c:\windows\system32\mlfcache.dat
2009-10-03 13:42 107,368 a------- c:\windows\system32\GEARAspi.dll
2009-10-03 13:42 26,600 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-03 13:41 <DIR> --d----- c:\program files\iPod
2009-10-03 13:41 <DIR> --d----- c:\program files\iTunes
2009-10-03 13:41 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-03 13:41 <DIR> --d----- c:\program files\Bonjour
2009-09-15 21:06 31 a------- c:\windows\tgo_v160.ini
2009-09-13 20:52 <DIR> --d----- C:\GRASS-6-SVN
==================== Find3M ====================
2009-10-10 08:36 128,832 a------- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-10-09 17:56 23,412 a------- c:\windows\system32\emptyregdb.dat
2009-10-07 22:05 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-03 15:07 403,816 a------- c:\windows\system32\OGACheckControl.dll
2009-08-03 15:07 322,928 a------- c:\windows\system32\OGAAddin.dll
2009-08-03 15:07 230,768 a------- c:\windows\system32\OGAEXEC.exe
2009-07-29 00:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 00:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-27 08:20 87,699 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2008-09-24 14:39 88 a--shr-- c:\windows\system32\55D4A5C27A.sys
2008-09-24 14:39 3,452 a--sh--- c:\windows\system32\KGyGaAvL.sys
============= FINISH: 1:05:51.89 ===============