Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malware Infection: Random Audio and Redirected Browsing


  • Please log in to reply
1 reply to this topic

#1 Okemah

Okemah

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 09 December 2009 - 03:16 PM

I recently picked up a nasty little bug that will play random audio samples (an Energizer commercial, a Disney commercial, two guys talking about their vacation, random music interludes) at random times. This audio is not on my computer. I also am having trouble browsing the internet. When I click on a search result, I get re-directed to other sites. I have tried a few programs in hopes of removing the problem but to no avail. Any help you can provide would be appreciated. I have run DDS and RootRepeal as well.
Here is the DDS one:

DDS (Ver_09-12-01.01) - FAT32x86
Run by Default at 11:52:23.60 on Wed 12/09/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.467 [GMT -8:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
SVCHOST.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\Default\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
IE: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {4D054067-DE3A-48F9-B19B-BCD229B9AE8D} - hxxp://www.samsungdp.com/printerhelp/ActiveX/DrPrinter.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157219373484
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://walmart.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-12-1 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1184912]
S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys --> c:\windows\system32\drivers\SSPORT.sys [?]
S3 c60a78d4-b1a7-4b68-a77e-96e427de3b80;c60a78d4-b1a7-4b68-a77e-96e427de3b80;\??\e:\player\cds300.dll --> e:\player\cds300.dll [?]
S3 DMSKSSRh;DMSKSSRh;\??\c:\docume~1\default\locals~1\temp\dmskssrh.sys --> c:\docume~1\default\locals~1\temp\DMSKSSRh.sys [?]

=============== Created Last 30 ================

2009-12-09 07:12:17 0 d-----w- c:\docume~1\default\applic~1\Malwarebytes
2009-12-09 07:12:04 0 d-----w- c:\program files\MSXML 4.0
2009-12-02 03:37:22 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-12-02 01:28:28 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-02 01:28:22 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-12-02 00:40:52 0 d--h--w- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-02 00:40:46 0 d-----w- c:\program files\Lavasoft
2009-11-29 01:25:42 72 ----a-w- c:\documents and settings\default\default.pls
2009-11-29 01:03:16 0 d-sha-r- C:\cmdcons
2009-11-29 01:00:50 77312 ----a-w- c:\windows\MBR.exe
2009-11-29 01:00:50 260096 ----a-w- c:\windows\pev.exe
2009-11-26 07:24:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-26 07:24:18 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-26 07:24:18 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-11-26 07:24:17 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-25 07:33:53 0 d-----w- c:\windows\system32\wbem\Repository
2009-11-19 21:19:15 0 d-----w- c:\program files\Vuze

==================== Find3M ====================

2009-12-03 01:32:14 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2009-12-03 01:32:14 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-10-22 09:19:04 5939712 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-09-25 22:45:14 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-09-25 21:55:58 21840 ----a-w- c:\windows\system32\SIntfNT.dll
2009-09-25 21:55:58 17212 ----a-w- c:\windows\system32\SIntf32.dll
2009-09-25 21:55:58 12067 ----a-w- c:\windows\system32\SIntf16.dll
2009-09-11 15:18:40 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 15:18:40 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2009-08-19 03:24:08 19388 ----a-w- c:\program files\common files\ixonybi._sy
2009-08-19 02:52:48 19014 ----a-w- c:\program files\common files\aqos.db
2009-08-19 02:52:48 14533 ----a-w- c:\program files\common files\fivigiv._sy
2009-08-19 02:22:24 18152 ----a-w- c:\program files\common files\qado.bin

============= FINISH: 11:52:45.78 ===============

BC AdBot (Login to Remove)

 


#2 Okemah

Okemah
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 09 December 2009 - 03:24 PM

I also have two logs to attach, but I don't have an attach option on my screen.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users