Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Browser redirect & Tdss.565


  • This topic is locked This topic is locked
2 replies to this topic

#1 migal

migal

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:46 AM

Posted 27 December 2009 - 07:46 PM

Browser is slow and jumpy. Selecting web pages using bookmarks works fine. However I get redirected when selecting a link after a search. Dr Web found Tdss.565 and eradicated it but it keeps returning. I also scanned the computer with AVG Free, Malwarbytes, and Kapersky online. They found infections and they were removed but the problem persists.



DDS (Ver_09-12-01.01) - NTFSx86
Run by Carmen at 19:20:34.03 on Sun 12/27/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.158 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Documents and Settings\Carmen\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Carmen\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Carmen\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Carmen\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Carmen\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Carmen\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://ca.finance.yahoo.com/p?k=pf_2
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\carmen\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1236517113187
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1236517215765
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-27 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-27 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-27 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-12-27 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-12-27 285392]
S2 gupdate1c9993d5b67a546;Google Update Service (gupdate1c9993d5b67a546);c:\program files\google\update\GoogleUpdate.exe [2009-2-27 133104]

=============== Created Last 30 ================

2009-12-27 22:23:56 0 d--h--w- C:\$AVG
2009-12-27 22:23:47 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-27 22:23:47 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-27 22:23:41 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-27 22:23:36 0 d-----w- c:\windows\system32\drivers\Avg
2009-12-27 18:41:04 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-12-27 17:38:37 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2009-12-27 11:20:23 0 d-sh--w- c:\docume~1\carmen\applic~1\SystemProc
2009-12-27 11:20:22 1 ----a-w- C:\s
2009-12-23 13:55:15 0 d-----w- c:\program files\MSECache
2009-12-23 13:40:09 28040 ----a-w- c:\windows\system32\mdimon.dll
2009-12-23 13:39:31 0 d-----w- c:\program files\Microsoft ActiveSync

==================== Find3M ====================

2009-12-27 19:56:16 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-12-27 18:40:52 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-03 21:14:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 21:13:56 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-29 07:45:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2007-03-21 00:25:26 2027029 ----a-w- c:\windows\inf\Rar.exe
2006-06-23 06:48:54 32768 ----a-r- c:\windows\inf\UpdateUSB.exe
2002-08-01 00:55:12 104 --sh--w- c:\windows\WSYS049.SYS

============= FINISH: 19:21:42.21 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 migal

migal
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:46 AM

Posted 28 December 2009 - 05:02 PM

I ran ComboFix followed by a scan with Malwarebytes and Dr. Web. I will scan with ESET later. No infections were found. I also uninstalled ComboFix. The computer is running normally. I suggest this thread be closed.

#3 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:01:46 PM

Posted 28 December 2009 - 07:00 PM

Closed per member's request
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users