When the redirection occurs it happens only in IE8, and I usually just shut down IE when it happens and just use chrome, then later I can go back to IE, and browse without redirection. These are some of the sites I'm redirected to.
http :// and2.2507.asklots.com /jump1/?affiliate=and2&subid=2507&terms=cisco&sid=Z485044415%40%40QMfVjNxkTOwMzX5cjMy8lMy8FOz81MxIzN2QDN4ITM&a=naq6&mr=1&rc=0
http :// www. happili.com /z/innerxy.php?q=Cisco&xy=and2-2507
www. aniengtgrhoo .com (which also removes itself from IE history)
Assistance in locating and removal of the infection is being requested.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Administrator at 8:40:02.11 on Wed 09/15/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.2038.1043 [GMT -4:00]
AV: Symantec AntiVirus *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Symantec AntiVirus *enabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\atashost.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Windows\system32\mstsc.exe
C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\EditPlus 2\editplus.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Administrator\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = 10.2.251.31:8000
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Google Update] "c:\users\administrator\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office10\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-US/wlscctrl2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://symantec.webex.com/client/T27L10NSP11EP14/support/ieatgpc1.cab
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
R2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2010-7-6 43912]
R2 SavRoam;SavRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-11-28 122008]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-9-14 1153368]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-11-28 1962136]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-6-17 102448]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 SolarWinds TFTP Server;SolarWinds TFTP Server;c:\program files\solarwinds\tftpserver\SolarWinds TFTP Server.exe [2010-6-10 54784]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-17 1343400]
S4 UEBHCOCUIAN;UEBHCOCUIAN;c:\users\admini~1\appdata\local\temp\uebhcocuian.exe --> c:\users\admini~1\appdata\local\temp\UEBHCOCUIAN.exe [?]
=============== Created Last 30 ================
2010-09-15 12:39:11 0 ----a-w- c:\users\administrator\defogger_reenable
2010-09-15 05:25:22 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-14 18:07:56 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-14 18:07:53 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-14 18:07:52 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 12:39:40 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-14 12:39:40 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-09-08 17:22:49 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2010-09-08 17:22:48 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2010-09-08 17:22:47 0 d-----w- c:\program files\PDFCreator
2010-09-08 11:12:53 0 d-----w- c:\program files\Beyond Compare 2
2010-09-08 11:10:33 0 d-----w- c:\users\admini~1\appdata\roaming\Scooter Software
2010-09-03 14:16:37 0 d-----w- c:\programdata\SolarWinds
2010-09-03 14:14:34 0 d-----w- c:\program files\SolarWinds
2010-09-01 15:44:30 720896 ----a-w- c:\windows\iun6002.exe
2010-09-01 15:44:18 0 d-----w- c:\program files\Look@LAN
2010-08-30 15:00:08 63560 ----a-w- c:\users\admini~1\appdata\roaming\GDIPFONTCACHEV1.DAT
2010-08-27 15:29:58 0 d-----w- C:\PFiles
2010-08-27 13:24:38 0 d-----w- c:\program files\BarCode 1.0a
2010-08-27 13:06:35 249856 ------w- c:\windows\Setup1.exe
2010-08-27 13:06:34 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-08-27 13:00:17 0 d-----w- C:\TFTP-Root
2010-08-25 15:07:43 0 d-----w- c:\programdata\Office Genuine Advantage
2010-08-25 14:55:23 0 d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-08-25 14:26:14 0 d-----w- c:\program files\Microsoft Security Essentials
2010-08-25 13:22:22 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-25 13:02:25 0 d-----w- c:\program files\Yahoo!
2010-08-25 13:02:20 0 d-----w- c:\program files\CCleaner
2010-08-25 12:36:01 0 d-----w- c:\program files\Trend Micro
2010-08-25 12:29:27 0 d-----w- c:\users\admini~1\appdata\roaming\Malwarebytes
2010-08-25 12:27:07 0 d-----w- c:\programdata\Malwarebytes
2010-08-25 04:27:09 571904 ----a-w- c:\windows\system32\oleaut32.dll
2010-08-24 13:18:17 0 d-----w- c:\program files\Canon
2010-08-24 13:18:12 306688 ----a-w- c:\windows\IsUninst.exe
2010-08-19 16:22:20 139264 ----a-w- c:\windows\system32\AudioCapture.ocx
2010-08-19 16:22:14 0 d-----w- c:\program files\Easy MP3 Sound Recorder
2010-08-18 18:50:03 0 d-sh--w- c:\windows\ftpcache
2010-08-18 16:17:22 0 d-----w- c:\users\admini~1\appdata\roaming\Password Solutions
2010-08-18 16:17:22 0 d-----w- c:\program files\Password Solutions
2010-08-18 14:21:07 12872 ----a-w- c:\windows\system32\bootdelete.exe
2010-08-18 14:17:04 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-08-18 14:16:10 0 d-----w- c:\programdata\Hitman Pro
2010-08-18 14:16:07 0 d-----w- c:\program files\Hitman Pro 3.5
2010-08-18 11:57:25 1355776 ----a-w- c:\windows\system32\MSVBVM50.DLL
2010-08-17 14:06:15 77312 ----a-w- c:\windows\MBR.exe
2010-08-17 14:06:13 256512 ----a-w- c:\windows\PEV.exe
2010-08-17 14:06:12 98816 ----a-w- c:\windows\sed.exe
2010-08-17 14:06:12 161792 ----a-w- c:\windows\SWREG.exe
2010-08-16 16:47:41 93696 --sha-r- c:\windows\system32\C_1254L.dll
2010-08-16 14:25:05 0 d-----w- C:\DRIVERS
2010-08-16 14:13:50 157696 ----a-w- c:\windows\system32\unrar.dll
2010-08-16 14:13:49 1415680 ----a-w- c:\windows\system32\WMV9VCM.dll
2010-08-16 14:13:47 344064 ----a-w- c:\windows\system32\msvcr70.dll
2010-08-16 14:13:47 245408 ----a-w- c:\windows\system32\unicows.dll
2010-08-16 14:13:47 19968 ----a-w- c:\windows\system32\cpuinf32.dll
2010-08-16 13:22:44 475136 ----a-w- c:\windows\lk_c4.dll
2010-08-16 13:22:44 399872 ----a-w- c:\windows\c4dstand.dll
2010-08-16 13:22:30 0 d-----w- c:\program files\LearnKey
2010-08-16 13:22:29 98304 ----a-w- c:\windows\system32\tsccvid.dll
2010-08-16 13:22:25 600576 ----a-w- c:\windows\LkUnInst.exe
2010-08-16 13:22:25 3460 ----a-w- c:\windows\splash.ini
2010-08-16 13:22:25 2238 ----a-w- c:\windows\LK.ico
==================== Find3M ====================
2010-08-26 16:29:25 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-11 18:21:26 230736 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-06 14:52:14 43912 ----a-w- c:\windows\system32\atashost.exe
2010-07-06 14:52:14 104328 ----a-w- c:\windows\system32\atsckernel.exe
2010-06-30 06:25:31 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-19 06:33:29 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07:18 2326016 ----a-w- c:\windows\system32\win32k.sys
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 8:40:51.49 ===============