I followed the instructions for my router.
Here is my DDS report.
Attached is the zipped attach file.
DDS (Ver_10-12-12.02) - FAT32x86
Run by a user at 13:59:34.05 on Sat 01/29/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1262.734 [GMT -5:00]
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
SVCHOST.EXE
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
SVCHOST.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\a user\Desktop\dds.com
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [LaunchApp] Alaunch
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.16.0.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\auser~1\applic~1\mozilla\firefox\profiles\r4hvxeho.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-1-25 11608]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-1-5 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 67656]
R1 SMBHC;Microsoft SM Bus Host Controller Driver;c:\windows\system32\drivers\smbhc.sys [2004-8-30 6784]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-1-25 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-1-25 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-1-25 61960]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-1-26 363344]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-1-26 20952]
R3 SMBBATT;Microsoft Smart Battery Driver;c:\windows\system32\drivers\smbbatt.sys [2004-8-30 16000]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 12872]
=============== File Associations ===============
.scr=AutoCADScriptFile
=============== Created Last 30 ================
2011-01-29 03:06:15 -------- d-sh--w- C:\Recycled
2011-01-27 03:23:32 -------- d-sha-r- C:\cmdcons
2011-01-27 03:11:49 98816 ----a-w- c:\windows\sed.exe
2011-01-27 03:11:49 89088 ----a-w- c:\windows\MBR.exe
2011-01-27 03:11:49 256512 ----a-w- c:\windows\PEV.exe
2011-01-27 03:11:49 161792 ----a-w- c:\windows\SWREG.exe
2011-01-27 02:58:32 -------- d-----w- c:\docume~1\auser~1\applic~1\Avira
2011-01-27 02:51:22 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-01-27 02:50:51 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-01-27 02:50:51 -------- d-----w- c:\docume~1\auser~1\applic~1\SUPERAntiSpyware.com
2011-01-27 02:50:28 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2011-01-27 02:45:24 -------- d-----w- c:\docume~1\auser~1\applic~1\Malwarebytes
2011-01-27 02:45:00 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-27 02:44:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-27 02:44:55 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-27 02:44:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-27 02:25:54 -------- d-----w- c:\program files\MSECache
2011-01-27 01:58:45 -------- d-----w- c:\docume~1\auser~1\locals~1\applic~1\Google
2011-01-27 01:58:23 -------- d-----w- c:\docume~1\auser~1\locals~1\applic~1\Deployment
2011-01-26 20:15:19 -------- d-----w- c:\docume~1\auser~1\locals~1\applic~1\Temp
2011-01-26 19:38:37 -------- d-----w- c:\docume~1\auser~1\locals~1\applic~1\Adobe
2011-01-26 17:09:27 -------- d-----w- c:\program files\common files\Macrovision Shared
2011-01-26 17:05:14 -------- d-----w- c:\program files\common files\Autodesk Shared
2011-01-26 17:05:14 -------- d-----w- c:\program files\AutoCAD 2010
2011-01-26 17:05:14 -------- d-----w- c:\docume~1\auser~1\locals~1\applic~1\Autodesk
2011-01-26 17:05:14 -------- d-----w- c:\docume~1\auser~1\applic~1\Autodesk
2011-01-26 17:04:35 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2011-01-26 17:04:35 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2011-01-26 17:04:30 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2011-01-26 17:04:08 -------- d-----w- c:\windows\Logs
2011-01-26 17:02:31 -------- d-----w- c:\windows\system32\XPSViewer
2011-01-26 17:01:23 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-01-26 17:01:02 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-01-26 17:01:02 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-01-26 17:01:02 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-01-26 17:01:02 117760 ------w- c:\windows\system32\prntvpt.dll
2011-01-26 17:01:01 575488 ------w- c:\windows\system32\xpsshhdr.dll
2011-01-26 17:01:01 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-01-26 17:01:01 1676288 ------w- c:\windows\system32\xpssvcs.dll
2011-01-26 17:01:01 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2011-01-26 17:01:01 -------- d-----w- C:\6986dbc250cfe2b0eb3f
2011-01-26 16:46:41 -------- d-----w- c:\program files\PowerISO
2011-01-26 03:44:00 26496 ----a-w- c:\windows\system32\dllcache\usbstor.sys
2011-01-25 22:04:21 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-01-25 22:04:20 -------- d-----w- c:\program files\Avira
2011-01-25 22:04:20 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2011-01-25 22:03:00 -------- d-----w- C:\V
2011-01-25 22:02:19 25840 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2011-01-25 22:02:19 24816 ----a-w- c:\windows\system32\mdimon.dll
2011-01-25 22:01:32 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-01-25 22:00:24 -------- d-----w- c:\windows\SHELLNEW
2011-01-25 21:44:53 -------- d-----w- c:\windows\system32\scripting
2011-01-25 21:44:53 -------- d-----w- c:\windows\l2schemas
2011-01-25 21:44:52 -------- d-----w- c:\windows\system32\en
2011-01-25 21:44:52 -------- d-----w- c:\windows\system32\bits
2011-01-25 21:39:34 -------- d-----w- c:\windows\network diagnostic
2011-01-25 21:26:48 -------- d-sh--w- c:\documents and settings\a user\PrivacIE
2011-01-25 21:26:10 135168 ----a-w- c:\windows\system32\igfxres.dll
2011-01-25 21:10:47 -------- d-sh--w- c:\documents and settings\a user\IETldCache
2011-01-25 21:07:48 557056 ----a-w- c:\windows\system32\Netw2c32.dll
2011-01-25 21:07:48 2732032 ----a-w- c:\windows\system32\Netw2r32.dll
2011-01-25 21:05:43 -------- d-----w- c:\program files\SystemRequirementsLab
2011-01-25 21:01:21 -------- d-----w- c:\windows\ie8updates
2011-01-25 21:01:11 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2011-01-25 21:01:11 602112 ------w- c:\windows\system32\dllcache\msfeeds.dll
2011-01-25 21:01:11 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-01-25 21:01:11 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2011-01-25 21:01:11 1991680 ------w- c:\windows\system32\dllcache\iertutil.dll
2011-01-25 21:01:11 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2011-01-25 21:01:09 11080704 ------w- c:\windows\system32\dllcache\ieframe.dll
2011-01-25 20:59:37 -------- d--h--w- c:\windows\ie8
2011-01-25 20:50:07 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-01-25 20:49:40 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-01-25 20:48:58 974848 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-01-25 20:48:58 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-01-25 20:48:32 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-01-25 20:38:44 -------- d-----w- c:\windows\ServicePackFiles
2011-01-25 20:29:56 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2011-01-25 20:29:56 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2011-01-25 20:29:55 357248 ------w- c:\windows\system32\dllcache\srv.sys
2011-01-25 20:29:02 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2011-01-25 20:28:53 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2011-01-25 20:28:35 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2011-01-25 20:27:18 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2011-01-25 20:27:18 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-01-25 20:27:18 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2011-01-25 20:27:18 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2011-01-25 20:27:18 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2011-01-25 20:27:18 110592 ------w- c:\windows\system32\dllcache\services.exe
2011-01-25 20:27:17 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2011-01-25 20:27:17 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2011-01-25 20:27:17 2146304 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-01-25 20:27:16 2189952 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-01-25 20:27:16 2024448 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-01-25 20:24:02 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2011-01-25 20:23:53 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2011-01-25 20:23:43 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2011-01-25 20:22:53 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-01-25 20:22:53 218112 ------w- c:\windows\system32\dllcache\wordpad.exe
2011-01-25 20:19:00 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2011-01-25 20:19:00 -------- d-----w- c:\windows\system32\PreInstall
2011-01-25 20:18:58 -------- d--h--w- c:\windows\$hf_mig$
2011-01-25 20:17:10 -------- d-sh--w- c:\documents and settings\a user\UserData
2011-01-25 17:05:58 -------- d-----w- c:\windows\system32\SoftwareDistribution
2011-01-25 17:03:24 21504 ----a-w- c:\windows\system32\hidserv.dll
2011-01-25 17:03:20 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-01-25 17:03:18 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2011-01-25 17:03:14 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-01-25 17:03:09 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
==================== Find3M ====================
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52:36 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26:58 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 ----a-w- c:\windows\system32\html.iec
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: TOSHIBA_MK8025GAS rev.KA023A -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-3
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89512555]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x895187b0]; MOV EAX, [0x8951882c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x89543AB8]
3 CLASSPNP[0xF7657FD7] -> nt!IofCallDriver[0x804E37D5] -> \Device\0000007d[0x894DC1C0]
5 ACPI[0xF75AE620] -> nt!IofCallDriver[0x804E37D5] -> [0x894DBD98]
\Driver\atapi[0x89538178] -> IRP_MJ_CREATE -> 0x89512555
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV DI, 0x5; XOR AX, AX; MOV DL, 0x80; INT 0x13; JAE 0x2d; DEC DI; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskTOSHIBA_MK8025GAS_______________________KA023A__#5&166915ea&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8951239B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
============= FINISH: 14:01:53.33 ===============