Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


infected with TDSS & google keeps redirecting

  • This topic is locked This topic is locked
2 replies to this topic

#1 pradip84


  • Members
  • 1 posts
  • Local time:02:19 PM

Posted 20 March 2011 - 12:54 PM

DDS (Ver_11-03-05.01) - NTFSx86
Run by deepak at 22:49:27.79 on Fri 03/04/2011
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3317.2795 [GMT 5.5:30]
AV: Total Security 11.00 *Enabled/Updated* {05C1329D-F0E0-4B19-9D15-54F9BC3ADE87}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\BrightEcho\LanRoad PPPoE Client\LanRoad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\deepak\Application Data\1.tmp
C:\Documents and Settings\deepak\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://in.rd.yahoo.com/customize/ycomp/defaults/sp/*http://in.yahoo.com
mDefault_Page_URL = hxxp://in.yahoo.com/?fr=fp-spt_gen
mStart Page = hxxp://in.yahoo.com/?fr=fp-spt_gen
uInternet Connection Wizard,ShellNext = https://activation.bsnl.co.in/wizlet/ReportAgent/reportAgentPrepare.do?embedded=false
uSearchURL,(Default) = hxxp://in.rd.yahoo.com/customize/ycomp/defaults/su/*http://in.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: QHIEPro Class: {02d6b6b3-5d97-4ede-aac1-4d0be8fe9cd3} - c:\progra~1\quickh~1\quickh~1\qhiepro.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: APop Class: {efca9d4b-f2e8-487d-8505-e4d0e459abfe} - c:\progra~1\quickh~1\quickh~1\apop.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [MS Service Manager] c:\docume~1\deepak\locals~1\temp\idemoodp0cetka.exe
uRun: [A9YA3MI1CF] c:\docume~1\deepak\locals~1\temp\Jt1.exe
uRun: [A9YA3MI1CF] c:\docume~1\deepak\locals~1\temp\Jt1.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [MotiveReportAgent] "c:\program files\common files\motive\mccibootstrapper.exe" /url="-appkey=motive -windowcontext=reportagent -url=file://c:\program files\common files\motive\reportagent.html" /browsertype=custommsie /browserpath="c:\program files\common files\motive\MotiveBrowser.exe" /hidden
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [Quick Heal Core UI] c:\progra~1\quickh~1\quickh~1\strtupap.exe
mRun: [CmPCIaudio] RunDll32 CMICNFG3.CPL,CMICtrlWnd
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [SecurDisc] c:\program files\nero\nero 7\incd\NBHGui.exe
mRun: [InCD] c:\program files\nero\nero 7\incd\InCD.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [MS Service Manager] c:\docume~1\deepak\locals~1\temp\idemoodp0cetka.exe
mRunOnce: [Startup Scan] c:\progra~1\quickh~1\quickh~1\Sensor.EXE /check
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
TCP: {1A3BD160-7014-4D7F-B3D3-4B114C480900} =
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
Hosts: www.avast.com
Hosts: www.avg.com
Hosts: www.bitdefender.com
Hosts: www.eset.com
Hosts: www.f-secure.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\deepak\applic~1\mozilla\firefox\profiles\aujue5dj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://in.search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.in/
FF - prefs.js: keyword.URL - hxxp://in.search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
R1 ggc;ggc;c:\windows\system32\drivers\ggc.sys [2011-2-21 46464]
R2 catflt;catflt;c:\windows\system32\drivers\catflt.sys [2011-2-21 108928]
R2 Core Mail Protection;Core Mail Protection;c:\progra~1\quickh~1\quickh~1\EMLPROXY.EXE [2011-2-21 30176]
R2 Core Scanning Server;Core Scanning Server;c:\progra~1\quickh~1\quickh~1\SAPISSVC.EXE [2011-2-21 54656]
R2 EMLSS;EMLSS;c:\windows\system32\drivers\EMLTDI.SYS [2011-2-21 29312]
R2 Online Protection System;Online Protection System;c:\progra~1\quickh~1\quickh~1\opssvc.exe [2011-2-21 19328]
R2 Quick Update Service;Quick Update Service;c:\progra~1\quickh~1\quickh~1\quhlpsvc.exe [2011-2-21 58752]
R2 SSHNAS;SSHNAS;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R3 iadusb;USB IAD LAN Modem;c:\windows\system32\drivers\glauiad.sys [2011-2-21 30336]
R3 LRMINIPORT;LanRoad PPPoE Adapter;c:\windows\system32\drivers\lrpppoe.sys [2011-2-21 23552]
S0 mscank;mscank;c:\windows\system32\drivers\mscank.sys [2011-2-21 31808]
S2 inezoezuqjkdg;inezoezuqjkdg;c:\docume~1\deepak\locals~1\temp\DAT24.tmp.exe [2011-3-12 59600]
S3 32252;32252;\??\c:\docume~1\deepak\locals~1\temp\47200190\32252.sys --> c:\docume~1\deepak\locals~1\temp\47200190\32252.sys [?]
S3 LRPPPOE;LanRoad PPPoE Protocol;c:\windows\system32\drivers\lrpppoe.sys [2011-2-21 23552]
=============== Created Last 30 ================
2011-03-12 14:15:42 163872 ----a-w- c:\windows\system32\drivers\str.sys
2011-03-04 17:18:55 75264 ------w- c:\docume~1\deepak\applic~1\1.tmp
2011-03-03 19:48:06 117760 ----a-w- c:\docume~1\deepak\applic~1\42.tmp
2011-03-03 13:47:04 119808 ----a-w- c:\windows\Jwogyc.exe
2011-03-03 09:10:22 119808 ----a-w- c:\windows\Jwogyb.exe
2011-03-03 08:35:45 119808 ----a-w- c:\windows\Jwogya.exe
2011-02-28 17:15:44 -------- d-----w- c:\docume~1\deepak\locals~1\applic~1\Adobe
2011-02-21 17:59:04 -------- d-----w- c:\program files\MovieToolbox
2011-02-21 17:03:37 31 ----a-w- c:\windows\system32\windowsnmgetini.dll
2011-02-21 17:03:28 -------- d-----w- c:\program files\MPEG Converter
2011-02-21 15:51:31 -------- d-----w- c:\docume~1\deepak\locals~1\applic~1\Yahoo
2011-02-21 15:50:59 -------- d-----w- c:\docume~1\deepak\locals~1\applic~1\Ahead
2011-02-21 15:46:26 -------- d-----w- c:\program files\Nero
2011-02-21 15:46:26 -------- d-----w- c:\docume~1\alluse~1\applic~1\Nero
2011-02-21 15:46:08 819200 ----a-w- c:\program files\windows media player\wmsetsdk.exe
2011-02-21 15:46:08 47616 ----a-w- c:\program files\windows media player\msoobci.dll
2011-02-21 15:45:25 -------- d-----w- c:\windows\RegisteredPackages
2011-02-21 15:21:57 917504 ----a-r- c:\windows\system\CMDS3D3.DLL
2011-02-21 15:21:57 712704 ----a-r- c:\windows\system32\AUDIO3D3.DLL
2011-02-21 15:21:57 712704 ----a-r- c:\windows\system32\a3d.dll
2011-02-21 15:21:56 801280 ----a-r- c:\windows\system32\drivers\cmuda3.sys
2011-02-21 15:21:56 36864 ----a-r- c:\windows\system32\CMUDA3.DLL
2011-02-21 15:21:56 32768 ----a-r- c:\windows\system32\UDAPROP3.DLL
2011-02-21 15:21:56 28672 ----a-r- c:\windows\system32\CMRMDRV3.DLL
2011-02-21 15:21:56 233472 ----a-r- c:\windows\system32\CMRMDRV3.exe
2011-02-21 15:21:16 28672 ------r- c:\windows\CmiPCIUninstall.exe
2011-02-21 15:20:28 -------- d-----w- c:\program files\C-Media PCI Audio
2011-02-21 15:20:01 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll
2011-02-21 15:20:01 192512 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll
2011-02-21 15:20:00 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll
2011-02-21 15:20:00 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2011-02-21 15:19:59 729088 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll
2011-02-21 15:19:57 188548 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll
2011-02-21 15:19:53 311428 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll
2011-02-21 10:40:21 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2011-02-21 09:45:06 -------- d-----w- c:\program files\Yahoo!
2011-02-21 07:47:24 31808 ----a-w- c:\windows\system32\drivers\mscank.sys
2011-02-21 07:47:15 29312 ----a-w- c:\windows\system32\drivers\EMLTDI.SYS
2011-02-21 07:47:02 108928 ----a-w- c:\windows\system32\drivers\catflt.sys
2011-02-21 07:46:58 -------- d-----w- c:\program files\Quick Heal
2011-02-21 07:45:46 -------- d-----w- c:\windows\system32\gprodat
2011-02-21 07:45:37 46464 ----a-w- c:\windows\system32\drivers\ggc.sys
2011-02-21 07:11:14 165376 ----a-w- c:\windows\system32\unrar.dll
2011-02-21 07:11:13 839680 ----a-w- c:\windows\system32\lameACM.acm
2011-02-21 07:11:12 790528 ----a-w- c:\windows\system32\xvidcore.dll
2011-02-21 07:11:12 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2011-02-21 07:11:12 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-02-21 07:11:12 134144 ----a-w- c:\windows\system32\xvidvfw.dll
2011-02-21 07:11:11 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2011-02-21 07:11:09 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-02-21 07:06:52 -------- d-----w- c:\program files\uTorrent
2011-02-21 07:06:37 -------- d-----w- c:\docume~1\deepak\applic~1\uTorrent
2011-02-21 07:05:43 -------- d-----w- c:\docume~1\deepak\locals~1\applic~1\Mozilla
2011-02-21 07:04:33 -------- d-----w- c:\program files\VideoLAN
2011-02-21 06:44:18 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2011-02-21 06:44:18 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-02-21 06:44:17 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-02-21 06:44:17 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-02-21 06:44:15 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2011-02-21 05:31:18 49152 ----a-w- c:\windows\system32\LRN2KE.DLL
2011-02-21 05:31:18 23552 ----a-w- c:\windows\system32\drivers\lrpppoe.sys
2011-02-21 05:31:18 -------- d-----w- c:\program files\BrightEcho
2011-02-21 05:31:10 733184 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iKernel.dll
2011-02-21 05:31:10 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\ctor.dll
2011-02-21 05:31:10 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\DotNetInstaller.exe
2011-02-21 05:31:10 303236 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\setup.dll
2011-02-21 05:31:10 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iscript.dll
2011-02-21 05:31:10 180356 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iGdi.dll
2011-02-21 05:31:10 172032 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iuser.dll
2011-02-21 05:26:32 38400 ----a-w- c:\windows\system32\CoInst.dll
2011-02-21 05:26:32 30336 ----a-w- c:\windows\system32\drivers\glauiad.sys
2011-02-21 05:26:32 -------- d-----w- C:\temp
2011-02-21 05:26:31 -------- d-----w- c:\program files\driver
2011-02-21 05:19:25 6345 ----a-r- c:\windows\system32\DevMngr.vxd
2011-02-21 05:16:52 -------- d-----w- c:\program files\common files\Motive
2011-02-21 05:08:27 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2011-02-21 05:08:27 32592 ----a-w- c:\windows\system32\msonpmon.dll
2011-02-21 05:05:27 -------- d-----w- c:\windows\SHELLNEW
2011-02-21 05:05:14 -------- d-----w- c:\docume~1\deepak\locals~1\applic~1\Microsoft Help
==================== Find3M ====================
2011-02-21 04:47:07 315392 ----a-w- c:\windows\HideWin.exe
============= FINISH: 22:50:17.45 ===============

Attached Files

BC AdBot (Login to Remove)


#2 SweetTech


    Agent ST

  • Members
  • 13,421 posts
  • Gender:Male
  • Location:Antarctica
  • Local time:04:49 AM

Posted 20 March 2011 - 01:05 PM

Hello and welcome to the forums!

My secret agent name on the forums is SweetTech (you can call me ST for short), it's a pleasure to meet you. :)

I would be glad to take a look at your log and help you with solving any malware problems.

If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
  • Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic.
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.

Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
  • IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

    Note: If AVG or CA Internet Security Suite is installed, you must remove these programs before using Combofix. If for some reason these applications will not uninstall, try uninstalling with AppRemover by Opswat.
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image

The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.

#3 SweetTech


    Agent ST

  • Members
  • 13,421 posts
  • Gender:Male
  • Location:Antarctica
  • Local time:04:49 AM

Posted 23 March 2011 - 11:03 AM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image

The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users