Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google redirects, pop-ups, "Generic host process" error


  • This topic is locked This topic is locked
2 replies to this topic

#1 warehouse8

warehouse8

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:05:50 PM

Posted 19 April 2011 - 12:18 AM

Hey guys,

Definitely appreciate the awesome service you are providing on this forum. I have been getting google redirects, pop-ups, and "generic host process" errors that shut down my audio upon restarting my computer. Malwarebytes has detected the trojan Hiloti, but I am still having issues. AVG is currently installed, and I am planning on uninstalling and replacing with Avira/Avast after this episode. Thanks for your help, as usual.

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Vamos Rafa at 1:13:16.76 on Tue 04/19/2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_21
.
============== Running Processes ===============
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
\??\C:\Program Files\AVG\AVG10\avgchsvx.exe
\??\C:\Program Files\AVG\AVG10\avgrsx.exe
\??\C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\DOCUME~1\VAMOSR~1\LOCALS~1\Temp\RarSFX0\h\iexplore.exe
C:\Documents and Settings\Vamos Rafa\My Documents\New2\OC\Core Temp.exe
C:\Documents and Settings\Vamos Rafa\Desktop\dds.scr
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k netsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\program files\flashget\jccatch.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll
uRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear
uRun: [Google Update] "c:\documents and settings\vamos rafa\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [DeathAdder] c:\program files\razer\deathadder\razerhid.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [nwiz] nwiz.exe /install
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [InstaLAN] "c:\program files\belkin\router setup and monitor\BelkinRouterMonitor.exe" startup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm
IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} - hxxps://uplink.healthsystem.virginia.edu/vdesk/terminal/urxvpn.cab#version=6030,2008,904,1951
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://uplink.healthsystem.virginia.edu/vdesk/terminal/f5tunsrv.cab#version=6030,2008,904,1947
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - c:\docume~1\vamosr~1\locals~1\temp\ixp000.tmp\InstallerControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {8E49176D-5B2E-4391-AA56-212161D660DE} - hxxp://pacs.hscs.virginia.edu/plugin/JavaSettings.exe
DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://uplink.healthsystem.virginia.edu/vdesk/terminal/urxshost.cab#version=6030,2008,904,1945
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://uplink.healthsystem.virginia.edu/vdesk/terminal/urxhost.cab#version=6030,2008,904,1940
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\vamosr~1\applic~1\mozilla\firefox\profiles\6320ji3r.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\vamos rafa\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\vamos rafa\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\vamos rafa\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\j2re1.4.2_05\bin\NPJPI142_05.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
.
============= SERVICES / DRIVERS ===============
.
R? f5ipfw;F5 Networks StoneWall Filter
R? Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service
R? npggsvc;nProtect GameGuard Service
R? SASENUM;SASENUM
R? TfFsMon;TfFsMon
R? TfNetMon;TfNetMon
R? TfSysMon;TfSysMon
R? urvpndrv;F5 Networks VPN Adapter
S? ALSysIO;ALSysIO
S? AVGIDSAgent;AVGIDSAgent
S? AVGIDSDriver;AVGIDSDriver
S? AVGIDSEH;AVGIDSEH
S? AVGIDSFilter;AVGIDSFilter
S? AVGIDSShim;AVGIDSShim
S? Avgldx86;AVG AVI Loader Driver
S? Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield
S? Avgrkx86;AVG Anti-Rootkit Driver
S? Avgtdix;AVG TDI Driver
S? avgwd;AVG WatchDog
S? DAdderFltr;DeathAdder Mouse
S? Envy24HFS;ICE Envy24 Family Audio Controller WDM
S? Lbd;Lbd
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? vsdatant;vsdatant
.
=============== Created Last 30 ================
.
2011-04-19 03:40:16 175616 ----a-w- c:\windows\system32\unrar.dll
2011-04-19 03:40:14 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-04-18 04:55:09 0 ----a-w- c:\windows\Ssexohoqusi.bin
2011-04-18 04:55:08 -------- d-----w- c:\docume~1\vamosr~1\locals~1\applic~1\{91EC9C83-8975-4713-BE75-2B9CF5E8E2F2}
2011-04-18 04:53:48 -------- d-----w- c:\docume~1\vamosr~1\applic~1\3027DCEB6FF29DEB4472D78FD4EFABF5
2011-03-24 05:58:23 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-03-24 05:58:23 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-03-24 05:58:23 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-03-24 05:58:23 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-03-24 05:58:23 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-03-24 05:58:23 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-03-24 05:58:23 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-03-24 05:58:23 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-03-23 15:57:31 -------- d-----w- C:\P?ogram Files
.
==================== Find3M ====================
.
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-17 13:51:57 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 13:51:57 667136 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 13:51:57 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-02-17 12:37:38 369664 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2008-04-08 17:46:28 680 ----a-w- c:\program files\mpc2.reg
2008-04-08 17:46:28 596 ----a-w- c:\program files\mpc1.reg
2008-04-08 17:46:28 4608 ----a-w- c:\program files\mpc4.reg
2008-04-08 17:46:28 3476 ----a-w- c:\program files\mpc7.reg
2008-04-08 17:46:28 3026 ----a-w- c:\program files\mpc3.reg
2008-04-08 17:46:28 27260 ----a-w- c:\program files\ffdssetts.reg
2008-04-08 17:46:28 24316 ----a-w- c:\program files\ffdsvsetts.reg
2008-04-08 17:46:28 18156 ----a-w- c:\program files\mpc6.reg
2008-04-08 17:46:28 16486 ----a-w- c:\program files\mpc5.reg
2008-04-08 17:46:28 1292 ----a-w- c:\program files\ffdsasetts.reg
2008-02-14 22:23:12 231944 ----a-w- c:\program files\gwflash.exe
2007-09-22 03:42:42 19008 ----a-w- c:\program files\markfun.a64
2007-08-22 03:49:28 17912 ----a-w- c:\program files\markfun.w32
2007-03-02 12:48:50 240448 ----a-w- c:\program files\gwf32.exe
2006-11-24 07:47:50 207680 ----a-w- c:\program files\BIOS_Run.exe
2005-04-28 03:40:26 6800 ----a-w- c:\program files\W95_HUA.vxd
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3320620AS rev.3.AAE -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-12
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89B0A4F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x89b107d0]; MOV EAX, [0x89b1084c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX,

[ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E13B9] -> \Device\Harddisk0\DR0[0x89B96030]
3 CLASSPNP[0xF7647FD7] -> nt!IofCallDriver[0x804E13B9] -> \Device\00000081[0x89BB89E8]
5 ACPI[0xF750E620] -> nt!IofCallDriver[0x804E13B9] -> [0x89B8B940]
\Driver\atapi[0x89B1EB10] -> IRP_MJ_CREATE -> 0x89B0A4F0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5;

REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x89B0A33B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 1:16:05.67 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 warehouse8

warehouse8
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:05:50 PM

Posted 19 April 2011 - 06:54 PM

Sorry for the inconvenience and for clogging up the forum, but I would like to request a close to this topic as I have received help from someone.

Still appreciate the help.

#3 SweetTech

SweetTech

    Agent ST


  • Members
  • 13,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Antarctica
  • Local time:05:50 PM

Posted 20 April 2011 - 02:49 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image


The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users