Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Possible TDL4 infection with Firefox redirection and outgoing malicious site activity

  • This topic is locked This topic is locked
2 replies to this topic

#1 tprice


  • Members
  • 2 posts
  • Local time:06:19 AM

Posted 02 May 2011 - 11:00 AM

Well, gmer says it's a possible TDL4 infection, and I'm not qualified to say for sure.

I believe I got a Trojan last week when a site told me I had to download a plugin to view website content. Shortly thereafter I had my computer show up with an installation of AntimalwareDoctor and my Firefox browser start redirecting me. Sometimes from Google, sometimes just with a popup to Budgetmatch.net. I subsequently installed MalwareBytes AntiMalware, and it pops up a window every 10 minutes or so that it is blocking outgoing access to a malicious site.

I don't know if it's helpful, but a sampling of the site addresses is given below.

Scanning with MBAM identified 8 infections (Spyware.OnLineGames, Adware.Searchbar, Rogue.AntiVirusAntiSpyware2011, Trojan.FakeAlert x 3, and Trojan.Hiloti) that were deleted.

ESET online found 4 more (Kryptik.NCK x 2, Wimpixo.AA, and Adware.AntimalwareDoctor.AE.Gen).

The computer has settled down a lot since, but I'm still getting redirected and rogue outgoing net access.

I downloaded and ran ComboKit (I hadn't seen the raft of online warnings about doing this at the time; I don't plan to do it again unless specifically recommended), but that didn't fix it.

I've tried to run TDSSKiller, but it won't run, even after renaming it, and it won't run in Safe Mode with or without network support. In all cases, it gets to 80% initialization, then I get the Windows error that TDSSKiller has an error and needs to close.

Thanks in advance. If you can, please give me another alternative to reformatting the system drive.

MBAM activity log:

10:53:49 (null) IP-BLOCK (Type: outgoing)
10:54:01 Tom IP-BLOCK (Type: outgoing)
10:54:04 Tom IP-BLOCK (Type: outgoing)
10:54:10 Tom IP-BLOCK (Type: outgoing)
10:54:22 Tom IP-BLOCK (Type: outgoing)
10:54:25 Tom IP-BLOCK (Type: outgoing)
10:54:31 Tom IP-BLOCK (Type: outgoing)
10:56:22 Tom IP-BLOCK (Type: outgoing)
10:56:25 Tom IP-BLOCK (Type: outgoing)
10:56:31 Tom IP-BLOCK (Type: outgoing)
10:59:43 Tom IP-BLOCK (Type: outgoing)
10:59:45 Tom IP-BLOCK (Type: outgoing)
10:59:51 Tom IP-BLOCK (Type: outgoing)
10:59:59 Tom IP-BLOCK (Type: outgoing)
11:00:02 Tom IP-BLOCK (Type: outgoing)
11:00:08 Tom IP-BLOCK (Type: outgoing)
11:00:20 Tom IP-BLOCK (Type: outgoing)
11:00:23 Tom IP-BLOCK (Type: outgoing)
11:00:29 Tom IP-BLOCK (Type: outgoing)
11:03:03 Tom IP-BLOCK (Type: outgoing)
11:03:06 Tom IP-BLOCK (Type: outgoing)
11:03:12 Tom IP-BLOCK (Type: outgoing)
11:04:44 Tom IP-BLOCK (Type: outgoing)
11:04:46 Tom IP-BLOCK (Type: outgoing)
11:04:53 Tom IP-BLOCK (Type: outgoing)
11:06:24 Tom IP-BLOCK (Type: outgoing)
11:06:27 Tom IP-BLOCK (Type: outgoing)
11:06:33 Tom IP-BLOCK (Type: outgoing)


DDS (Ver_11-03-05.01) - NTFSx86
Run by Tom at 11:03:04.68 on Mon 05/02/2011
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.1079 [GMT -4:00]
AV: eTrust EZ Antivirus *Enabled/Updated* {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
============== Running Processes ===============
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\11\ISUSPM.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [ISUSPM] "c:\documents and settings\all users\application data\macrovision\flexnet connect\11\ISUSPM.exe" -scheduler
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Desktop Disc Tool] "c:\program files\roxio\roxio burn\RoxioBurnLauncher.exe"
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [CaISSDT] "c:\program files\ca\etrust internet security suite\caissdt.exe"
mRun: [CaAvTray] "c:\progra~1\ca\etrust~1\etrust~1\CAVTray.exe"
mRun: [CAVRID] "c:\progra~1\ca\etrust~1\etrust~1\CAVRID.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [SNM] c:\program files\spynomore\SNM.exe /startup
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: intuit.com\ttlc
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1304055364764
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\tom\applic~1\mozilla\firefox\profiles\044gep7z.default\
FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/mail/?shva=1#inbox
FF - component: c:\documents and settings\tom\application data\mozilla\firefox\profiles\044gep7z.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\platform\winnt_x86-msvc\components\SSSLauncher.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\tom\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\canon\zoombrowser ex\program\NPCIG.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\\npGoogleUpdate3.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\tom\application data\Move Networks
FF - Ext: BlockSite: {dd3d7613-0246-469d-bc65-2a3cc1668adc} - %profile%\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
FF - Ext: FireShot: {0b457cAA-602d-484a-8fe7-c1d894a011ba} - %profile%\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
============= SERVICES / DRIVERS ===============
R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [2009-11-5 184848]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\Vet-Filt.sys [2009-11-15 21043]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\Vet-Rec.sys [2009-11-15 15490]
R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\VetEFile.sys [2011-4-29 879832]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\VetFDDNT.sys [2009-11-15 15747]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2011-4-29 26787]
R2 CAISafe;CAISafe;c:\progra~1\ca\etrust~1\etrust~1\ISafe.exe [2009-11-15 140840]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-12-18 155648]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-5-1 363344]
R2 VETMSGNT;VET Message Service;c:\progra~1\ca\etrust~1\etrust~1\VetMsg.exe [2009-11-15 202280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-5-1 20952]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\VetEBoot.sys [2011-4-29 108360]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-11-5 992256]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-29 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-5-29 136176]
=============== Created Last 30 ================
2011-05-02 14:48:20 -------- d-----w- c:\docume~1\tom\applic~1\Malwarebytes
2011-05-02 03:14:49 1152 ----a-w- c:\windows\system32\windrv.sys
2011-05-01 18:16:25 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-01 18:16:25 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-05-01 18:16:22 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-01 18:16:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-01 17:03:06 -------- d-sha-r- C:\cmdcons
2011-05-01 16:59:09 98816 ----a-w- c:\windows\sed.exe
2011-05-01 16:59:09 89088 ----a-w- c:\windows\MBR.exe
2011-05-01 16:59:09 256512 ----a-w- c:\windows\PEV.exe
2011-05-01 16:59:09 161792 ----a-w- c:\windows\SWREG.exe
2011-05-01 16:35:05 -------- d-----w- c:\program files\CCleaner
2011-04-29 17:47:22 -------- d-----w- c:\windows\CAVTemp
2011-04-29 16:26:06 -------- d-----w- c:\docume~1\alluse~1\applic~1\CA
2011-04-29 16:26:05 26787 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2011-04-29 16:23:32 879832 ----a-w- c:\windows\system32\drivers\VetEFile.sys
2011-04-29 16:23:32 108360 ----a-w- c:\windows\system32\drivers\VetEBoot.sys
2011-04-29 16:23:27 75304 ----a-w- c:\windows\system32\iSafProd.dll
2011-04-29 16:23:27 244264 ----a-w- c:\windows\unicows.dll
2011-04-29 06:12:34 0 ----a-w- c:\windows\Ndoqey.bin
2011-04-29 06:03:26 -------- d-----w- c:\docume~1\alluse~1\applic~1\STOPzilla!
==================== Find3M ====================
2011-04-29 16:23:32 99880 ----a-w- c:\windows\UnVet32.exe
2011-04-29 16:23:32 75304 ----a-w- c:\windows\system32\VetRedir.dll
2011-04-29 16:23:32 112168 ----a-w- c:\windows\AVShlExt.dll
============= FINISH: 11:05:04.59 ===============

DDS Attach.txt :

Attached as .zip


Attached as .zip

Attached Files

BC AdBot (Login to Remove)


#2 tprice

  • Topic Starter

  • Members
  • 2 posts
  • Local time:06:19 AM

Posted 05 May 2011 - 09:57 AM

I updated TDSSKiller last night, and it looks as if it solved it. No redirection or malicious activity for 12 hours.

#3 Budapest


    Bleepin' Cynic

  • Moderator
  • 23,579 posts
  • Gender:Male
  • Local time:09:19 PM

Posted 05 May 2011 - 04:47 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users