I seem to have picked up a virus or spyware or something. The primary problem is when I'm using Firefox and I get additional tabs being opened and popups. The tabs are typically "mens health base", "womens health base", and I've also seen some tabs about allergy and Google hiring. The popups say I've won/qualified for a Walmart gift card.
Secondary issue is that sometimes on startup svchost.exe takes a lot of CPU %. When this happens I kill the process and things seem to work fine.
dds info below. Other info in attached zip file. I do not have access to a windows install or boot CD.
Any help greatly appreciated! Thanks in advance.
-Steve
DDS (Ver_2011-05-26.01) - NTFS_x86
Internet Explorer: 7.0.5730.13
Run by Administrator at 19:52:17 on 2011-05-26
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.349 [GMT -7:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
============== Running Processes ===============
.
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\tp4mon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\PROGRA~1\NavNT\rtvscan.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\rundll32.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_7
uRun: [Malware Protection] c:\documents and settings\all users\application data\defender.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [TrackPointSrv] tp4mon.exe
mRun: [QCTRAY] c:\program files\thinkpad\connectutilities\QCTRAY .exe
mRun: [QCWLICON] c:\program files\thinkpad\connectutilities\QCWLICON .exe
mRun: [TP4EX] tp4ex.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Tgcmd] "c:\program files\support.com\bin\tgcmd.exe /server"
mRun: [UC_SMB]
mRun: [vptray] c:\progra~1\navnt\vptray.exe
mRun: [IntelliType] "c:\program files\microsoft hardware\keyboard\type32.exe"
mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
mRun: [Pure Networks Port Magic] "c:\progra~1\purene~1\portma~1\PortAOL.exe" -Run
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [HostManager] c:\program files\common files\aol\1127543071\ee\AOLSoftware.exe
mRun: [ISLP2STA.EXE] ISLP2STA.EXE START
mRun: [Audit Wizard] \\madriver\awizard\ScanWS_SD.bat
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0_06\bin\jusched.exe
mRun: [IPHSend] c:\program files\common files\aol\iphsend\IPHSend.exe
mRun: [AIRPLUS] "c:\program files\d-link\AIRPLUS.exe" -nogui
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [MSMSGS] "c:\program files\messenger\MSMSGS.EXE" /background
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snagit~1.lnk - c:\program files\techsmith\snagit 6\SnagIt32.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: YExplorer1_8US.CAB - hxxp://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc.cab
DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} - hxxp://office.microsoft.com/productupdates/content/opuc.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1218830946680
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38099.5881944444
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_01-win.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://aol124.pogo.com/game/deluxe/zuma/popcaploader_v5.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://claritas.webex.com/client/v_mywebex/webex/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\controls\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\controls\SAPHTMLP.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: ckpNotify - ckpNotify.dll
Notify: igfxcui - igfxsrvc.dll
Notify: itlntfy - itlnfw32.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
mASetup: {8A3D586A-C7FE-456E-A9E2-F96EEAF0C7B6} - rundll32.exe "c:\documents and settings\administrator\application data\sun\kfb0.dll", UnregisterDll
Hosts: 127.0.0.1
www.spywareinfo.com
Hosts: 10.10.103.44 ezsys # EASY ARCHIVE SYSTEM
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\pzvzcuuj.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.internet-search-results.com/?sid=10101138100&s=
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
.
---- FIREFOX POLICIES ----
user_pref(security.warn_viewing_mixed,false);
user_pref(security.warn_viewing_mixed.show_once,false);
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
user_pref(security.warn_submit_insecure,false);
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-5-7 64512]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2002-11-20 12288]
R2 NAVAPEL;NAVAPEL;c:\program files\navnt\Navapel.sys [2003-8-11 30208]
R2 Norton AntiVirus Server;Symantec AntiVirus Client;c:\progra~1\navnt\rtvscan.exe [2003-10-7 647168]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [2005-10-26 17456]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-1-7 24652]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [2005-10-26 670128]
R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\windows\system32\drivers\Vch.sys [2002-11-20 20023]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [2005-10-26 2041904]
R3 NAVAP;NAVAP;c:\progra~1\navnt\NAVAP.sys [2003-8-11 224768]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20060413.007\NAVENG.sys [2006-4-14 77864]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20060413.007\NAVEX15.sys [2006-4-14 799208]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2006-4-14 14336]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-4-29 2151128]
S3 ISLP2;Intersil 802.11 Wireless LAN Driver;c:\windows\system32\drivers\islp2nds.sys [2002-10-3 611840]
S3 jswimd;jswimd Service;c:\windows\system32\drivers\jswimd.sys [2008-8-14 19104]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-4-29 15232]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-5-22 38224]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-5-7 50704]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [2005-10-26 14924]
S3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [1980-1-1 14096]
S3 WPC11;Instant Wireless Network PC Card V3.0 Driver;c:\windows\system32\drivers\LSWLNDS.sys [2002-3-27 51072]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-05-25 05:35:09 -------- d-----w- c:\program files\iPod
2011-05-25 05:33:32 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-05-25 05:33:32 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-05-25 05:32:51 -------- d-----w- c:\program files\Bonjour
2011-05-25 05:18:40 42496 ----a-w- c:\windows\system32\tp4res.dll
2011-05-25 05:18:40 42496 ----a-w- c:\windows\system32\dllcache\tp4res.dll
2011-05-25 05:18:40 31744 ----a-w- c:\windows\system32\tp4.dll
2011-05-25 05:18:40 31744 ----a-w- c:\windows\system32\dllcache\tp4.dll
2011-05-25 05:18:40 11520 ----a-w- c:\windows\system32\drivers\TwoTrack.sys
2011-05-25 05:18:40 11520 ----a-w- c:\windows\system32\dllcache\twotrack.sys
2011-05-25 05:18:37 82432 ----a-w- c:\windows\system32\tp4mon.exe
2011-05-25 05:18:37 82432 ----a-w- c:\windows\system32\dllcache\tp4mon.exe
2011-05-25 04:43:29 -------- d-----w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-24 15:26:39 -------- d-----w- c:\documents and settings\all users\application data\Security Essentials Ultimate Pack
2011-05-23 00:40:56 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes
2011-05-23 00:40:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-23 00:40:28 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-05-23 00:40:21 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-23 00:40:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-22 00:52:13 -------- d-----w- c:\documents and settings\all users\application data\WSTB
2011-05-13 03:35:27 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-05-13 03:35:22 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-05-13 03:35:22 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-05-13 03:35:21 89048 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-05-13 03:35:21 465880 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-05-13 03:35:21 1974616 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-05-13 03:35:21 1892184 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-05-13 03:35:21 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-05-11 08:07:54 -------- d--h--w- C:\$AVG
2011-05-11 04:05:59 -------- d-----w- c:\documents and settings\administrator\application data\AVG10
2011-05-11 04:03:27 -------- d--h--w- c:\documents and settings\all users\application data\Common Files
2011-05-11 03:48:43 -------- d-----w- c:\documents and settings\all users\application data\AVG10
2011-05-11 03:45:47 -------- d-----w- c:\program files\AVG
2011-05-10 19:11:39 -------- d-----w- c:\documents and settings\all users\application data\MFAData
2011-05-10 14:45:01 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-05-08 03:19:58 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-05-08 03:09:12 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2011-05-08 03:09:12 281104 ----a-w- c:\windows\system32\wpcap.dll
2011-05-08 03:09:12 100880 ----a-w- c:\windows\system32\Packet.dll
2011-05-08 01:21:18 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-05-08 01:16:58 -------- d-----w- c:\program files\Lavasoft
2011-05-07 17:34:32 -------- d-----w- c:\program files\ESET
.
==================== Find3M ====================
.
2011-04-06 23:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20:16 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 23:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
GMER - Rootkit Detector and Remover
Windows 5.1.2600 Disk: HTS548080M9AT00 rev.MG4OA53A -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82F3A4D0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x82f407f0]; MOV EAX, [0x82f4086c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37C5] -> \Device\Harddisk0\DR0[0x82FCE688]
3 CLASSPNP[0xF872305B] -> nt!IofCallDriver[0x804E37C5] -> \Device\00000088[0x82FCF650]
5 ACPI[0xF8679620] -> nt!IofCallDriver[0x804E37C5] -> [0x82FCF030]
\Driver\atapi[0x82F37500] -> IRP_MJ_CREATE -> 0x82F3A4D0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { CLI ; XOR AX, AX; MOV ES, AX; MOV DS, AX; MOV SS, AX; MOV SP, 0x7c00; MOV SI, SP; STI ; CLD ; MOV DI, 0x600; MOV CX, 0x100; REP MOVSW ; MOV AX, 0x6df; PUSH AX; RET ; ADD [BX], CL; ADD [BX+DI], AL; OR AL, [DI+0x72]; JB 0x95; JB 0x48; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x82F3A31B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 19:55:17.37 ===============