robpp
Topic Starter
Sometimes I click links from a Google search and they redirect me to other sites.
a few times today i ended up on 'monstermarketplace.com
I went to safe mode and did a norton full scan. it found stuff.
i then reboot and safe mode; scan again shows clean.
redirects still happening, maybe not as ofteen. almost always the first time I use google after opening a browser.
I attached the norton export of the scan that found stuff.
it shows a lot of the finding were in a java folder.
TIA,
ROB
_______________________________________
DDS SCAN___________
_______________________
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:16:05.57 on Mon 06/14/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3016.2003 [GMT -6:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: ISS Proventia 9.0.226.0 *enabled* {1B42F604-2FE3-485B-BA3D-B55276659D1F}
============== Running Processes ===============
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Accenture Connection\9341989\Program\ServiceWrapper-9341989.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe
C:\Program Files\ManageSoft\Launcher\ndserv.exe
C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\ManageSoft\Schedule Agent\ndtask.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\Prot_srv.exe
C:\WINDOWS\system32\pstartSr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ManageSoft\Schedule Agent\ndtask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\Accenture\AMDD\AMDD.exe
C:\Program Files\Microsoft Office Communicator\communicator.exe
C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\ISS\Proventia Desktop\blackice.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Symantec AntiVirus\VPC32.exe
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
D:\Documents and Settings\robert.p.powell\Desktop\dds.scr
============== Pseudo HJT Report ===============
uWindow Title = Windows Internet Explorer provided by Accenture
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = localhost;
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ManageSoft Web Application Tracker: {30a22ec9-42d0-4d46-a2f7-7516419f943d} - c:\progra~1\manage~1\usagea~1\mgsiebho.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MPlayer] c:\windows\system32\MPlayer.vbs
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\BackWeb-8876480.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [picon] "c:\program files\common files\intel\privacy icon\PrivacyIconClient.exe" -startup
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [AMDD] c:\program files\accenture\amdd\AMDD.exe
mRun: [Communicator] "c:\program files\microsoft office communicator\communicator.exe" /fromrunkey
mRun: [ACSTP] e:\local\other\locpost62\icollect\acstp_install.exe
mRun: [Accenture Connection] "c:\program files\accenture connection\9341989\program\Accenture Connection.exe" -startup
mRun: [Pointsec Tray] c:\program files\pointsec\pointsec for pc\P95Tray.exe
mRun: [SchedulingAgent_nDG] "c:\program files\managesoft\schedule agent\ndschedag.exe" -o RunNDStartup=True -o Startup=True
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [Total PC Defender] c:\program files\total pc defender\Total PC Defender.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: d:\docume~1\robert~1.pow\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\accent~1.lnk - c:\program files\accenture connection\9341989\program\Accenture Connection.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\thinkpad\bluetooth software\BTTray.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\proven~1.lnk - c:\program files\iss\proventia desktop\blackice.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: LogonType = 0 (0x0)
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: accenture.com
Trusted Zone: accenture.com
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0D0950E6-046D-437A-8985-369BE10C7E2A} - hxxps://iauthor.accenture.com/iAuthor/ASP/IALogOut.CAB
DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} - hxxps://iauthor.accenture.com/iAuthor/ASP/Reporting/ScriptX.cab
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxps://sync.accenture.com/projectserver/objects/pjclient.cab
DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} - hxxps://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} - hxxps://secure.logmeinrescue-enterprise.com/Customer/x86/RescueDownloader.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269724662777
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} - hxxps://www2.gotomeeting.com/default/applets/g2mdlax.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxps://sync.accenture.com/projectserver/objects/1033/pjcintl.cab
DPF: {BF17C411-9ADA-4C73-B12C-BD814BDE187F} - hxxps://mylearning.accenture.com/accenture/core/common/ScheduleServices/ScheduleServices.cab
DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://amr1-extranet.accenture.com/dana-cached/setup/JuniperSetupSP1.cab
Handler: bwfile-9341989 - {358D3935-0C33-4169-9598-63FAF077328B} - c:\program files\accenture connection\9341989\program\GAPlugProtocol-9341989.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 prot_2k;prot_2k;c:\windows\system32\drivers\prot_2k.sys [2008-4-12 221632]
R1 abdc;abdc;c:\windows\system32\abdc.sys [2010-6-13 80896]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [2009-8-27 13480]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 BackWeb Plug-in - 9341989;Accenture Connection;c:\program files\accenture connection\9341989\program\ServiceWrapper-9341989.exe [2009-10-23 28711]
R2 BlackICE;BlackICE;c:\program files\iss\proventia desktop\blackd.exe [2009-10-21 2081034]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 mgssecsvc;ManageSoft Security Service;c:\program files\managesoft\security agent\mgssecsvc.exe [2009-8-8 1095168]
R2 ndGlobalLauncher;ManageSoft installation agent;c:\program files\managesoft\launcher\ndserv.exe [2009-8-8 2899264]
R2 ndinit;ManageSoft managed device;c:\program files\managesoft\schedule agent\ndinit.exe [2009-8-8 730944]
R2 Pointsec;Pointsec;c:\windows\system32\Prot_srv.exe [2008-4-12 367168]
R2 Pointsec_start;Pointsec Service Start;c:\windows\system32\pstartSr.exe [2008-4-12 145984]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-10-7 1822648]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\common files\intel\privacy icon\uns\UNS.exe [2009-10-21 2058776]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2009-8-27 239760]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-27 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100614.003\naveng.sys [2010-6-14 85552]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100614.003\navex15.sys [2010-6-14 1347504]
R4 black;black;c:\windows\system32\drivers\Blackcat.sys [2009-10-21 205938]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2009-11-6 114016]
S3 Cdmsvos;Cdmsvos; [x]
S3 IgniteService;IgniteService;c:\program files\ignitecds\IgniteService.exe [2009-10-20 86016]
S3 MakoNT;MakoNT;c:\windows\system32\drivers\isskboep.sys [2009-10-21 80512]
S3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [2009-10-21 50163]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-10-7 116664]
S3 VPatch;ISS Buffer Overflow Exploit Prevention;c:\program files\iss\proventia desktop\vpatch.exe [2009-10-21 405770]
S4 mgsdl;ManageSoft Peer-to-Peer Download Service;c:\program files\managesoft\launcher\mgsdl.exe [2009-8-8 1401344]
=============== Created Last 30 ================
2010-06-13 15:48 80,896 a——- c:\windows\system32\abdc.sys
2010-06-08 08:59 –d—– c:\program files\examotion
==================== Find3M ====================
2010-05-04 22:50 3,600,384 a——- c:\windows\system32\dllcache\mshtml.dll
2010-04-16 07:24 70,656 a——- c:\windows\system32\dllcache\ie4uinit.exe
2010-04-16 07:24 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2010-04-16 05:43 634,656 a——- c:\windows\system32\dllcache\iexplore.exe
2010-04-16 05:43 161,792 a——- c:\windows\system32\dllcache\ieakui.dll
2008-07-18 10:48 45,056 a——- c:\program files\common files\Period20.dll
2008-07-18 10:48 24,576 a——- c:\program files\common files\Artes32X.dll
2008-07-18 10:48 24,576 a——- c:\program files\common files\ACTripsLog.dll
2007-07-26 20:02 305,688 a——- c:\windows\inf\IaStor.sys
2006-09-12 16:21 319 a——- c:\program files\VersionMarker.dat
2009-10-24 17:07 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009102420091025\index.dat
============= FINISH: 20:16:38.03 ===============