Welcome! Register for a free account (or login) > How does it work?
|
|


Jul 3 2009, 03:09 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 58 Joined: 20-March 07 Member No.: 68,926 Operating System: Windows XP |
Hi there I've got two computer problems. One is my laptop.... it has been getting weird page redirects from Google whenever I searched for a page and clicked on what I want but it redirects to some other page (for example I clicked on a Spybot help forum but I got redirected to Spybot's own page for no reason). My second problem is my desktop computer where I got some popups from IE (even though I use Firefox and never touched IE) where it auto installs something that triggers opening IE and going into some online game page. Then when I tried updating Spybot, it says and error retrieving info date (or something like that) and when I tried going to Spybot's page, the page returned null (most likely blocked). It even cut off my internet access to other security sites. I think it has to do something with my Flash drive when I used it on previous occasions. I could not open Spybot on my desktop either... could it be blocked too? Could not find Hijack This on my desktop and can't transfer a new version to install from my laptop to my desktop either. Your help is greatly appreciated ( A BIG HEADACHE!!!!!)
Here is the log from my laptop. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:00:35 AM, on 03/07/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18248) Boot mode: Normal Running processes: C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\rundll32.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\System32\regsvr32.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\MagicDisc\MagicDisc.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Windows\system32\conime.exe C:\Windows\Explorer.exe C:\Windows\system32\taskeng.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sgicanada.org/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NexusServer] "C:\Program Files\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe" -SelfLaunch O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [AcPePropertyEditorEnum] regsvr32 /s /u "C:\Users\Gent\AppData\Local\AcPePropertyEditorEnum\AcPePropertyEditorEnum.dll" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 9332 bytes Thank you. |
|
|
|
![]() |
Jul 6 2009, 07:30 PM
Post
#2
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,680 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
does this redirection also happen when you use I.E. or is it just happening in firefox? If it is happening in both IE as well as FF then please run this program: If it only happens in FF then report back and don't run the program we will need to reset your hosts file Please download HostsXpert
|
|
|
|
masterarchitect [Closed] Possible malware (Google redirects when clicked on a pag Jul 3 2009, 03:09 AM
masterarchitect Can anybody please help me on this? Thank you. Jul 5 2009, 05:00 PM
CatByte Hi and Welcome,
NOTE:Malware removal is NOT insta... Jul 5 2009, 07:05 PM
masterarchitect I am posting and attaching the results from the St... Jul 6 2009, 02:42 AM
CatByte Hi,
You can try zipping the GMER.txt and attachin... Jul 6 2009, 05:58 AM
masterarchitect Hi there, thanks for the reply. Attached is the sc... Jul 6 2009, 11:02 AM
masterarchitect Here's the scan from GooredFix:
GooredFix by ... Jul 6 2009, 11:04 AM
CatByte No, that's OK
the GMER scan didn't attach... Jul 6 2009, 11:19 AM
masterarchitect here is the GMER scan
GMER 1.0.15.14972 - http:/... Jul 6 2009, 11:44 AM
CatByte Ok,
sorry, I'm not really making myself clear... Jul 6 2009, 11:50 AM
masterarchitect The underlying issues with my laptop are still bei... Jul 6 2009, 11:50 AM
CatByte Hi,
Please do the following:
Please open your Ma... Jul 6 2009, 11:53 AM
masterarchitect MBAM log:
Malwarebytes' Anti-Malware 1.38
Dat... Jul 6 2009, 12:44 PM
masterarchitect I also have previous logs....:
Malwarebytes' ... Jul 6 2009, 12:46 PM
CatByte OK, thank-you
Please continue with the kaspersky ... Jul 6 2009, 12:54 PM
masterarchitect Here is the Kaspersky scan. Jul 6 2009, 06:06 PM
CatByte Well, the laptop is clean,
lets clean up the lapt... Jul 6 2009, 06:33 PM
masterarchitect Actually for some reason I still do have that prob... Jul 6 2009, 07:03 PM
masterarchitect It happens in both IE and Firefox. After using Hos... Jul 6 2009, 11:21 PM
CatByte that will reset your hosts file and should stop th... Jul 6 2009, 11:23 PM
masterarchitect Everything seems to be working normally now (at th... Jul 7 2009, 12:37 AM
CatByte OK good,
Use that one as normal and advise after ... Jul 7 2009, 04:44 AM
masterarchitect For some reason my desktop is not able to connect ... Jul 9 2009, 01:29 AM
CatByte Can you log onto the desktop in safemode with netw... Jul 9 2009, 01:39 AM
masterarchitect QUOTE (CatByte @ Jul 9 2009, 12:39 AM) Ca... Jul 13 2009, 02:10 AM
masterarchitect QUOTE (masterarchitect @ Jul 13 2009, 01... Jul 13 2009, 12:51 PM
masterarchitect What is the keyboard shortcut for logging in to Sa... Jul 10 2009, 04:16 PM
masterarchitect I tried finding HJT on my computer but it doesn... Jul 10 2009, 04:17 PM
masterarchitect And BTW, I still am getting redirects on my laptop... Jul 10 2009, 04:24 PM
CatByte To Enter Safemode
Go to Start> Shut off your C... Jul 10 2009, 04:55 PM
CatByte Hi,
Run this program on the laptop:
Download and... Jul 10 2009, 04:58 PM
CatByte Hi,
HJT was probably installed in your root direc... Jul 13 2009, 06:45 AM
CatByte what is the status of the computer now...are you a... Jul 13 2009, 01:14 PM
masterarchitect QUOTE (CatByte @ Jul 13 2009, 12:14 PM) w... Jul 13 2009, 02:20 PM
masterarchitect QUOTE (CatByte @ Jul 13 2009, 12:14 PM) w... Jul 13 2009, 02:21 PM
CatByte QUOTE Do I still have to do the next steps as you ... Jul 13 2009, 03:38 PM
masterarchitect QUOTE (CatByte @ Jul 13 2009, 02:38 PM) Q... Jul 14 2009, 04:13 PM
CatByte Try searcing for HJt in windows explorer (windows ... Jul 14 2009, 04:30 PM
masterarchitect QUOTE (CatByte @ Jul 14 2009, 03:30 PM) T... Jul 14 2009, 11:50 PM
masterarchitect OK... I managed to open a DDS scan on my desktop (... Jul 15 2009, 02:01 AM
masterarchitect However, I have some difficulty opening HJT (the T... Jul 15 2009, 02:09 AM
CatByte Hi,
Please do the following:
Open Notepad
Click... Jul 15 2009, 05:20 AM
masterarchitect QUOTE (CatByte @ Jul 15 2009, 04:20 AM) H... Jul 16 2009, 10:39 AM
masterarchitect QUOTE (CatByte @ Jul 15 2009, 04:20 AM) H... Jul 16 2009, 12:09 PM
masterarchitect Hi,
Here is the log from Super AntiSpyware for th... Jul 16 2009, 09:51 AM
masterarchitect I am now working on your instructions regarding Co... Jul 16 2009, 09:52 AM
CatByte RE: [Closed] Possible malware (Google redirects when clicked on a pag Jul 16 2009, 09:56 AM
masterarchitect Still not shutting down........... Jul 16 2009, 10:52 AM
CatByte Hi, give it a hard reboot (hold down the power but... Jul 16 2009, 11:22 AM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 10:22 AM) H... Jul 16 2009, 11:37 AM
CatByte If you are using Firefox, make sure that your down... Jul 16 2009, 12:37 PM
masterarchitect I have a problem connecting to the internet in nor... Jul 16 2009, 01:11 PM
CatByte Hi,
Try this
Start, Programs\Accessories an... Jul 16 2009, 01:24 PM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 12:24 PM) H... Jul 16 2009, 01:50 PM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 12:24 PM) H... Jul 16 2009, 01:56 PM
CatByte you could try uninstalling then reinstalling AVG o... Jul 16 2009, 01:53 PM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 12:53 PM) y... Jul 16 2009, 02:02 PM
CatByte Ok...reboot, try running ComboFix in safe mode
(... Jul 16 2009, 01:58 PM
masterarchitect Sorry for the quotes. Just trying to be cooperativ... Jul 16 2009, 02:04 PM
CatByte No problem, try running ComboFix in safe mode..as ... Jul 16 2009, 02:56 PM
masterarchitect I'm getting a message stating that "This ... Jul 16 2009, 03:05 PM
CatByte We will have to manage with out it right now, the ... Jul 16 2009, 03:22 PM
masterarchitect I have run ComboFix and it has detected rootkit ac... Jul 16 2009, 04:35 PM
CatByte ComboFix will reboot the machine, when it boots ba... Jul 16 2009, 06:48 PM
masterarchitect I got this when I started up in normal mode:
Prep... Jul 16 2009, 11:33 PM
masterarchitect Here is the ComboFix log:
ComboFix 09-07-14.08 - ... Jul 17 2009, 12:12 AM
CatByte Hi,
QUOTE Is this the way it should behave?
yes,... Jul 17 2009, 05:44 AM
masterarchitect I was able to see the link and power lights again ... Jul 17 2009, 03:42 PM
CatByte yes please
please also run the MalwareBytes prog... Jul 17 2009, 03:42 PM
masterarchitect Question.... do I drag the CFScript into "Com... Jul 17 2009, 04:27 PM
CatByte Hi,
whichever is the newest ComboFix - the older ... Jul 17 2009, 04:58 PM
masterarchitect Oh no, I just had a confusion with the animation w... Jul 17 2009, 05:29 PM
masterarchitect I still don't have internet access yet. So I a... Jul 17 2009, 05:33 PM
masterarchitect Here is the malwarebytes log (without updates):
C... Jul 17 2009, 05:43 PM
CatByte Hi,
that's the same ComboFix log Jul 17 2009, 05:47 PM
masterarchitect But I ran the ComboFix as you told me to...? It... Jul 17 2009, 05:55 PM
masterarchitect Or I didn't copy and paste the code right? Jul 17 2009, 05:56 PM
CatByte No, you did that correctly.
There was another req... Jul 17 2009, 05:58 PM
masterarchitect I actually downloaded Malwarebytes from my laptop ... Jul 17 2009, 06:04 PM
masterarchitect I guess I'll post the Malwarebytes log again.
... Jul 17 2009, 06:04 PM
CatByte Thank-you for posting the Malwarebytes log.
what ... Jul 17 2009, 06:21 PM
masterarchitect I still do not have access to the internet after t... Jul 17 2009, 06:39 PM
masterarchitect second scan reveals no new threats. Should I conti... Jul 17 2009, 06:43 PM
CatByte yes please...hopefully one of the steps will resol... Jul 17 2009, 06:43 PM
masterarchitect Sorry I have been dormant in this forum for the pa... Jul 22 2009, 09:59 PM
CatByte RE: [Closed] Possible malware (Google redirects when clicked on a pag Jul 22 2009, 10:32 PM
masterarchitect Hi there, sorry for the really late attempt. I jus... Jul 29 2009, 02:08 AM
CatByte Try this
Press Start > Run type CMD in the ... Jul 29 2009, 04:22 AM
masterarchitect Hi there, I am finally back.... and for some reaso... Aug 5 2009, 11:45 PM
CatByte Hi,
It is certainly sounding more like a hardware... Aug 6 2009, 05:02 AM
masterarchitect Ok....
On a side note, I'm noticing the redi... Aug 6 2009, 12:01 PM
CatByte If all these computers are on the same network or ... Aug 6 2009, 12:30 PM
CatByte Due to inactivity this topic will be closed.
If yo... Aug 18 2009, 02:56 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
268 | AplusWebMaster | 19,661 | Today, 06:33 PM Last post by: AplusWebMaster |
|||
![]() |
4 | ladykrimson | 75 | Today, 06:16 PM Last post by: ladykrimson |
|||
![]() |
0 | chaoticflash | 6 | Today, 05:08 PM Last post by: chaoticflash |
|||
![]() |
5 | tomryan222 | 60 | Today, 04:52 PM Last post by: oldman960 |
|||
|
Time is now: 21st March 2010 - 07:53 PM |