Welcome! Register for a free account (or login) > How does it work?
|
|


Jul 3 2009, 03:09 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 58 Joined: 20-March 07 Member No.: 68,926 Operating System: Windows XP |
Hi there I've got two computer problems. One is my laptop.... it has been getting weird page redirects from Google whenever I searched for a page and clicked on what I want but it redirects to some other page (for example I clicked on a Spybot help forum but I got redirected to Spybot's own page for no reason). My second problem is my desktop computer where I got some popups from IE (even though I use Firefox and never touched IE) where it auto installs something that triggers opening IE and going into some online game page. Then when I tried updating Spybot, it says and error retrieving info date (or something like that) and when I tried going to Spybot's page, the page returned null (most likely blocked). It even cut off my internet access to other security sites. I think it has to do something with my Flash drive when I used it on previous occasions. I could not open Spybot on my desktop either... could it be blocked too? Could not find Hijack This on my desktop and can't transfer a new version to install from my laptop to my desktop either. Your help is greatly appreciated ( A BIG HEADACHE!!!!!)
Here is the log from my laptop. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:00:35 AM, on 03/07/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18248) Boot mode: Normal Running processes: C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\rundll32.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\System32\regsvr32.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\MagicDisc\MagicDisc.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Windows\system32\conime.exe C:\Windows\Explorer.exe C:\Windows\system32\taskeng.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sgicanada.org/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NexusServer] "C:\Program Files\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe" -SelfLaunch O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [AcPePropertyEditorEnum] regsvr32 /s /u "C:\Users\Gent\AppData\Local\AcPePropertyEditorEnum\AcPePropertyEditorEnum.dll" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 9332 bytes Thank you. |
|
|
|
![]() |
Jul 6 2009, 11:21 PM
Post
#2
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 58 Joined: 20-March 07 Member No.: 68,926 Operating System: Windows XP |
It happens in both IE and Firefox. After using HostsXpert what shall I do?
|
|
|
|
masterarchitect [Closed] Possible malware (Google redirects when clicked on a pag Jul 3 2009, 03:09 AM
masterarchitect Can anybody please help me on this? Thank you. Jul 5 2009, 05:00 PM
CatByte Hi and Welcome,
NOTE:Malware removal is NOT insta... Jul 5 2009, 07:05 PM
masterarchitect I am posting and attaching the results from the St... Jul 6 2009, 02:42 AM
CatByte Hi,
You can try zipping the GMER.txt and attachin... Jul 6 2009, 05:58 AM
masterarchitect Hi there, thanks for the reply. Attached is the sc... Jul 6 2009, 11:02 AM
masterarchitect Here's the scan from GooredFix:
GooredFix by ... Jul 6 2009, 11:04 AM
CatByte No, that's OK
the GMER scan didn't attach... Jul 6 2009, 11:19 AM
masterarchitect here is the GMER scan
GMER 1.0.15.14972 - http:/... Jul 6 2009, 11:44 AM
CatByte Ok,
sorry, I'm not really making myself clear... Jul 6 2009, 11:50 AM
masterarchitect The underlying issues with my laptop are still bei... Jul 6 2009, 11:50 AM
CatByte Hi,
Please do the following:
Please open your Ma... Jul 6 2009, 11:53 AM
masterarchitect MBAM log:
Malwarebytes' Anti-Malware 1.38
Dat... Jul 6 2009, 12:44 PM
masterarchitect I also have previous logs....:
Malwarebytes' ... Jul 6 2009, 12:46 PM
CatByte OK, thank-you
Please continue with the kaspersky ... Jul 6 2009, 12:54 PM
masterarchitect Here is the Kaspersky scan. Jul 6 2009, 06:06 PM
CatByte Well, the laptop is clean,
lets clean up the lapt... Jul 6 2009, 06:33 PM
masterarchitect Actually for some reason I still do have that prob... Jul 6 2009, 07:03 PM
CatByte Hi,
does this redirection also happen when you us... Jul 6 2009, 07:30 PM
CatByte that will reset your hosts file and should stop th... Jul 6 2009, 11:23 PM
masterarchitect Everything seems to be working normally now (at th... Jul 7 2009, 12:37 AM
CatByte OK good,
Use that one as normal and advise after ... Jul 7 2009, 04:44 AM
masterarchitect For some reason my desktop is not able to connect ... Jul 9 2009, 01:29 AM
CatByte Can you log onto the desktop in safemode with netw... Jul 9 2009, 01:39 AM
masterarchitect QUOTE (CatByte @ Jul 9 2009, 12:39 AM) Ca... Jul 13 2009, 02:10 AM
masterarchitect QUOTE (masterarchitect @ Jul 13 2009, 01... Jul 13 2009, 12:51 PM
masterarchitect What is the keyboard shortcut for logging in to Sa... Jul 10 2009, 04:16 PM
masterarchitect I tried finding HJT on my computer but it doesn... Jul 10 2009, 04:17 PM
masterarchitect And BTW, I still am getting redirects on my laptop... Jul 10 2009, 04:24 PM
CatByte To Enter Safemode
Go to Start> Shut off your C... Jul 10 2009, 04:55 PM
CatByte Hi,
Run this program on the laptop:
Download and... Jul 10 2009, 04:58 PM
CatByte Hi,
HJT was probably installed in your root direc... Jul 13 2009, 06:45 AM
CatByte what is the status of the computer now...are you a... Jul 13 2009, 01:14 PM
masterarchitect QUOTE (CatByte @ Jul 13 2009, 12:14 PM) w... Jul 13 2009, 02:20 PM
masterarchitect QUOTE (CatByte @ Jul 13 2009, 12:14 PM) w... Jul 13 2009, 02:21 PM
CatByte QUOTE Do I still have to do the next steps as you ... Jul 13 2009, 03:38 PM
masterarchitect QUOTE (CatByte @ Jul 13 2009, 02:38 PM) Q... Jul 14 2009, 04:13 PM
CatByte Try searcing for HJt in windows explorer (windows ... Jul 14 2009, 04:30 PM
masterarchitect QUOTE (CatByte @ Jul 14 2009, 03:30 PM) T... Jul 14 2009, 11:50 PM
masterarchitect OK... I managed to open a DDS scan on my desktop (... Jul 15 2009, 02:01 AM
masterarchitect However, I have some difficulty opening HJT (the T... Jul 15 2009, 02:09 AM
CatByte Hi,
Please do the following:
Open Notepad
Click... Jul 15 2009, 05:20 AM
masterarchitect QUOTE (CatByte @ Jul 15 2009, 04:20 AM) H... Jul 16 2009, 10:39 AM
masterarchitect QUOTE (CatByte @ Jul 15 2009, 04:20 AM) H... Jul 16 2009, 12:09 PM
masterarchitect Hi,
Here is the log from Super AntiSpyware for th... Jul 16 2009, 09:51 AM
masterarchitect I am now working on your instructions regarding Co... Jul 16 2009, 09:52 AM
CatByte RE: [Closed] Possible malware (Google redirects when clicked on a pag Jul 16 2009, 09:56 AM
masterarchitect Still not shutting down........... Jul 16 2009, 10:52 AM
CatByte Hi, give it a hard reboot (hold down the power but... Jul 16 2009, 11:22 AM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 10:22 AM) H... Jul 16 2009, 11:37 AM
CatByte If you are using Firefox, make sure that your down... Jul 16 2009, 12:37 PM
masterarchitect I have a problem connecting to the internet in nor... Jul 16 2009, 01:11 PM
CatByte Hi,
Try this
Start, Programs\Accessories an... Jul 16 2009, 01:24 PM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 12:24 PM) H... Jul 16 2009, 01:50 PM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 12:24 PM) H... Jul 16 2009, 01:56 PM
CatByte you could try uninstalling then reinstalling AVG o... Jul 16 2009, 01:53 PM
masterarchitect QUOTE (CatByte @ Jul 16 2009, 12:53 PM) y... Jul 16 2009, 02:02 PM
CatByte Ok...reboot, try running ComboFix in safe mode
(... Jul 16 2009, 01:58 PM
masterarchitect Sorry for the quotes. Just trying to be cooperativ... Jul 16 2009, 02:04 PM
CatByte No problem, try running ComboFix in safe mode..as ... Jul 16 2009, 02:56 PM
masterarchitect I'm getting a message stating that "This ... Jul 16 2009, 03:05 PM
CatByte We will have to manage with out it right now, the ... Jul 16 2009, 03:22 PM
masterarchitect I have run ComboFix and it has detected rootkit ac... Jul 16 2009, 04:35 PM
CatByte ComboFix will reboot the machine, when it boots ba... Jul 16 2009, 06:48 PM
masterarchitect I got this when I started up in normal mode:
Prep... Jul 16 2009, 11:33 PM
masterarchitect Here is the ComboFix log:
ComboFix 09-07-14.08 - ... Jul 17 2009, 12:12 AM
CatByte Hi,
QUOTE Is this the way it should behave?
yes,... Jul 17 2009, 05:44 AM
masterarchitect I was able to see the link and power lights again ... Jul 17 2009, 03:42 PM
CatByte yes please
please also run the MalwareBytes prog... Jul 17 2009, 03:42 PM
masterarchitect Question.... do I drag the CFScript into "Com... Jul 17 2009, 04:27 PM
CatByte Hi,
whichever is the newest ComboFix - the older ... Jul 17 2009, 04:58 PM
masterarchitect Oh no, I just had a confusion with the animation w... Jul 17 2009, 05:29 PM
masterarchitect I still don't have internet access yet. So I a... Jul 17 2009, 05:33 PM
masterarchitect Here is the malwarebytes log (without updates):
C... Jul 17 2009, 05:43 PM
CatByte Hi,
that's the same ComboFix log Jul 17 2009, 05:47 PM
masterarchitect But I ran the ComboFix as you told me to...? It... Jul 17 2009, 05:55 PM
masterarchitect Or I didn't copy and paste the code right? Jul 17 2009, 05:56 PM
CatByte No, you did that correctly.
There was another req... Jul 17 2009, 05:58 PM
masterarchitect I actually downloaded Malwarebytes from my laptop ... Jul 17 2009, 06:04 PM
masterarchitect I guess I'll post the Malwarebytes log again.
... Jul 17 2009, 06:04 PM
CatByte Thank-you for posting the Malwarebytes log.
what ... Jul 17 2009, 06:21 PM
masterarchitect I still do not have access to the internet after t... Jul 17 2009, 06:39 PM
masterarchitect second scan reveals no new threats. Should I conti... Jul 17 2009, 06:43 PM
CatByte yes please...hopefully one of the steps will resol... Jul 17 2009, 06:43 PM
masterarchitect Sorry I have been dormant in this forum for the pa... Jul 22 2009, 09:59 PM
CatByte RE: [Closed] Possible malware (Google redirects when clicked on a pag Jul 22 2009, 10:32 PM
masterarchitect Hi there, sorry for the really late attempt. I jus... Jul 29 2009, 02:08 AM
CatByte Try this
Press Start > Run type CMD in the ... Jul 29 2009, 04:22 AM
masterarchitect Hi there, I am finally back.... and for some reaso... Aug 5 2009, 11:45 PM
CatByte Hi,
It is certainly sounding more like a hardware... Aug 6 2009, 05:02 AM
masterarchitect Ok....
On a side note, I'm noticing the redi... Aug 6 2009, 12:01 PM
CatByte If all these computers are on the same network or ... Aug 6 2009, 12:30 PM
CatByte Due to inactivity this topic will be closed.
If yo... Aug 18 2009, 02:56 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
12 | km1234 | 150 | Yesterday, 11:41 PM Last post by: Tomk |
|||
![]() |
0 | GGGGG | 0 | Yesterday, 11:26 PM Last post by: GGGGG |
|||
![]() |
2 | GGGGG | 37 | Yesterday, 11:09 PM Last post by: GGGGG |
|||
![]() |
14 | hubbcap_86 | 227 | Yesterday, 10:31 PM Last post by: hubbcap_86 |
|||
|
Time is now: 17th March 2010 - 01:14 AM |