This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] google redirect

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Can you give a little more information? What kind of sites, which browser, any other symptoms?

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from one of the following locations and save it to your desktop.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • In the Select Scan dialog, check
    [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Please post this log in your next reply.
I am using internet explorer version 8 for my browser and doing google searches and redirects me to any random site. I have done the steps to see if i am infected and sending you the results from MBAM, GMER, attach, and DDS. Let me know what i should do nextt.

Hi,

Can you give a little more information? What kind of sites, which browser, any other symptoms?

Please download DDS and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from one of the following locations and save it to your desktop.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • In the Select Scan dialog, check
    [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Please post this log in your next reply.

I am using internet explorer version 8 as my browser and when i do google searches i get redirected to any random sites. I am sending you the MBAM report, Gmer report, Attach, and DDS logs as well. Please advise me as to what i should do next. Looking forward to hearing from you.📎mbam_log_2010_01_03__12_34_21_.txt📎ark.txt[attachmen
t=6650:Attach.txt.zip]📎DDS.txt

Attachments:

Hi,

In future, please post the logs rather than attaching them.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Hi,

In future, please post the logs rather than attaching them.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Hi, I ran combo fix and while it was running i left the computer for about 10 minutes and while i was away the program had finished and the computer rebooted. I did not see the report and i do not know where i would get it. I enabled my virus protection and went back on line and did a google search and it worked fine. i tried about five google searches and was not redirected once. I think the combo fix must have removed the infections. if there is anything else i should do please let me know but right now the google searches are running fine.

Try looking for the log at C:\ComboFix.txt

i did a search and could not find it. What do you suggest i do to get this report? Is it possible to rerun combo fix again?
Do you have a folder called C:\QooBox? If so, please look in there for a log, or even this file: ComboFix-quarantined-files.txt. If you don't have this folder, or if you can't find the logs, please tell me if you have a C:\ComboFix folder.

Do you have a folder called C:\QooBox? If so, please look in there for a log, or even this file: ComboFix-quarantined-files.txt. If you don't have this folder, or if you can't find the logs, please tell me if you have a C:\ComboFix folder.

I have QooBox folder no log in this folder and I do not have ComboFix-quarantined-files.txt or a Combo Fix folder. I only have the download application.
OK, in that case, please run it again. If you can, try and stay near the machine just in case it does it again. Usually, it will ask to reboot your machine once or twice.

OK, in that case, please run it again. If you can, try and stay near the machine just in case it does it again. Usually, it will ask to reboot your machine once or twice.

ComboFix 10-01-03.03 - Lorraine 01/04/2010 18:41:08.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.447 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\downloads\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Lorraine\Local Settings\Temporary Internet Files\esb-windows.zip
c:\windows\desktop
c:\windows\desktop\Install America Online - Free Trial.lnk
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\winhelp.ini

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-12-04 to 2010-01-04 )))))))))))))))))))))))))))))))
.

2010-01-04 20:48 . 2010-01-04 20:48 ——– d—–w- c:\windows\LastGood
2010-01-03 02:00 . 2010-01-03 02:01 ——– dc-h–w- c:\windows\ie8
2010-01-03 00:23 . 2010-01-03 00:23 ——– d—–w- c:\documents and settings\Administrator.HOME-1097449D87\Local Settings\Application Data\Adobe
2010-01-03 00:00 . 2010-01-03 00:00 ——– d—–w- c:\windows\system32\wbem\Repository
2010-01-02 23:57 . 2010-01-02 23:57 ——– d—–w- c:\program files\QuickTime
2010-01-02 23:57 . 2010-01-02 23:57 ——– d—–w- c:\program files\iPod
2010-01-02 23:57 . 2010-01-02 23:57 ——– d—–w- c:\program files\iTunes
2010-01-02 21:09 . 2010-01-02 21:09 ——– d—–w- c:\documents and settings\Lorraine\Application Data\Malwarebytes
2010-01-02 21:09 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 21:09 . 2010-01-02 21:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-02 21:09 . 2010-01-03 00:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 21:09 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 21:05 . 2010-01-03 00:00 ——– d—–w- c:\program files\ERUNT
2010-01-02 03:10 . 2010-01-02 03:10 0 —-a-w- c:\windows\nsreg.dat
2010-01-02 03:10 . 2010-01-02 03:10 ——– d—–w- c:\documents and settings\Lorraine\Local Settings\Application Data\Mozilla
2010-01-01 18:22 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-04 21:11 . 2009-10-02 12:44 ——– d—–w- c:\program files\SpyZooka
2010-01-03 04:16 . 2009-10-02 17:44 ——– d—–w- c:\documents and settings\Lorraine\Application Data\Spyzooka
2010-01-03 01:32 . 2009-10-02 13:00 ——– d—–w- c:\program files\RegZooka
2010-01-03 00:00 . 2006-02-28 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-03 00:00 . 2006-02-28 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2010-01-02 23:59 . 2009-01-10 21:22 ——– d—–w- c:\program files\Yahoo!
2010-01-02 23:59 . 2008-09-17 20:52 ——– d—–w- c:\documents and settings\Lorraine\Application Data\Aladdin Systems
2010-01-02 23:57 . 2009-11-18 23:23 ——– d—–w- c:\program files\QuickTime(2)
2010-01-02 23:57 . 2009-11-18 23:27 ——– d—–w- c:\program files\iPod(2)
2010-01-02 23:57 . 2009-11-18 23:27 ——– d—–w- c:\program files\iTunes(2)
2010-01-02 23:57 . 2008-09-21 02:25 ——– d—–w- c:\program files\Common Files\Apple
2010-01-02 23:55 . 2009-09-17 19:38 ——– d—–w- c:\program files\WebEx
2010-01-02 23:55 . 2009-03-23 19:29 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-02 23:55 . 2009-03-23 19:28 ——– d—–w- c:\program files\NOS
2010-01-02 22:35 . 2008-09-18 00:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-02 22:35 . 2008-09-18 00:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-02 22:34 . 2008-09-17 20:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-02 02:14 . 2008-09-18 03:27 ——– d—–w- c:\program files\Google
2010-01-02 01:30 . 2008-09-17 21:12 ——– d—–w- c:\program files\McAfee
2009-12-12 14:03 . 2008-09-21 01:21 ——– d—–w- c:\documents and settings\Lorraine\Application Data\Apple Computer
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 23:28 . 2009-11-18 23:27 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-29 07:45 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-10-08 818288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2006-05-05 36864]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2006-05-05 40960]
"MediaFace Integration"="c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe" [2003-08-18 53248]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"nwiz"="nwiz.exe" [2009-02-18 1657376]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-01-19 11776]
"PrintServer Diagnostic"="c:\program files\Print Server\PTP\PSDiagnostic.exe" [2004-11-24 266240]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"PCLEPCI"="c:\progra~1\Pinnacle\PPE\ppe.exe" [2002-01-15 32768]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-26 198160]
"mumservice"="c:\program files\Motorola\Software Update\mumservice.exe" [2009-08-19 1070336]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{D468BCE5-D18E-49A4-8EA7-34BD583659D5}"= "c:\progra~1\SpyZooka\spyguard.dll" [2005-05-08 173568]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R1 LStone;Pinnacle Systems Studio AV/DV Overlay;c:\windows\system32\drivers\LStone2k.sys [9/18/2008 3:29 PM 256113]
R1 MemAlloc;MemAlloc;c:\windows\system32\drivers\MemAlloc.sys [9/18/2008 3:29 PM 5543]
R2 MotoConnect Service;MotoConnect Service;c:\program files\Motorola\MotoConnectService\MotoConnectService.exe [10/12/2009 7:40 PM 91392]
R2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\drivers\UBSBM.sys [7/27/2005 4:25 PM 14080]
R2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\drivers\UBUMAPI.sys [7/27/2005 4:25 PM 36352]
R3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\drivers\ubohci.sys [7/27/2005 4:25 PM 77056]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" –> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
S3 dfg;dfg;c:\windows\system32\drivers\dfg.sys [10/2/2009 8:00 AM 23552]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys –> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys –> c:\windows\system32\DRIVERS\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2/23/2009 6:18 PM 42752]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys –> c:\windows\system32\DRIVERS\motport.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - MOTOCONNECT_SERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2009-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-01-04 c:\windows\Tasks\User_Feed_Synchronization-{9C555607-B381-491E-9775-F0953C79E912}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Send Image to Photo Library
Trusted Zone: musicmatch.com\online
DPF: Geni Publisher - hxxp://www.geni.com/plugins/genipublisher.CAB
DPF: {F3CAAA40-344A-412E-84E3-D176D64EE54F} - hxxps://www.bms2000.org/BMS2000_Access_Control.ocx
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-04 18:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-04 18:52:26
ComboFix-quarantined-files.txt 2010-01-04 23:52

Pre-Run: 63,509,377,024 bytes free
Post-Run: 64,204,640,256 bytes free

- - End Of File - - 03E48B5615751D615505B78B1FFD896E

That looks a lot better, how are things running?

I did a few google searches and everything seems fine. I am not being redirected any more. Thank you so very much. You guys are the best.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI