This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE redirecting Ebay and other sites

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, When I try to log into Ebay it redirects me to a page asking for personal information that Ebay does not ask for. Having a similar problem when trying to log onto my Online Banking site. here is my DDS txt thing. Any help is greatly appreciated DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 5:52:53.82 on Sun 06/13/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.174 [GMT -7:00] AV: Norton Security Suite *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Security Suite *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe C:\Program Files\Acer\Acer VCM\RS_Service.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\igfxsrvc.exe C:\PROGRA~1\LAUNCH~1\LManager.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\WebCam\M3000\M3000Mnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Acer\Acer VCM\AcerVCM.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\WINDOWS\system32\igfxext.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Documents and Settings\Sammy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.bing.com/ uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0610&m=aspire_one uInternet Connection Wizard,ShellNext = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0610&m=aspire_one uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\4.2.0.12\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\4.2.0.12\IPSBHO.DLL BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.415.1646\swg.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\4.2.0.12\coIEPlg.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [AzMixerSel] c:\program files\realtek\audio\drivers\AzMixerSel.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [LManager] c:\progra~1\launch~1\LManager.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [NotificationCenterLauncher] c:\program files\acer\acer erecovery management\NotificationLauncher.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acervc~1.lnk - c:\program files\acer\acer vcm\AcerVCM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\acer\acer vcm\Skype4COM.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL ============= SERVICES / DRIVERS =============== R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2001-1-1 328752] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2001-1-1 173104] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100429.001\BHDrvx86.sys [2010-4-29 537136] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2001-1-1 501888] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2001-1-1 116784] R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\4.2.0.12\ccsvchst.exe [2001-1-1 126392] R2 RS_Service;Raw Socket Service;c:\program files\acer\acer vcm\RS_Service.exe [2009-3-7 237568] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100604.004\IDSXpx86.sys [2001-1-1 331640] R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2009-3-3 38912] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-6-13 38224] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\virusdefs\20100612.003\NAVENG.SYS [2001-1-1 85552] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\virusdefs\20100612.003\NAVEX15.SYS [2001-1-1 1347504] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-3-7 1684736] S3 M3000Srv;WebCam Driver;c:\windows\system32\drivers\M3000KNT.sys [2010-6-11 145408] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-3-7 162816] S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys –> c:\windows\system32\drivers\Rts516xIR.sys [?] S4 0124031276314268mcinstcleanup;McAfee Application Installer Cleanup (0124031276314268);c:\docume~1\sammy\locals~1\temp\012403~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\docume~1\sammy\locals~1\temp\012403~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?] S4 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-3-7 24064] =============== Created Last 30 ================ 2010-06-13 05:35 –d—– c:\docume~1\sammy\applic~1\Malwarebytes 2010-06-13 05:35 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-13 05:35 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-06-13 05:35 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-06-13 05:35 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-06-12 23:59 –dsh— c:\documents and settings\sammy\IECompatCache 2010-06-12 23:58 –dsh— c:\documents and settings\sammy\PrivacIE 2010-06-12 23:56 –dsh— c:\documents and settings\sammy\IETldCache 2010-06-11 21:04 –d—– c:\program files\NortonInstaller 2010-06-11 21:04 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2010-06-11 21:02 –d—– C:\bd8348ea9863416b01c87055f12a 2010-06-11 21:01 –d—– c:\docume~1\alluse~1\applic~1\Norton 2010-06-11 20:27 –d—– c:\documents and settings\sammy\Tracing 2010-06-11 13:50 –d—– c:\windows\system32\LogFiles 2010-06-11 11:41 107,368 a—-r– c:\windows\system32\GEARAspi.dll 2010-06-11 11:41 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys 2010-06-11 11:40 –d—– c:\program files\iPod 2010-06-11 11:40 –d—– c:\program files\iTunes 2010-06-11 11:40 –d—– c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2010-06-11 11:38 –d—– c:\program files\Bonjour 2010-06-11 10:54 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys 2010-06-11 10:54 14,592 a——- c:\windows\system32\drivers\kbdhid.sys 2010-06-11 10:53 10,368 ac—— c:\windows\system32\dllcache\hidusb.sys 2010-06-11 10:53 10,368 a——- c:\windows\system32\drivers\hidusb.sys 2010-06-11 03:01 2,560 ——– c:\windows\system32\xpsp4res.dll 2010-06-11 03:00 –d—– c:\windows\system32\PreInstall 2010-06-11 00:43 –d—– c:\windows\Screensavers 2010-06-11 00:41 21,504 ac—— c:\windows\system32\dllcache\hidserv.dll 2010-06-11 00:41 21,504 a——- c:\windows\system32\hidserv.dll 2010-06-11 00:40 12,160 ac—— c:\windows\system32\dllcache\mouhid.sys 2010-06-11 00:40 12,160 a——- c:\windows\system32\drivers\mouhid.sys 2010-06-11 00:38 106,557 a——- c:\windows\system32\btw_ci.dll 2010-06-11 00:38 879,528 a——- c:\windows\system32\drivers\btkrnl.sys 2010-06-11 00:38 156,392 a——- c:\windows\system32\drivers\btwdndis.sys 2010-06-11 00:38 55,352 a——- c:\windows\system32\drivers\btwhid.sys 2010-06-11 00:38 37,424 a——- c:\windows\system32\drivers\btport.sys 2010-06-11 00:38 539,576 a——- c:\windows\system32\drivers\btaudio.sys 2010-06-11 00:38 –d—– c:\program files\WIDCOMM 2010-06-11 00:38 a-d—– c:\windows\BTW 2010-06-11 00:34 –d—– c:\program files\ALi 2010-06-11 00:33 –d—– c:\docume~1\sammy\applic~1\Super-Cow 2010-06-11 00:33 –d—– c:\docume~1\sammy\applic~1\Acer GameZone Console 2010-06-11 00:33 –d—– c:\docume~1\sammy\applic~1\Acer 2010-06-11 00:33 –d—– c:\documents and settings\Sammy 2010-06-11 00:29 8,192 a——- c:\windows\REGLOCS.OLD 2010-06-11 00:29 5,504 a——- c:\windows\system32\drivers\MSTEE.sys 2010-06-11 00:29 10,880 a——- c:\windows\system32\drivers\NdisIP.sys 2010-06-11 00:29 16,384 a——- c:\windows\system32\ipsink.ax 2010-06-11 00:29 15,232 a——- c:\windows\system32\drivers\StreamIP.sys 2010-06-11 00:29 11,136 a——- c:\windows\system32\drivers\SLIP.sys 2010-06-11 00:25 –d—– c:\windows\3G 2010-06-10 23:49 –d—– c:\windows\system32\SoftwareDistribution ==================== Find3M ==================== 2010-06-11 00:42 2,505 a——- c:\windows\CLEANUP.CMD 2010-05-01 22:22 1,851,264 a——- c:\windows\system32\win32k.sys 2010-04-19 22:30 285,696 a——- c:\windows\system32\atmfd.dll 2010-04-08 13:20 107,808 a——- c:\windows\system32\dns-sd.exe 2010-04-08 13:20 91,424 a——- c:\windows\system32\dnssd.dll 2009-03-07 07:10 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat ============= FINISH: 5:55:10.25 ===============
Hello xwomadness and welcome to WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again xwomadness

It sounds like a phishing scam and you are right to be wary and give no information. I would advise you not to attempt any online banking until we can discover what is causing this.

have had a look through your log but need some more information so please follow the instructions below: if you have any problems please ask before continuing.

Run OTL

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    • netsvcs
      %SYSTEMDRIVE%\*.exe
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      mv61xx.sys
      nvraid.sys
      /md5stop
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\drivers\*.sys /90
      CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.


Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
Hello xwomadness It has been several days since I sent my last post with instructions to help with your computer problem.. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI