This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Redirected browser searches

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I perform a search in my browser, I am redirected to a variety of sites. My HiJackThis log is attached.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:50:48, on 03/13/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Ethan\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=bfus
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=bfus&s={…hTerms}&f=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 11.11.11.11 support.steampowered.com
O1 - Hosts: 11.11.11.11 www.support.steampowered.com
O1 - Hosts: 11.11.11.11 steampowered.com
O1 - Hosts: 11.11.11.11 www.steampowered.com
O1 - Hosts: 11.11.11.11 steamcommunity.com
O1 - Hosts: 11.11.11.11 www.steamcommunity.com
O1 - Hosts: 11.11.11.11 support.steampowered.com
O1 - Hosts: 11.11.11.11 www.support.steampowered.com
O1 - Hosts: 11.11.11.11 steampowered.com
O1 - Hosts: 11.11.11.11 www.steampowered.com
O1 - Hosts: 11.11.11.11 steamcommunity.com
O1 - Hosts: 11.11.11.11 www.steamcommunity.com
O1 - Hosts: 11.11.11.11 support.steampowered.com
O1 - Hosts: 11.11.11.11 www.support.steampowered.com
O1 - Hosts: 11.11.11.11 steampowered.com
O1 - Hosts: 11.11.11.11 www.steampowered.com
O1 - Hosts: 11.11.11.11 steamcommunity.com
O1 - Hosts: 11.11.11.11 www.steamcommunity.com
O2 - BHO: (no name) - {0D08E004-0A74-FD55-5B6F-1D0470F3804D} - (no file)
O2 - BHO: (no name) - {1770AFBB-BD91-4EF2-9FB6-86DDD841A2Bc} - (no file)
O2 - BHO: (no name) - {2103A80D-3224-5735-5F2E-7C14B4C91D17} - (no file)
O2 - BHO: (no name) - {267A5683-080C-99BB-4DBB-81F08C6F57D8} - (no file)
O2 - BHO: (no name) - {272A074B-85B0-9CE5-A201-C157C7D3C906} - (no file)
O2 - BHO: (no name) - {2929B2D9-86AE-2BF6-AAC5-DFC527B326F9} - (no file)
O2 - BHO: (no name) - {2B117686-108B-4D84-F69D-B18C229F60A5} - (no file)
O2 - BHO: (no name) - {2B81364B-C57E-BC9D-5DAB-9CE6A5C4BD83} - (no file)
O2 - BHO: (no name) - {2EF83A32-9B68-6F11-4275-84541C8A9A51} - (no file)
O2 - BHO: (no name) - {3C959E02-C6D6-146A-845C-0A4EC8F93BE6} - (no file)
O2 - BHO: (no name) - {3CE5324A-6FD1-1CED-888D-0F861F882479} - (no file)
O2 - BHO: (no name) - {3DCF8336-1854-A225-2DB6-11CC2A943859} - (no file)
O2 - BHO: (no name) - {4468E4A4-E9ED-AFCA-E67E-2B3881464CAC} - (no file)
O2 - BHO: (no name) - {50657ABA-65FB-A5D6-46E9-5D132ED8D815} - (no file)
O2 - BHO: (no name) - {51C7CE62-FAC1-FD9D-78E9-DE526A77433B} - (no file)
O2 - BHO: (no name) - {531F51D4-3A91-8D43-2AD0-9C73E888D9C5} - (no file)
O2 - BHO: (no name) - {5C45072D-8F18-F116-7E2A-1D91BC51409A} - (no file)
O2 - BHO: (no name) - {5E9F8BE1-FCA3-F367-55D1-63CE9EA70E85} - (no file)
O2 - BHO: (no name) - {5EBFFC6E-2D3A-65AA-1026-8E8D5D31DC91} - (no file)
O2 - BHO: (no name) - {632930DE-7F73-E052-5316-2AC2B226AD63} - (no file)
O2 - BHO: (no name) - {63A37950-EFDD-5429-B88F-F5358FE3B406} - (no file)
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll
O2 - BHO: (no name) - {6A3944E1-F859-9803-6A34-433F85F21AC6} - (no file)
O2 - BHO: (no name) - {72CF1E59-6658-8A6A-9367-90D6B72BF9BE} - (no file)
O2 - BHO: (no name) - {7AC9E862-3254-25C7-A490-05A8AEFD5FF7} - (no file)
O2 - BHO: (no name) - {7BA5BC6A-6EB9-ADF1-1C99-B5D684FA09BD} - (no file)
O2 - BHO: (no name) - {7FFEB4BD-A50C-82C9-1B73-B405088EFD9F} - (no file)
O2 - BHO: (no name) - {81165555-AF68-9F96-7B70-A4C16DCE2E70} - (no file)
O2 - BHO: (no name) - {84F19EFD-B596-FA45-1BAB-0DE2E50AFE2D} - (no file)
O2 - BHO: (no name) - {875A269E-D816-7531-3117-048D77DB39AA} - (no file)
O2 - BHO: (no name) - {8E285885-EECD-475D-D28B-C78ACC920AF5} - (no file)
O2 - BHO: (no name) - {95F68A6D-0484-1A8A-72FF-8A87224ADB3F} - (no file)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: (no name) - {9FF4A793-8E5E-8EA7-B84D-446B3E9CF2D5} - (no file)
O2 - BHO: (no name) - {A0C22258-80B9-BA65-9B87-87EE73EADFA7} - (no file)
O2 - BHO: (no name) - {AD6378C2-A21B-9289-AE61-1F91ACB677C6} - (no file)
O2 - BHO: (no name) - {B0D67B27-1C8F-63A7-4BAA-F6C95CF4E5D3} - (no file)
O2 - BHO: (no name) - {B56E9B2A-240E-176F-F58C-2764F224EEA0} - (no file)
O2 - BHO: (no name) - {B98D62D3-58A0-A8D4-C168-8D726E77920E} - (no file)
O2 - BHO: (no name) - {C07C0548-9FEF-ED43-1D31-7BBD86AF16E9} - (no file)
O2 - BHO: (no name) - {C0B36D9F-AC2A-7C95-0CFF-F0B0E5578174} - (no file)
O2 - BHO: (no name) - {C7819F87-C1E1-4FC2-AD73-B3AD3B0E51BE} - (no file)
O2 - BHO: (no name) - {CBB66BE1-349A-ACC3-2455-620A959FEF66} - (no file)
O2 - BHO: (no name) - {DA0B33EA-3D1B-F558-FF2F-E657F53C3453} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {DC0DA7CB-349F-3989-4B23-2765FBBE92AB} - (no file)
O2 - BHO: (no name) - {E61B7643-1305-2FD8-E292-5DDD6894D539} - (no file)
O2 - BHO: (no name) - {EDB140D4-1C82-73B2-9437-ABE65FA33BF9} - (no file)
O2 - BHO: (no name) - {F3CFC2F4-B594-42B5-E064-2E7D7AF69A15} - (no file)
O2 - BHO: (no name) - {F93426F2-3A07-493F-0F7D-9FE53D293D6D} - (no file)
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: CNET TechTracker.lnk = C:\Users\Ethan\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe
O4 - Global Startup: Secunia PSI Tray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Secunia Update Agent - Unknown owner - C:\Program Files (x86)\Secunia\PSI\sua.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Stardock WindowBlinds (WindowBlinds) - Stardock Corporation - C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11685 bytes

Thanks for looking.
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.


Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.




Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI