yolozone
Topic Starter
I confess it, I did download iLiVid video software and have been cursed with the searchqu.com browser hijack ever since.
Some other curious symptoms, over the same 2-week period:
- MalwareBytes AntiMalware has been unable to run its updating protocol;
- My Thunderbird Profiles directory is not editable
- Clicking on Google/NortonSafe search results gets hijacked to various vendor sites rather than the requested search result.
I spent about 20 days (part time!) working with the AntiMalware tech support to try to fix these two issues. Eventually we agreed to close the ticket and I should re-install Windows. I meanwhile read that whatthetech is more familiar with the searchqu.com infection, and I see you are using some different tools than the MBAM tech. So if it's all right I would like to try your tech support in hopes to avoid scrubbing the machine and re-installing all my apps.
OK?
here is the DDS.txt log contents:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 19:43:34 on 2011-10-28
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.289 [GMT -4:00]
.
AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\PKWARE\PKZIPM\9.00.0010\PKTray.exe
C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [DiskeeperSystray] "c:\program files\diskeeper corporation\diskeeper\DkIcon.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [DATAMNGR] c:\progra~1\search~1\search~1\DATAMN~1.EXE
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\docume~1\user\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\user\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pkzipa~1.lnk - c:\program files\pkware\pkzipm\9.00.0010\PKTray.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{62B01DCB-0F6D-4468-98F0-E1C04CEDAE56} : DhcpNameServer = 192.168.1.1
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\3p0gzzlb.default\
FF - prefs.js: keyword.URL - hxxp://www.hpmirror.com
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2011-10-18 28552]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-6-9 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-6-9 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111014.001\BHDrvx86.sys [2011-10-14 818808]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-10-19 98392]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-6-9 136312]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-15 366152]
R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccSvcHst.exe [2011-6-9 130008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-10-22 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20111026.030\IDSXpx86.sys [2011-10-26 356280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-10-15 22216]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\virusdefs\20111028.002\NAVENG.SYS [2011-10-28 86136]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\virusdefs\20111028.002\NAVEX15.SYS [2011-10-28 1576312]
S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\shldrv51.sys –> c:\windows\system32\drivers\ShlDrv51.sys [?]
S2 PavProc;Panda Process Protection Driver;\??\c:\windows\system32\drivers\pavproc.sys –> c:\windows\system32\drivers\PavProc.sys [?]
S2 PavPrSrv;Panda Process Protection Service;"c:\program files\common files\panda software\pavshld\pavprsrv.exe" –> c:\program files\common files\panda software\pavshld\pavprsrv.exe [?]
S3 2812992B;2812992B;c:\windows\system32\2812992b.exe –> c:\windows\system32\2812992B.exe [?]
S3 71418283;71418283;c:\windows\system32\71418283.exe –> c:\windows\system32\71418283.exe [?]
S3 84563EAA;84563EAA;c:\windows\system32\84563eaa.exe –> c:\windows\system32\84563EAA.exe [?]
S3 BrYNSvc;BrYNSvc;c:\program files\browny02\BrYNSvc.exe [2011-6-29 245760]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2011-6-1 227896]
S3 DrvAgent32;DrvAgent32;\??\c:\windows\system32\drivers\drvagent32.sys –> c:\windows\system32\drivers\DrvAgent32.sys [?]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [2011-6-1 588032]
UnknownUnknown BlackBox;BlackBox; [x]
.
=============== Created Last 30 ================
.
2011-10-20 03:15:39 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-20 03:15:39 27984 —-a-w- c:\windows\system32\sbbd.exe
2011-10-18 12:34:36 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2011-10-18 12:34:16 ——– d—–w- c:\program files\Panda Security
2011-10-18 12:00:22 ——– d—–w- c:\program files\MozBackup
2011-10-18 02:33:27 753664 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iKernel.dll
2011-10-18 02:33:27 69714 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\ctor.dll
2011-10-18 02:33:27 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\DotNetInstaller.exe
2011-10-18 02:33:27 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iscript.dll
2011-10-18 02:33:27 184320 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iuser.dll
2011-10-18 02:33:25 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\setup.dll
2011-10-18 02:33:25 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iGdi.dll
2011-10-16 16:23:37 ——– d—–w- c:\program files\ESET
2011-10-16 02:17:35 ——– d—–w- c:\documents and settings\user\application data\Malwarebytes
2011-10-16 02:17:27 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
2011-10-16 02:17:24 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-16 02:17:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-10-14 19:03:24 ——– d-sha-r- C:\cmdcons
2011-10-14 19:01:28 518144 —-a-w- c:\windows\SWREG.exe
2011-10-14 19:01:28 256000 —-a-w- c:\windows\PEV.exe
2011-10-14 19:01:28 208896 —-a-w- c:\windows\MBR.exe
2011-10-14 19:01:27 98816 —-a-w- c:\windows\sed.exe
2011-10-13 07:07:45 ——– d—–w- C:\fa473302f039f3817773a7
2011-10-12 18:35:05 ——– d—–w- c:\documents and settings\user\local settings\application data\WMTools Downloaded Files
2011-10-05 02:30:19 ——– d—–w- c:\documents and settings\user\application data\SUPERAntiSpyware.com
2011-10-05 02:29:08 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-10-05 02:29:08 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
.
==================== Find3M ====================
.
2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-24 15:28:00 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48:55 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 ——w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56:39 385024 ——w- c:\windows\system32\html.iec
2011-08-17 13:49:54 138496 —-a-w- c:\windows\system32\drivers\afd.sys
.
============= FINISH: 19:44:17.75 ===============