This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Search Engine Hijacked

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

LDTate (or other moderator):
It seems others have had this same problem lately. I followed what you suggested for someone else and used ComboFix and it seemed to fix the issue, but I want to be sure there isn't anything more I should do to clean things up. I didn't do anything other than running ComboFix (I didn't do anything with notepad or cmd line things you mentioned to someone). Previously, anytime I used any search engine such as yahoo or google I was getting results that are to the wrong sites (ad sites or other search type things). Now it seems to be fixed. Here is my ComboFix log. Thank you!

ComboFix 09-01-19.05 - bfmn 2009-01-20 11:49:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.530 [GMT -8:00]
Running from: F:\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\wdmaud.sys

.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.

2009-01-20 10:56 . 2009-01-20 10:57 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-20 10:56 . 2009-01-20 10:56 d——– c:\documents and settings\bfortman\Application Data\Malwarebytes
2009-01-20 10:56 . 2009-01-20 10:56 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-20 10:56 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-20 10:56 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-16 17:52 . 2009-01-16 17:52 d——– c:\program files\Trend Micro
2009-01-16 15:44 . 2009-01-16 15:47 d——– C:\test
2009-01-16 15:08 . 2009-01-16 15:08 d——– c:\windows\Sun
2008-12-22 10:13 . 2009-01-13 17:36 69 –a—— c:\windows\NeroDigital.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-16 23:51 ——— d—–w c:\program files\Windows Desktop Search
2008-12-24 01:49 ——— d—–w c:\documents and settings\bfortman\Application Data\AdobeUM
2008-12-23 19:42 ——— d—–w c:\program files\Common Files\Adobe
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-10 18:11 ——— d—–w c:\program files\IrfanView
2008-12-09 22:57 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-09 22:57 ——— d—a-w c:\program files\Canon
2008-12-09 22:56 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-08 17:24 ——— d—–w c:\documents and settings\bfortman\Application Data\FileMaker
2008-12-08 17:23 ——— d—–w c:\program files\FileMaker
2008-12-05 23:31 ——— d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-05 22:39 ——— d—–w c:\documents and settings\bfortman\Application Data\Windows Search
2008-12-05 22:32 ——— d—–w c:\program files\MIKSOFT
2008-12-05 22:30 ——— d—–w c:\program files\Java
2008-12-05 22:14 ——— d—–w c:\documents and settings\administrator\Application Data\Windows Desktop Search
2008-12-05 21:55 ——— d—–w c:\documents and settings\Owner\Application Data\Windows Desktop Search
2008-12-05 21:53 ——— d—–w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-05 21:26 ——— d—–w c:\program files\Creative
2008-12-05 21:22 ——— d—–w c:\program files\SigmaTel
2008-12-05 21:18 ——— d—–w c:\program files\AMD
2008-12-05 21:17 ——— d—–w c:\program files\Common Files\Java
2008-12-05 21:15 5 —-a-w c:\windows\system32\drivers\DELL_DIM_E521.MRK
2008-12-05 21:15 5 —-a-w c:\windows\system32\drivers\1028_DELL_DIM_E521.MRK
2008-12-05 21:14 ——— d—–w c:\program files\Broadcom
2008-12-05 21:07 ——— d—–w c:\program files\Eset
2008-12-05 21:07 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2008-12-05 21:06 ——— d—–w c:\program files\RealVNC
2008-12-05 20:45 ——— d—–w c:\program files\Analog Devices
2008-12-05 12:36 3,328 —-a-w c:\windows\system32\drivers\pciide.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2005-08-31 1658592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe" [2007-11-09 1274600]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe" [2007-11-09 884696]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-11-09 136472]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-05 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-05 137752]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-05 136600]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2006-08-23 c:\windows\system32\nwiz.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 c:\windows\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2008-02-20 25214]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"= wdmaud.sys

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-02-20 33800]
R3 shwMirror;shwMirror;c:\windows\system32\drivers\shwMirror.sys [2006-08-29 3584]
R4 ekrn;Eset Service;c:\program files\Eset\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-01-20 38496]
.
.
——- Supplementary Scan ——-
.
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\bfortman\Application Data\Mozilla\Firefox\Profiles\3okjpcqt.default\
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 11:58:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(812)
c:\windows\system32\relog_ap.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\windows\system32\rundll32.exe
c:\program files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
.
**************************************************************************
.
Completion time: 2009-01-20 11:59:22 - machine was rebooted [bfortman]
ComboFix-quarantined-files.txt 2009-01-20 19:59:20

Pre-Run: 105,552,703,488 bytes free
Post-Run: 106,128,818,176 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

148 — E O F — 2009-01-14 11:01:38
DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.




[external image: Posted Image]

Sorry about the delay in responding :(

If you still need help, Scan again with HijackThis, and "copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI