Search Engine Redirect Problem

Reply

Join Date: Aug 2009
Posts: 11
Reputation: Zacharyah is an unknown quantity at this point 
Solved Threads: 0
Zacharyah's Avatar
Zacharyah Zacharyah is offline Offline
Newbie Poster

Search Engine Redirect Problem

 
0
  #1
Aug 3rd, 2009
Some sort of malware is causing all my search engines to redirect me. Whenever I click on a link in a search engine, it opens a new tab and redirects me to one of a long list of search engines like couponmountain, buyerzone, bestwebchoices, pronto, etc. I've run a few things that I've found in old forums but none of it has worked. I'll include a hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:33:22 AM, on 8/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\CScp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CSSvc.exe
C:\WINDOWS\system32\CSSvr.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Owner.KITCHENCOMPY\My Documents\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [csrun] CScp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: cssp.dll
O10 - Unknown file in Winsock LSP: cssp.dll
O10 - Unknown file in Winsock LSP: cssp.dll
O10 - Unknown file in Winsock LSP: cssp.dll
-Z
Reply With Quote Quick reply to this message  
Join Date: May 2009
Posts: 1
Reputation: Techy 45 is an unknown quantity at this point 
Solved Threads: 0
Techy 45 Techy 45 is offline Offline
Newbie Poster

Re: Search Engine Redirect Problem

 
0
  #2
Aug 3rd, 2009
Reboot into 'safe mode' and perform a free online virus/malware scan.
Trend Micro:
housecall.trendmicro.com (this one will give option to remove infections)
Symantec:
security.symantec.com (this one you have to take note of where the infections are and go delete them yourself)
Note: You may want to scan and if infections are found turn off system restore (or the infections will never go away) or just turn it off and then scan, the down side to this is that if you turn off system restore all of your restore points get removed and you have no way to roll your system files back in time. The best solution is to see if you have infections, then disable system restore.
To disable system restore, right click 'My Computer' select 'Properties' locate the 'System Restore' tab, check the box that states "Turn off system restore on all drives".
Good luck!
Reply With Quote Quick reply to this message  
Join Date: May 2009
Posts: 908
Reputation: Rik from RCE is on a distinguished road 
Solved Threads: 68
Rik from RCE's Avatar
Rik from RCE Rik from RCE is offline Offline
Posting Shark

Re: Search Engine Redirect Problem

 
0
  #3
Aug 3rd, 2009
Absolutely do not turn system restore off before your PC is cleaned.

Should things go wrong, it is better to be able to restore to an infected point rather than not be able to restore at all.

Download Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

Once done, post a fresh HJT log too.
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 11
Reputation: Zacharyah is an unknown quantity at this point 
Solved Threads: 0
Zacharyah's Avatar
Zacharyah Zacharyah is offline Offline
Newbie Poster

Re: Search Engine Redirect Problem

 
0
  #4
Aug 3rd, 2009
For whatever reason malwarebyte isn't working. I download it and it installs, though it does take forever, and then it won't open the program.
-Z
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 70
Reputation: slash49er is an unknown quantity at this point 
Solved Threads: 5
slash49er slash49er is offline Offline
Junior Poster in Training

Re: Search Engine Redirect Problem

 
0
  #5
Aug 3rd, 2009
download and run Spybot search and destroy. I had this exact same problem a few months back and I got rid of it with spybot. Also I dl'ed and ran a 1 click maintenance of Glary utilities and I was back to running like a new machine.

PS. Can't remember if this is the time I also noticed that the proxy settings for Internet Explorer and Firefox were also changed. So check them when you are finished your scans

Hope this helps
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 11
Reputation: Zacharyah is an unknown quantity at this point 
Solved Threads: 0
Zacharyah's Avatar
Zacharyah Zacharyah is offline Offline
Newbie Poster

Re: Search Engine Redirect Problem

 
0
  #6
Aug 3rd, 2009
And trendmicro's housecall didn't find any threats
-Z
Reply With Quote Quick reply to this message  
Join Date: May 2009
Posts: 908
Reputation: Rik from RCE is on a distinguished road 
Solved Threads: 68
Rik from RCE's Avatar
Rik from RCE Rik from RCE is offline Offline
Posting Shark

Re: Search Engine Redirect Problem

 
0
  #7
Aug 3rd, 2009
Locate mbam.exe and rename it to helpme.exe and see if that gets it going.
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 11
Reputation: Zacharyah is an unknown quantity at this point 
Solved Threads: 0
Zacharyah's Avatar
Zacharyah Zacharyah is offline Offline
Newbie Poster

Re: Search Engine Redirect Problem

 
0
  #8
Aug 3rd, 2009
renaming the file didn't help
-Z
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 9,699
Reputation: caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold 
Solved Threads: 509
Team Colleague
caperjack's Avatar
caperjack caperjack is offline Offline
Posting Prodigy

Re: Search Engine Redirect Problem

 
0
  #9
Aug 3rd, 2009
did you rename the exe in programs folder or just the icon on the desktop .
Linux boot cd http://www.knopper.net/knoppix/index-en.html
Wubi is an officially supported Ubuntu Linux installer for Windows .
http://wubi-installer.org/
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 11
Reputation: Zacharyah is an unknown quantity at this point 
Solved Threads: 0
Zacharyah's Avatar
Zacharyah Zacharyah is offline Offline
Newbie Poster

Re: Search Engine Redirect Problem

 
0
  #10
Aug 3rd, 2009
The .exe
-Z
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Windows NT / 2000 / XP Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC