943,589 Members | Top Members by Rank

Ad:
You are currently viewing page 1 of this multi-page discussion thread
Aug 3rd, 2009
0

Search Engine Redirect Problem

Expand Post »
Some sort of malware is causing all my search engines to redirect me. Whenever I click on a link in a search engine, it opens a new tab and redirects me to one of a long list of search engines like couponmountain, buyerzone, bestwebchoices, pronto, etc. I've run a few things that I've found in old forums but none of it has worked. I'll include a hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:33:22 AM, on 8/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\CScp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CSSvc.exe
C:\WINDOWS\system32\CSSvr.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Owner.KITCHENCOMPY\My Documents\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [csrun] CScp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: cssp.dll
O10 - Unknown file in Winsock LSP: cssp.dll
O10 - Unknown file in Winsock LSP: cssp.dll
O10 - Unknown file in Winsock LSP: cssp.dll
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Zacharyah is offline Offline
11 posts
since Aug 2009
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

Reboot into 'safe mode' and perform a free online virus/malware scan.
Trend Micro:
housecall.trendmicro.com (this one will give option to remove infections)
Symantec:
security.symantec.com (this one you have to take note of where the infections are and go delete them yourself)
Note: You may want to scan and if infections are found turn off system restore (or the infections will never go away) or just turn it off and then scan, the down side to this is that if you turn off system restore all of your restore points get removed and you have no way to roll your system files back in time. The best solution is to see if you have infections, then disable system restore.
To disable system restore, right click 'My Computer' select 'Properties' locate the 'System Restore' tab, check the box that states "Turn off system restore on all drives".
Good luck!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Techy 45 is offline Offline
1 posts
since May 2009
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

Absolutely do not turn system restore off before your PC is cleaned.

Should things go wrong, it is better to be able to restore to an infected point rather than not be able to restore at all.

Download Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

Once done, post a fresh HJT log too.
Reputation Points: 125
Solved Threads: 193
Nearly a Posting Maven
Rik from RCE is offline Offline
2,204 posts
since May 2009
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

For whatever reason malwarebyte isn't working. I download it and it installs, though it does take forever, and then it won't open the program.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Zacharyah is offline Offline
11 posts
since Aug 2009
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

download and run Spybot search and destroy. I had this exact same problem a few months back and I got rid of it with spybot. Also I dl'ed and ran a 1 click maintenance of Glary utilities and I was back to running like a new machine.

PS. Can't remember if this is the time I also noticed that the proxy settings for Internet Explorer and Firefox were also changed. So check them when you are finished your scans

Hope this helps
Reputation Points: 11
Solved Threads: 8
Junior Poster in Training
slash49er is offline Offline
99 posts
since Jun 2008
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

And trendmicro's housecall didn't find any threats
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Zacharyah is offline Offline
11 posts
since Aug 2009
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

Locate mbam.exe and rename it to helpme.exe and see if that gets it going.
Reputation Points: 125
Solved Threads: 193
Nearly a Posting Maven
Rik from RCE is offline Offline
2,204 posts
since May 2009
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

renaming the file didn't help
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Zacharyah is offline Offline
11 posts
since Aug 2009
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

did you rename the exe in programs folder or just the icon on the desktop .
Team Colleague
Reputation Points: 1056
Solved Threads: 791
I hate 20 Questions
caperjack is offline Offline
12,713 posts
since Aug 2003
Aug 3rd, 2009
0

Re: Search Engine Redirect Problem

The .exe
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Zacharyah is offline Offline
11 posts
since Aug 2009

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Windows NT / 2000 / XP Forum Timeline: concerning "system volume information"
Next Thread in Windows NT / 2000 / XP Forum Timeline: Audio Breaking up





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC