Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - Google redirect virus help!! posted in the Security & Safety forums; I am having a crapload of trouble getting this off of my computer i have been scanning, downloading, and deleting for days now and I have come to the mercy ...


Reply
Recommended Driver Scanner
Old 3 Weeks Ago   #1
Bronze Member
 
Sneakyone's Avatar
 
Join Date: Oct 2009
Posts: 11
PC Experience: Very Experienced
Unhappy Google redirect virus help!!

I am having a crapload of trouble getting this off of my computer i have been scanning, downloading, and deleting for days now and I have come to the mercy of this forum for help i am a semi experienced computer user and i can't run safe mode it gives me a error but normal mode is perfectly fine it's just that when i click on something on google it takes me to z with a bunch of random numbers and says the page is invaild or it takes me to a stupid video on youtube i have mcafee, windows defender, hijack this, superantispyware, malware bytes, combofix, spyware doctor, and drwebcure it i have tried it all i have never had this much trouble with anything computer related and when i scan on mcafee, win def, malware bytes, it finds nothing,but spyware doctor finds a couple low risk cookies, and adware but they keep coming back so if you can help me that would be greatly appreciated
Sneakyone is offline   Reply With Quote
Advertisement - Register to Remove

Old 3 Weeks Ago   #2
Moderator
 
skindred's Avatar
 
Join Date: May 2009
Location: Illinois
Posts: 361
PC Experience: Some Experience
Default Re: Google redirect virus help!!

Hello and Welcome to PCHF

If you would please follow my prework link below and post your logs in this thread. A Senior Security staff member will be with you soon. I will move your thread to the HJT logs(new).


Thank You
Skindred
skindred is offline   Reply With Quote
Old 3 Weeks Ago   #3
Bronze Member
 
Sneakyone's Avatar
 
Join Date: Oct 2009
Posts: 11
PC Experience: Very Experienced
Default Re: Google redirect virus help!!

here they are

ComboFix 09-10-27.08 - Alan 10/28/2009 16:42.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.421 [GMT -5:00]
Running from: c:\documents and settings\Alan\Desktop\Combo-fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Alan\Application Data\gyboz.inf
c:\documents and settings\Alan\Application Data\iniasd.txt
c:\documents and settings\Alan\Application Data\yluhuleguf.inf
c:\documents and settings\Alan\Local Settings\Application Data\rucic.pif
c:\documents and settings\All Users\Application Data\akit.com
c:\documents and settings\All Users\Application Data\aridu.lib
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\otak.dll
c:\documents and settings\All Users\Application Data\rury.sys
c:\documents and settings\All Users\Application Data\ymiz.sys
c:\documents and settings\All Users\Documents\ixomy.pif
c:\documents and settings\All Users\Documents\loqeva.bin
c:\documents and settings\All Users\Documents\pibohapy.sys
c:\program files\Common Files\inisuwa.sys
c:\program files\Common Files\viqefany.pif
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\temp\DIV55
c:\temp\DIV55\xDb.log
c:\temp\tn3
c:\windows\etufijos.dl
c:\windows\mozaq.exe
c:\windows\subo.inf
c:\windows\system32\bin
c:\windows\system32\drivers\npf.sys
c:\windows\system32\ki3
c:\windows\system32\kuwopo._sy
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\tmp.reg
c:\windows\system32\uv9
c:\windows\system32\VC
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\yfazovih.pif
c:\windows\uwulep.bat
----- BITS: Possible infected sites -----
hxxp://dna65.fastaccess.com
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF

((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 )))))))))))))))))))))))))))))))
.
2009-10-28 17:28 . 2009-10-28 17:28 -------- d-----w- c:\documents and settings\Alan\Local Settings\Application Data\Threat Expert
2009-10-28 17:19 . 2009-10-08 16:31 767952 ----a-w- c:\windows\BDTSupport.dll
2009-10-28 17:19 . 2009-10-08 16:31 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-10-28 17:19 . 2009-10-08 16:31 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-10-28 17:19 . 2009-10-08 16:31 1636304 ----a-w- c:\windows\PCTBDCore.dll
2009-10-28 17:19 . 2009-10-02 19:19 1152470 ----a-w- c:\windows\UDB.zip
2009-10-28 17:19 . 2008-11-26 17:08 131 ----a-w- c:\windows\IDB.zip
2009-10-28 17:16 . 2009-09-24 13:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-28 17:16 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-28 17:16 . 2009-09-23 21:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-28 17:16 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-10-28 17:16 . 2009-10-28 22:05 -------- d-----w- c:\program files\Spyware Doctor
2009-10-28 17:16 . 2009-10-28 17:20 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-28 17:16 . 2009-10-28 17:16 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-10-28 17:16 . 2009-10-28 17:16 -------- d-----w- c:\documents and settings\Alan\Application Data\PC Tools
2009-10-28 17:04 . 2009-10-28 17:04 -------- d-----w- C:\Combo-fix
2009-10-27 22:57 . 2009-10-27 23:01 111197 ----a-w- C:\MGlogs.zip
2009-10-27 22:57 . 2009-10-27 23:02 -------- d-----w- C:\MGtools
2009-10-27 21:41 . 2009-10-27 22:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-27 21:41 . 2009-10-27 21:45 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-27 02:52 . 2009-10-27 22:17 16750112 ----a-w- c:\documents and settings\Alan\ATT_SST_Installer.exe
2009-10-27 02:27 . 2009-10-27 02:27 -------- d-----w- c:\documents and settings\Alan\Application Data\AVG8
2009-10-27 01:19 . 2009-10-27 01:19 -------- d-----w- c:\program files\AxBx
2009-10-26 23:14 . 2009-10-26 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-26 23:14 . 2009-10-26 23:14 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-26 23:14 . 2009-10-26 23:14 -------- d-----w- c:\documents and settings\Alan\Application Data\SUPERAntiSpyware.com
2009-10-26 23:13 . 2009-10-26 23:13 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-26 01:47 . 2009-10-27 02:06 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2009-10-25 23:17 . 2009-10-25 23:17 -------- d-----w- c:\documents and settings\Alan\Application Data\Malwarebytes
2009-10-25 23:17 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-25 23:16 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-22 21:25 . 2009-10-22 21:25 19 ----a-w- c:\documents and settings\Alan\killbat.bat
2009-10-14 21:34 . 2009-10-14 21:34 -------- d-----w- c:\documents and settings\Alan\Application Data\WebCam Recorder
2009-10-14 21:34 . 2009-10-14 21:34 -------- d-----w- c:\program files\Solent
2009-10-14 21:18 . 2009-10-14 21:18 -------- d-----w- c:\program files\LEDSET
2009-10-14 21:08 . 2007-08-13 19:51 446464 ----a-w- c:\windows\system32\wmvdmoe.dll
2009-10-14 21:08 . 2009-10-14 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\PY_Software
2009-10-14 20:32 . 2008-04-13 17:39 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-10-14 20:32 . 2008-04-13 17:39 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
2009-10-14 20:32 . 2008-04-13 17:46 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2009-10-14 20:32 . 2008-04-13 17:46 10880 ----a-w- c:\windows\system32\dllcache\ndisip.sys
2009-10-14 20:32 . 2008-04-13 17:46 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2009-10-14 20:32 . 2008-04-13 17:46 15232 ----a-w- c:\windows\system32\dllcache\streamip.sys
2009-10-14 20:31 . 2008-04-13 17:46 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2009-10-14 20:31 . 2008-04-13 17:46 11136 ----a-w- c:\windows\system32\dllcache\slip.sys
2009-10-14 20:31 . 2008-04-13 17:46 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-10-14 20:31 . 2008-04-13 17:46 19200 ----a-w- c:\windows\system32\dllcache\wstcodec.sys
2009-10-14 20:31 . 2008-04-13 17:46 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2009-10-14 20:31 . 2008-04-13 17:46 85248 ----a-w- c:\windows\system32\dllcache\nabtsfec.sys
2009-10-14 20:31 . 2008-04-13 17:46 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2009-10-14 20:31 . 2008-04-13 17:46 17024 ----a-w- c:\windows\system32\dllcache\ccdecode.sys
2009-10-14 20:30 . 2008-04-13 23:12 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-10-14 20:30 . 2008-04-13 23:12 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2009-10-14 00:47 . 2009-10-14 00:47 -------- d-----w- c:\documents and settings\Alan\Application Data\Publish Providers
2009-10-14 00:47 . 2009-10-14 00:47 -------- d-----w- c:\documents and settings\Alan\Local Settings\Application Data\Sony
2009-10-14 00:37 . 2009-10-14 00:47 -------- d-----w- c:\documents and settings\Alan\Application Data\Sony
2009-10-14 00:35 . 2009-10-20 16:29 -------- d-----w- c:\program files\Sony
2009-10-14 00:34 . 2009-10-14 00:34 -------- d-----w- c:\program files\Sony Setup
2009-10-12 22:01 . 2009-10-12 22:15 -------- d-----w- c:\program files\PVPXX
2009-10-12 13:12 . 2009-09-23 15:41 26176 ---ha-w- c:\windows\system32\hamachi.sys
2009-10-05 23:20 . 2009-10-05 23:20 -------- d-----w- C:\Sun
2009-10-05 23:04 . 2009-10-05 23:16 -------- d-----w- c:\documents and settings\Alan\.SunDownloadManager
2009-10-04 20:52 . 2009-10-04 20:52 11933 ----a-w- c:\windows\begofyn.com
2009-10-03 18:03 . 2009-10-01 15:29 195440 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-10-28 22:05 . 2008-12-07 03:01 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-28 20:06 . 2008-12-10 00:38 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-10-28 03:15 . 2008-12-06 03:30 -------- d-----w- c:\program files\Unlocker
2009-10-28 03:01 . 2008-12-10 00:21 -------- d-----w- c:\program files\McAfee
2009-10-28 00:01 . 2007-08-02 03:24 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-27 22:26 . 2006-08-25 23:36 -------- d-----w- c:\program files\Common Files\Motive
2009-10-27 22:17 . 2006-08-25 23:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2009-10-27 02:54 . 2006-08-11 03:32 -------- d-----w- c:\program files\Common Files\Jasc Software Inc
2009-10-27 02:51 . 2006-08-11 03:32 -------- d-----w- c:\documents and settings\Alan\Application Data\Jasc Software Inc
2009-10-27 02:33 . 2008-12-06 04:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-27 00:17 . 2007-12-21 19:00 -------- d-----w- c:\program files\Bellsouth
2009-10-26 23:07 . 2006-08-08 07:13 -------- d-----w- c:\program files\WildTangent
2009-10-26 23:06 . 2006-08-08 07:08 -------- d-----w- c:\program files\Dell
2009-10-25 23:17 . 2008-12-06 03:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-24 23:12 . 2008-12-08 22:23 21870 ----a-w- c:\documents and settings\Everybody\Application Data\wklnhst.dat
2009-10-22 21:53 . 2006-08-29 00:43 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent
2009-10-22 21:53 . 2006-08-29 00:44 -------- d-----w- c:\program files\Dell Games
2009-10-22 21:24 . 2008-11-02 02:28 -------- d-----w- c:\program files\Sun
2009-10-22 21:20 . 2006-08-08 07:04 -------- d-----w- c:\program files\Java
2009-10-21 00:55 . 2006-08-22 22:51 29390 ----a-w- c:\documents and settings\Alan\Application Data\wklnhst.dat
2009-10-20 16:25 . 2009-08-17 22:55 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-10-15 03:32 . 2006-08-08 07:17 -------- d-----w- c:\program files\Microsoft Works
2009-10-09 13:29 . 2006-08-08 07:18 -------- d-----w- c:\program files\Microsoft Money 2006
2009-10-04 13:04 . 2006-08-11 03:30 -------- d-----w- c:\program files\Dl_cats
2009-09-23 21:57 . 2009-03-01 17:36 58600 ----a-w- c:\documents and settings\Connor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-16 15:22 . 2008-12-10 00:22 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2008-12-10 00:22 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2008-12-10 00:22 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2008-06-27 12:08 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2008-12-10 00:20 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-16 08:20 . 2009-10-28 17:16 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-09-15 11:20 . 2009-10-28 17:16 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat
2009-09-15 07:12 . 2009-10-28 17:16 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2009-09-15 06:01 . 2009-10-28 17:16 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat
2009-09-11 14:18 . 2008-10-25 00:03 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 23:49 . 2009-09-09 21:46 540 ----a-w- c:\windows\system32\drivers\sthdae.log
2009-09-09 22:26 . 2009-09-09 22:26 -------- d-----w- c:\documents and settings\Alan\Application Data\Blitware
2009-09-09 21:44 . 2006-08-08 07:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-04 21:03 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 00:29 . 2009-09-04 00:29 -------- d-----w- c:\documents and settings\Alan\Application Data\Mael
2009-09-02 12:52 . 2009-09-02 12:52 -------- d-----w- c:\documents and settings\Everybody\Application Data\Datel
2009-09-02 01:00 . 2008-12-14 00:17 58600 ----a-w- c:\documents and settings\Everybody\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-02 00:27 . 2006-08-11 01:50 58600 ----a-w- c:\documents and settings\Alan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-02 00:22 . 2009-09-02 00:22 -------- d-----w- c:\program files\MSBuild
2009-09-02 00:22 . 2009-09-02 00:22 -------- d-----w- c:\program files\Reference Assemblies
2009-09-01 23:47 . 2009-09-01 23:47 -------- d-----w- c:\documents and settings\Alan\Application Data\Datel
2009-08-29 07:36 . 2004-08-10 17:51 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2004-08-10 17:51 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2004-08-10 17:50 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-27 21:05 . 2009-08-27 21:04 34 ----a-w- c:\documents and settings\Connor\jagex_runescape_preferences.dat
2009-08-26 08:00 . 2004-08-10 17:51 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-20 20:09 . 2009-08-20 20:09 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-19 01:01 . 2008-12-10 21:28 34 ----a-w- c:\documents and settings\Everybody\jagex_runescape_preferences.dat
2009-08-07 01:10 . 2009-05-30 19:18 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-07 01:10 . 2009-05-30 19:18 88 --sh--r- c:\windows\system32\3F285D0D6D.sys
2009-08-05 09:01 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2008-10-25 00:03 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2008-10-25 00:03 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2004-08-04 10:00 . 2004-08-10 17:51 94784 --sh--w- c:\windows\twain.dll
2008-04-14 00:12 . 2008-10-25 00:03 551936 --sha-w- c:\windows\system32\oleaut32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{472734EA-242A-422B-ADF8-83D1E48CC825}"= "c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll" [2009-10-08 395216]
[HKEY_CLASSES_ROOT\clsid\{472734ea-242a-422b-adf8-83d1e48cc825}]
[HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{175B7885-28AB-4D18-8773-7A13A99980A4}]
[HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{472734EA-242A-422B-ADF8-83D1E48CC825}"= "c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll" [2009-10-08 395216]
[HKEY_CLASSES_ROOT\clsid\{472734ea-242a-422b-adf8-83d1e48cc825}]
[HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{175B7885-28AB-4D18-8773-7A13A99980A4}]
[HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-28 68856]
"DellSupport-"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-10-13 2000112]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X 86\3\DLCCtime.dll" [2005-09-14 73728]
"lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-08 74672]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 295856]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-04-13 198184]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2000-08-14 32768]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-09-22 1243088]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-12-06 03:18 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Alan^Start Menu^Programs^Startup^Camio Viewer.lnk]
backup=c:\windows\pss\Camio Viewer.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Auto Detect.lnk]
backup=c:\windows\pss\Auto Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"tmproxy"=2 (0x2)
"TmPfw"=2 (0x2)
"Tmntsrv"=2 (0x2)
"PcCtlCom"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\lxczcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcods.exe"=
"c:\\Program Files\\Windows Defender\\MsMpEng.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/28/2009 12:16 PM 207280]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 9:24 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 9:24 PM 74480]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [10/28/2009 12:19 PM 112592]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/9/2008 7:25 PM 210216]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/28/2009 12:16 PM 358600]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 9:24 PM 7408]
S1 Hdaudioo;Hdaudioo; [x]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
*Deregistered* - PCTSDInjDriver32
.
Contents of the 'Scheduled Tasks' folder
2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1258719614-4290492059-3762695196-1011Core.job
- c:\documents and settings\Everybody\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-10 00:37]
2009-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1258719614-4290492059-3762695196-1011UA.job
- c:\documents and settings\Everybody\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-10 00:37]
2009-06-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-10 17:22]
2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-10 17:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.att.net/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: musicmatch.com\online
DPF: {EA7F451B-94DD-4009-A8BF-8F977B0B2696} - hxxp://pbells.broadjump.com/wizlet/StandardInstall/static/controls/WebflowActiveXInstaller_4-2-0.cab
.
- - - - ORPHANS REMOVED - - - -
BHO-{C2875410-9359-471E-8CAE-3DEBC361F14A} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
SharedTaskScheduler-{55e21788-a65f-416c-b71d-8a24db927486} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SSODL-yetawasok-{55e21788-a65f-416c-b71d-8a24db927486} - (no file)

************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-28 17:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtim e.dll,_RunDLLEntry@16????????????????????????????? ?????????????????????????????????????????????????? ?????????????????????????????????????????????????? ??????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
- - - - - - - > 'explorer.exe'(2132)
c:\windows\system32\WININET.dll
c:\program files\Spyware Doctor\pctgmhk.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\lxczcoms.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\combo-fix6337c\CF30780.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\dlcccoms.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\combo-fix6337c\PEV.cfxxe
.
************************************************** ************************
.
Completion time: 2009-10-28 17:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-28 22:11
Pre-Run: 53,365,575,680 bytes free
Post-Run: 54,220,865,536 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 287EF021CA53A9C92F49E108FF7B9959
Attached Files
File Type: txt RootRepeal report 10-28-09 (17-26-14).txt (4.9 KB, 0 views)
File Type: txt Attach.txt (11.7 KB, 2 views)
File Type: txt checkup.txt (894 Bytes, 1 views)
File Type: txt ComboFix.txt (26.1 KB, 2 views)
File Type: log hijackthis.log (12.4 KB, 1 views)

Last edited by Pancake; 3 Weeks Ago at 12:30 AM. Reason: Copied and pasted for better viewing....
Sneakyone is offline   Reply With Quote
Old 3 Weeks Ago   #4
Senior Security Analyst
 
Pancake's Avatar
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 6,863
PC Experience: Elite PC Guru
Default Re: Google redirect virus help!!

You should never run Combofix unless asked to do so.It is a powerful tool...I will look at you log.In the meantime please run this..

Please download Malwarebytes' Anti-Malware from one of these places:
|MG| Malwarebytes Anti-Malware 1.41 Download
http://www.besttechie.net/tools/mbam-setup.exe


Double Click mbam-setup.exe to install the application.
If it will not run make a copy of the MBAM.exe and rename MBAM.exe to xxx.exe and run that.Keep the genuine MBAM.exe as we may need to run that later as is.
* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.

* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
PLEASE NOTE:
If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you after scanning with MBAM. Please temporarily disable such programs or permit them to allow the changes.

Once that Malwarebytes' Anti-Malware is done removing the malware and you have rebooted the computer, browse around and see if you are still having that problem.
__________________
  • An Australian Member of
  • and
My real name is Eddy
Pancake is online now   Reply With Quote
Old 3 Weeks Ago   #5
Bronze Member
 
Sneakyone's Avatar
 
Join Date: Oct 2009
Posts: 11
PC Experience: Very Experienced
Default Re: Google redirect virus help!!

i am very familiar with combo-fix.exe sorry though i will run malwarebytes right now
Sneakyone is offline   Reply With Quote
Old 3 Weeks Ago   #6
Bronze Member
 
Sneakyone's Avatar
 
Join Date: Oct 2009
Posts: 11
PC Experience: Very Experienced
Default Re: Google redirect virus help!!

heres the malwarebytes log:

Malwarebytes' Anti-Malware 1.41
Database version: 3033
Windows 5.1.2600 Service Pack 3
10/28/2009 6:43:29 PM
mbam-log-2009-10-28 (18-43-29).txt
Scan type: Quick Scan
Objects scanned: 117227
Time elapsed: 9 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Sneakyone is offline   Reply With Quote
Old 3 Weeks Ago   #7
Bronze Member
 
Sneakyone's Avatar
 
Join Date: Oct 2009
Posts: 11
PC Experience: Very Experienced
Default Re: Google redirect virus help!!

heres the fresh hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:48:43 PM, on 10/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = AT&T - Home Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\s wg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtim e.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
O4 - HKCU\..\Run: [DellSupport-] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.7.109.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase8942.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1186022855750
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {EA7F451B-94DD-4009-A8BF-8F977B0B2696} - http://pbells.broadjump.com/wizlet/S...ller_4-2-0.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
--
End of file - 12826 bytes
Sneakyone is offline   Reply With Quote

Reply

Bookmarks

Tags
google, google redirect virus, redirect, virus
Similar discussions...
Thread Thread Starter Forum Replies Last Post
Pending: Google Redirect vegaman Spyware / AdWare 1 09-17-2009 04:23 PM
Pending: Google Redirect Virus WJennings [Pending] HJT Logs 5 09-09-2009 05:49 AM
Fixed: The Google Redirect Virus korsondo [Fixed] Hijackthis! Logs 31 09-04-2009 12:13 AM
Fixed: Google redirect tenlarn [Fixed] Hijackthis! Logs 10 10-10-2008 10:38 PM
Google Redirect??????????? sbuxman Windows XP/2000 2 02-11-2008 12:36 PM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 09:15 PM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2