Help!

Google Hijack

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs RSS
Next:  MS .NET Framework update KB963707  
Author Message
doog15



Joined: Jun 25, 2009
Posts: 6



PostPosted: Thu Jun 25, 2009 5:21 pm    Post subject: Google Hijack

I have been having this problem for the past few days and I don't know how it happen. I scaned with AVG but it found nothing.

EDIT: I'm sorry but i had to edit because I didn't copy the from notepad right.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:32:05 PM, on 6/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wudfhost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_U...mp;c=Q1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN...&c=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN...&c=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN...&c=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_U...mp;c=Q1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN...&c=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/clien...uweb_si
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B31FC12-94FA-4A6B-8050-3C618192F790}: NameServer = 68.94.156.1 68.94.157.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

--
End of file - 7276 bytes
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Thu Jun 25, 2009 9:12 pm    Post subject:

Welcome to Lockergnome.

No problem with the edit. I assume it's because of the word wrap issue? If that's the case, thanks for fixing it up. Some users just post their logs without reviewing it one more time and leave it like that. If the log file has lines jumping all over the place it will slow us down when we try to analyze the logs Sad

If you haven't ran Malwarebytes' yet, please do so below. Otherwise, skip that step and proceed with the HijackThis fix and ComboFix scan.
Back to top
AIM Address Yahoo Messenger
doog15



Joined: Jun 25, 2009
Posts: 6



PostPosted: Fri Jun 26, 2009 2:50 am    Post subject:

Sorry you kinda lost me. In Malwarebytes, Do you want me to click Remove Selected (even on things like Registry) then post a log?
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Fri Jun 26, 2009 6:40 pm    Post subject:

I'm not sure if you ran Malwarebytes' yet. But yes, either way, if you haven't done so already, make sure you tell it to remove everything it finds (including registry entries). Post that log here when ready.

I will also need the ComboFix log once the scan is completed.
Back to top
AIM Address Yahoo Messenger
doog15



Joined: Jun 25, 2009
Posts: 6



PostPosted: Fri Jun 26, 2009 9:12 pm    Post subject:

Malwarebytes and combofix logs

Malwarebytes' Anti-Malware 1.38
Database version: 2335
Windows 5.1.2600 Service Pack 2

6/26/2009 7:56:43 PM
mbam-log-2009-06-26 (19-56-42).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 391706
Time elapsed: 3 hour(s), 22 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
c:\documents and settings\gamexprt.YOUR-F78BF48CE2.000\Application Data\searchtoolbarcorp (Adware.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\gamexprt.your-f78bf48ce2.000\application data\searchtoolbarcorp\Toolbar Vision (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec (Stolen.data) -> Delete on reboot.

Files Infected:
c:\WINDOWS\Temp\132F.tmp (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\1510.tmp (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\CA3.tmp (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\CA4.tmp (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\documents and settings\gamexprt.your-f78bf48ce2.000\application data\searchtoolbarcorp\toolbar vision\PageHistory.txt (Adware.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\gamexprt.your-f78bf48ce2.000\application data\searchtoolbarcorp\toolbar vision\WebHistory.txt (Adware.Agent) -> Quarantined and deleted successfully.
c:\windows\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
c:\windows\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
c:\documents and settings\gamexprt.familycom\application data\Sskknwrd.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sdra64.exe (Trojan.FakeAlert) -> Delete on reboot.


ComboFix 09-06-26.02 - Compaq_Owner 06/26/2009 20:51.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.104 [GMT -4:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Internet Explorer\msimg32.dll
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\dh.ini
c:\windows\Downloaded Program Files\ijjiPreNotify2.exe
c:\windows\IA
c:\windows\jestertb.dll
c:\windows\msagent\chars\kbamc.bak1
c:\windows\msagent\chars\kbamc.ini
c:\windows\system32\drivers\SKYNETibgvdjns.sys
c:\windows\system32\SKYNETfcpsyjbd.dll
c:\windows\system32\SKYNETgskltowq.dll
c:\windows\system32\SKYNETtviwmrqp.dat
c:\windows\system32\SKYNETupkkoori.dat
D:\Autorun.inf
D:\Desktop.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETsvpavhos


((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-06-27 )))))))))))))))))))))))))))))))
.

2009-06-26 02:52 . 2009-06-26 02:52 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2009-06-26 02:52 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-26 02:52 . 2009-06-26 02:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-26 02:52 . 2009-06-26 02:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-26 02:52 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-25 20:59 . 2009-06-25 20:59 -------- d-----w- c:\program files\Trend Micro
2009-06-21 05:59 . 2009-06-21 06:00 -------- d-----w- c:\program files\audacity-win-unicode-1.3.7
2009-06-11 23:31 . 2009-06-11 23:31 -------- d-----w- c:\program files\Opera 10 Beta
2009-06-11 14:07 . 2009-06-11 14:07 -------- d-----w- c:\program files\NRF
2009-06-05 17:18 . 2009-06-05 17:18 -------- d-----w- c:\program files\att-prt22
2009-06-05 17:17 . 2009-06-05 17:18 -------- d-----w- c:\program files\Common Files\Motive
2009-06-05 17:17 . 2009-06-05 17:18 -------- d-----w- c:\program files\ATT-PRT22-WISE
2009-05-31 12:15 . 2009-05-31 12:15 174664 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-31 12:12 . 2009-05-31 12:12 -------- d-----w- c:\windows\system32\XPSViewer
2009-05-31 12:08 . 2006-06-29 17:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-05-30 09:37 . 2009-05-30 09:38 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\eMule
2009-05-30 09:37 . 2009-05-30 09:38 -------- d-----w- c:\program files\eMule
2009-05-30 09:14 . 2009-05-30 09:14 0 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2009-05-30 09:04 . 2009-05-30 09:23 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\FrostWire
2009-05-30 09:02 . 2009-05-30 09:03 -------- d-----w- c:\program files\AskBarDis
2009-05-30 08:42 . 2009-05-30 09:29 -------- d-----w- c:\program files\New Folder
2009-05-30 08:40 . 2009-05-30 09:30 -------- d-----w- c:\program files\Incomplete
2009-05-30 00:28 . 2009-06-06 08:43 105 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\RenPy\persistent\act1.katawa-shoujo.com
2009-05-29 10:39 . 2009-05-29 10:39 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\RenPy
2009-05-29 10:36 . 2009-05-30 11:39 -------- d-----w- c:\program files\Katawa Shoujo Act 1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 00:03 . 2008-03-17 20:40 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-25 01:19 . 2009-04-10 08:52 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Audacity
2009-06-24 09:59 . 2009-04-08 06:08 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\uTorrent
2009-06-13 18:05 . 2009-06-13 18:05 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-06-05 17:17 . 2005-02-26 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2009-06-04 02:16 . 2005-02-26 22:08 -------- d-----w- c:\program files\Easy Internet signup
2009-05-31 12:37 . 2009-04-05 09:36 38816 ----a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-30 09:33 . 2009-04-08 07:09 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\LimeWire
2009-05-14 00:35 . 2009-05-14 00:25 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\DAEMON Tools Lite
2009-05-14 00:32 . 2009-05-14 00:32 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-05-14 00:32 . 2009-05-14 00:32 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-05-14 00:32 . 2009-05-14 00:32 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-05-14 00:26 . 2009-05-14 00:26 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-07 15:44 . 2004-08-04 18:00 344064 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 08:20 . 2009-05-07 07:59 -------- d-----w- c:\documents and settings\All Users\Application Data\RFA_Backups
2009-05-02 06:42 . 2009-05-02 06:20 -------- d-----w- c:\program files\Realtek AC97
2009-05-01 20:50 . 2009-04-06 09:32 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-01 20:50 . 2009-04-06 09:32 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-01 20:50 . 2009-04-06 09:32 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-01 20:49 . 2009-04-06 09:32 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-01 09:26 . 2009-05-01 09:26 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\AdobeUM
2009-04-29 04:56 . 2004-08-04 18:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 18:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-22 02:40 . 2009-04-22 02:40 26582 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{B8672913-A995-4C4A-AA0F-DE5D83549FA0}\Project64.exe1_B797CA9398E846EAA83635BE088145CE.exe
2009-04-22 02:40 . 2009-04-22 02:40 26582 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{B8672913-A995-4C4A-AA0F-DE5D83549FA0}\Project64.exe_7FDC4F26BA404AD0BE57AC3D01EAD3E0.exe
2009-04-22 02:40 . 2009-04-22 02:40 25214 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{B8672913-A995-4C4A-AA0F-DE5D83549FA0}\UNINST_Uninstall_P_156F75ED3AC34F899F4E49E7BCF228E8.exe
2009-04-22 02:40 . 2009-04-22 02:40 24942 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{B8672913-A995-4C4A-AA0F-DE5D83549FA0}\Project64.chm_FC8E88CE0FC0416A8DCED87702F81733.exe
2009-04-22 02:40 . 2009-04-22 02:40 1150 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{B8672913-A995-4C4A-AA0F-DE5D83549FA0}\evoodoo.cpl_218B97DFEF7B43DBB14A0C45C482ABEE.exe
2009-04-22 02:40 . 2009-04-22 02:40 24942 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{B8672913-A995-4C4A-AA0F-DE5D83549FA0}\PJgameFAQ.chm_4CFA8D737AA64B3EB46FBE36D300F34E.exe
2009-04-22 02:40 . 2009-04-22 02:40 26582 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{B8672913-A995-4C4A-AA0F-DE5D83549FA0}\ARPPRODUCTICON.exe
2009-04-17 09:58 . 2004-08-04 18:00 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2004-08-04 18:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-08 06:51 . 2009-04-08 06:52 410984 -c--a-w- c:\windows\system32\deploytk.dll
2009-04-08 06:46 . 2009-04-08 06:46 152576 -c--a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-06 11:41 . 2009-04-06 11:41 15240 -c--a-w- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\IdentityCRL\prod\ppcrlconfig.dll
2009-03-21 05:58 . 2009-03-21 05:58 0 -c--a-w- c:\program files\WMHelper.log
2007-08-27 19:56 . 2007-08-27 19:56 1089440 -c--a-w- c:\program files\msidcrl40.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-09 02:08 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-08 148888]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-10-14 278528]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-13 98304]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-01 1947928]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-30 88363]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2005-01-24 544768]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Compaq Connections.lnk - c:\program files\Compaq Connections\6750491\Program\Compaq Connections.exe [2005-2-26 45056]
Run Google Web Accelerator.lnk - c:\program files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-7-9 1134592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-01 20:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\Program Files\\eMule\\emule.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/6/2009 5:32 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/6/2009 5:32 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/13/2009 8:50 AM 298776]
.
Contents of the 'Scheduled Tasks' folder

2009-06-04 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-08-13 16:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_U...mp;c=Q1
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN...&c=
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN...&c=
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-26 21:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-06-27 21:06
ComboFix-quarantined-files.txt 2009-06-27 01:06

Pre-Run: 7,708,467,200 bytes free
Post-Run: 11,559,968,768 bytes free

172 --- E O F --- 2009-06-11 07:04
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Sat Jun 27, 2009 5:39 pm    Post subject:

Download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.

Still getting redirects?
Back to top
AIM Address Yahoo Messenger
doog15



Joined: Jun 25, 2009
Posts: 6



PostPosted: Sat Jun 27, 2009 7:05 pm    Post subject:

so far I clicked about 12 google links and didn't get any redirects.


GooredFix v1.92 by jpshortstuff
Log created at 19:03 on 27/06/2009 running Option #1 (Compaq_Owner)
Firefox version [Unable to determine]

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Sun Jun 28, 2009 6:15 pm    Post subject:

Good job. Your log is clean.

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If none, go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go.
Back to top
AIM Address Yahoo Messenger
doog15



Joined: Jun 25, 2009
Posts: 6



PostPosted: Sun Jun 28, 2009 8:41 pm    Post subject:

Not having anymore redirects problems. Thank you for the help

edit: agh but now I cant hear any sound from my computer, but I can still hear MP3s and videos on my computer.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Mon Jun 29, 2009 7:12 pm    Post subject:

What kind of sounds? Like Windows starting up and shutting down? Go to Start > Control Panel > Sounds and Audio Devices. Go to the Sounds tab and make sure they have a sound file assigned to those entries that you said have no more sound.

If you still need help with this, try asking in the Windows board to get this problem fixed.
Back to top
AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum