Help!

Hit with the google hijack as well

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs RSS
Next:  Advocates of Gun Rights Are Poised for a Victory  
Author Message
ganglion5



Joined: Nov 30, 2008
Posts: 18



PostPosted: Wed May 20, 2009 1:28 pm    Post subject: Hit with the google hijack as well

I think I got hit with a google hijack, along with many others. here's my hijack log. I can't even install avg after i was hit.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:42 AM, on 5/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify2?&.src=ym
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\IPSBHO.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://mweb.winthrop.org
O16 - DPF: {5EDEA7DC-96C2-4F53-8810-31CF8A0946C2} (iFly NetPlayers ActiveX 1.0) - http://twong88.homedns.org:1026/iFlyNPSX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/cli.../wuweb_
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {A7B17C34-D894-11D3-AE37-0050DA39FE5C} (WebClientInstall Class) - https://mweb.winthrop.org/magicweb/cabs/WebClientInstall.cab
O16 - DPF: {B37D8AB5-3A6C-4219-BC46-93B26EF0E53D} (ActiveFormX Control) - http://211.174.251.155/XViewer.cab
O16 - DPF: {FFA315A3-20D3-11CF-8FDD-943611C10000} (Ter Control) - https://netaccess2.smshealthconx.net/NTAP062-NTAP-HTM/webPrint.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5BEB1D3-59E4-46FA-9449-D5C991671BFC}: NameServer = 85.255.112.127,85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.127,85.255.112.196
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.127,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.127,85.255.112.196
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--
End of file - 5666 bytes
Back to top
ganglion5



Joined: Nov 30, 2008
Posts: 18



PostPosted: Fri May 22, 2009 11:52 am    Post subject:

Hi, I was wondering if anyone can help me out on this problem. I'm trying to run different antiviral softwares and it's not fixing the problem. Your help is greatly appreciated.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Fri May 22, 2009 10:16 pm    Post subject:

Please print the below instructions or copy them to Notepad. Make sure to work through the fixes in the order mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

Download Malwarebytes ' Anti-Malware at http://www.besttechie.net/tools/mbam-setup.exe or http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html Double-click on mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform Full Scan, then click Scan.
* The scan may take some time to finish, so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to restart (see Extra Note below).
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy & paste the entire report into your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you checked the last one:

O17 - HKLM\System\CCS\Services\Tcpip\..\{C5BEB1D3-59E4-46FA-9449-D5C991671BFC}: NameServer = 85.255.112.127,85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.127,85.255.112.196
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.127,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.127,85.255.112.196


Go to http://www.bleepingcomputer.com/combofix/how-to-use-combofix and follow the instructions on how to install the Recovery Console and run ComboFix. Go through all the steps until posting the log part. Post the combofix log here.
Back to top
AIM Address Yahoo Messenger
ganglion5



Joined: Nov 30, 2008
Posts: 18



PostPosted: Tue May 26, 2009 12:24 pm    Post subject:

I don't know if this is part of the virus. For some reason, I can't even run Malwarebytes. It seems to install ok, but when it comes to launching it, it doesn't work. I uninstalled norton and the service pack 3 in the interim. Malwarebytes still doesn't run. Should I proceed with the hijackthis delete that you mentioned?
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Thu May 28, 2009 12:43 pm    Post subject:

Rename C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe to something like MBganglion5.exe instead. Then double click on that renamed file and see if you can run Malwarebytes' and post the log here.

Yes, run HijackThis regardless if Malwarebytes' ran or not. Don't forget ComboFix also.
Back to top
AIM Address Yahoo Messenger
ganglion5



Joined: Nov 30, 2008
Posts: 18



PostPosted: Thu May 28, 2009 1:42 pm    Post subject:

OK, I had to fun combofix first, then I was able to finally run malwarebytes. (of course, I reran combofix a second time after malwarebytes). So here are the logs. Thanks again.

>>>>>>>>Malwarebytes<<<<<<<<<<<

Malwarebytes' Anti-Malware 1.37
Database version: 2186
Windows 5.1.2600 Service Pack 2

5/28/2009 1:33:11 PM
mbam-log-2009-05-28 (13-33-11).txt

Scan type: Full Scan (C:\|)
Objects scanned: 141545
Time elapsed: 34 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Qoobox\quarantine\C\DOCUME~1\Client\LOCALS~1\Temp\tmp1.tmp.vir (Trojan.Alureon) -> Quarantined and deleted successfully.



>>>>>>>Now for the combofix log<<<<<<<<

ComboFix 09-05-26.05 - Client1 05/28/2009 13:36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.257 [GMT -4:00]
Running from: c:\documents and settings\Client\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\rrfw.sys

.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-28 )))))))))))))))))))))))))))))))
.

2009-05-28 07:00 . 2009-05-28 07:00 -------- d-----w c:\windows\LastGood
2009-05-27 22:08 . 2009-05-27 22:08 3371383 ----a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-27 22:07 . 2009-05-27 22:07 -------- d-----w c:\documents and settings\Client\Application Data\Malwarebytes
2009-05-27 20:07 . 2009-05-27 20:38 -------- d-----w c:\windows\system32\CatRoot_bak
2009-05-26 20:10 . 2009-05-27 22:08 -------- d-----w C:\Malwarebytes' Anti-Malware
2009-05-26 14:48 . 2009-05-26 17:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 14:48 . 2009-05-26 17:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 14:48 . 2009-05-26 14:48 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-26 14:48 . 2009-05-26 20:06 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-26 14:12 . 2009-05-26 14:15 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-19 14:46 . 2009-05-19 14:46 -------- d-----w c:\program files\Trend Micro
2009-05-18 17:03 . 2009-05-18 17:48 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-05-18 17:03 . 2009-05-18 17:03 -------- d-----w c:\program files\AVG
2009-05-14 20:02 . 2009-05-26 15:32 -------- d-----w c:\windows\system32\scripting
2009-05-14 20:02 . 2009-05-26 15:32 -------- d-----w c:\windows\l2schemas
2009-05-14 20:02 . 2009-05-26 15:32 -------- d-----w c:\windows\system32\en
2009-05-14 19:53 . 2007-06-13 10:23 1033216 ----a-w c:\windows\system32\dllcache\explorer.exe
2009-05-13 22:12 . 2009-05-13 22:12 -------- d-----w c:\documents and settings\Client\Local Settings\Application Data\Symantec
2009-05-12 07:00 . 2009-05-12 07:00 -------- d-----w c:\windows\system32\KB905474
2009-05-12 07:00 . 2009-03-11 02:26 1403264 ----a-w c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-05-12 07:00 . 2009-03-11 02:18 453512 ----a-w c:\windows\system32\KB905474\wgasetup.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 15:30 . 2002-09-07 02:16 87383 ----a-w c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2009-05-26 15:05 . 2009-01-29 19:54 -------- d-----w c:\program files\Norton AntiVirus
2009-05-26 15:05 . 2009-01-29 19:44 -------- d-----w c:\documents and settings\All Users\Application Data\Norton
2009-05-26 15:04 . 2002-10-08 14:18 -------- d-----w c:\program files\Symantec
2009-05-26 15:04 . 2002-10-08 14:18 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-05-18 18:10 . 2009-01-29 19:44 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-04-16 18:24 . 2002-10-08 16:54 -------- d-----w c:\program files\Common Files\Adobe
2009-04-14 15:05 . 2009-04-14 15:05 0 ----a-w c:\windows\nsreg.dat
2009-03-06 14:44 . 2002-10-08 13:57 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-01-21 20:16 826368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((( SnapShot.DeleteThis@2009-05-27_22.04.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2002-09-07 02:17 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
- 2002-09-07 02:17 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2002-03-27 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-03-27 106496]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-01-31 81920]
"Tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2001-11-07 1519616]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"MIDI1"= SYNCOR11.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

S?4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [5/26/2009 10:48 AM 40160]
S3 qic157;qic157;c:\windows\system32\drivers\qic157.sys [5/14/2009 3:53 PM 6016]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [7/1/2003 4:15 PM 72576]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MBAMSWISSARMY
.
Contents of the 'Scheduled Tasks' folder

2009-05-27 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]
.
.
------- Supplementary Scan -------
.
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: care360.com\portal
Trusted Zone: winthrop.org\mweb
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5EDEA7DC-96C2-4F53-8810-31CF8A0946C2} - hxxp://twong88.homedns.org:1026/iFlyNPSX.CAB
DPF: {A7B17C34-D894-11D3-AE37-0050DA39FE5C} - hxxps://mweb.winthrop.org/magicweb/cabs/WebClientInstall.cab
DPF: {B37D8AB5-3A6C-4219-BC46-93B26EF0E53D} - hxxp://211.174.251.155/XViewer.cab
DPF: {FFA315A3-20D3-11CF-8FDD-943611C10000} - hxxps://netaccess2.smshealthconx.net/NTAP062-NTAP-HTM/webPrint.cab
FF - ProfilePath - c:\documents and settings\Client\Application Data\Mozilla\Firefox\Profiles\4t9uqjhp.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-28 13:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-05-28 13:41
ComboFix-quarantined-files.txt 2009-05-28 17:40
ComboFix2.txt 2009-05-27 22:07

Pre-Run: 19,581,054,976 bytes free
Post-Run: 19,576,864,768 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
118 --- E O F --- 2009-05-28 07:01
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Fri May 29, 2009 3:05 pm    Post subject:

Download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.

Are you still getting redirected now?
Back to top
AIM Address Yahoo Messenger
ganglion5



Joined: Nov 30, 2008
Posts: 18



PostPosted: Mon Jun 01, 2009 10:34 am    Post subject:

GooredFix v1.92 by jpshortstuff
Log created at 10:46 on 01/06/2009 running Option #1 (Client1)
Firefox version 3.0.8 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"
Back to top
ganglion5



Joined: Nov 30, 2008
Posts: 18



PostPosted: Mon Jun 01, 2009 10:35 am    Post subject:

No, no more redirection. So far so good. Thanks so much.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Sun Jun 07, 2009 11:46 am    Post subject:

Good job. Your log is clean.

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Go to Start->Run, copy/paste in combofix /u and hit OK to remove it.

You should be set to go.

Topic locked since issue is resolved.
Back to top
AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum