Http:// redirect

#1 maxnix


Posted 26 February 2009 - 11:39 PM

Everytime I click a link in google or anything else I get redirected to an ad page somewhere else. I've run spybot and avira and live center, hjt, ccleaner, housecall...It keeps coming back.
Can anyone help me?


here is my DDS:

DDS (Ver_09-02-01.01) - NTFSx86
Run by Jane at 23:16:54.68 on Thu 02/26/2009
Internet Explorer: 7.0.5730.13

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mWinlogon: Userinit=c:\windows\system32\Userinit.exe
BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_5_7_0.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_5_7_0.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Google Update] "c:\documents and settings\jane\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: z57.com\www
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} - hxxp://www2.stlu.com/plugins/Plugin0501.0105/streetnoagent7.cab
DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} - hxxp://msx.mlxchange.com/Control/FileCruiser.cab
DPF: {16FD824B-8E7B-11D2-9855-00802962956C} - hxxp://msx.mlxchange.com/Control/Specfile.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} - hxxp://org.mlxchange.com/Control/SISC.cab
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} - hxxp://org.mlxchange.com/Control/MultiSelectComboBox.cab
DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1218227891312
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220101258359
DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} - hxxp://org.mlxchange.com/Control/MLXClientUtils.cab
DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} - hxxp://msx.mlxchange.com/Control/LiteGrid.cab
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://org.mlxchange.com/
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {B198A72B-B4C3-42B5-B8DA-B364E76429AA} - hxxp://org.mlxchange.com/Control/WebDog.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} - hxxp://msx.mlxchange.com/Control/AspCustomCtrls.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {9914B4D2-F63E-48C1-ABA6-635153835DAC} - No File
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\awtrSlli
LSA: Notification Packages = :\windows\system32\srr scecli

============= SERVICES / DRIVERS ===============

=============== Created Last 30 ================

2009-02-26 19:31 <DIR> --d----- c:\docume~1\jane\applic~1\Windows Search
2009-02-26 18:51 0 a------- c:\windows\system32\drivers\nfr.dll.mpref
2009-02-26 11:51 664 a------- c:\windows\system32\d3d9caps.dat
2009-02-26 10:36 <DIR> --d----- c:\windows\system32\XPSViewer
2009-02-26 10:34 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-26 10:34 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-02-26 10:34 117,760 -------- c:\windows\system32\prntvpt.dll
2009-02-26 10:34 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-02-26 10:34 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-26 10:34 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-02-26 10:34 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-02-26 10:34 <DIR> --d----- C:\6a32a0545c94283daae921
2009-02-26 10:21 <DIR> --d----- c:\docume~1\jane\applic~1\Windows Desktop Search
2009-02-26 10:18 <DIR> --d----- c:\windows\system32\GroupPolicy
2009-02-26 10:18 <DIR> --d----- c:\program files\Windows Desktop Search
2009-02-26 10:17 98,304 -c------ c:\windows\system32\dllcache\nlhtml.dll
2009-02-26 10:17 29,696 -c------ c:\windows\system32\dllcache\mimefilt.dll
2009-02-26 10:16 192,000 -c------ c:\windows\system32\dllcache\offfilt.dll
2009-02-26 09:17 <DIR> --d----- c:\program files\Microsoft
2009-02-26 09:15 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-25 09:18 <DIR> --d----- c:\program files\Avira
2009-02-25 09:18 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-02-25 08:18 <DIR> --d----- c:\program files\common files\Windows Live
2009-02-25 08:10 5,760 -------- c:\windows\system32\3.tmp
2009-02-25 07:34 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-02-25 00:45 <DIR> --d----- c:\windows\{7F7635FC-B887-49FA-8526-094724C01A6E}
2009-02-25 00:21 <DIR> --d----- c:\program files\Linksys
2009-02-24 19:48 14,592 ac------ c:\windows\system32\dllcache\kbdhid.sys
2009-02-24 19:48 14,592 a------- c:\windows\system32\drivers\kbdhid.sys
2009-02-18 16:16 0 a------- c:\windows\system32\drivers\nfr.dll.gpref
2009-02-18 09:33 0 a------- c:\windows\system32\drivers\nfr.dll.assembly
2009-02-18 09:33 16,900 a------- c:\windows\system32\drivers\nfr.dll

==================== Find3M ====================

2009-02-19 12:36 150,329 a------- c:\windows\hpwins05.dat
2009-01-26 14:21 442,404 a------- c:\windows\system32\GeacView.dll
2008-12-20 18:15 826,368 a------- c:\windows\system32\wininet.dll
2008-01-08 11:32 557,056 a------- c:\documents and settings\jane\GoToAssist_phone__317_en.exe
2008-01-03 21:23 630,784 a------- c:\documents and settings\jane\GoToAssist_chat2way__317_en.exe
2008-08-30 14:21 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008083020080831\index.dat

============= FINISH: 23:18:08.75 ===============


==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
Avira AntiVir Personal - Free Antivirus
Banctec Service Agreement
Business Contact Manager for Outlook 2003
CCleaner (remove only)
Conexant SmartHSFi V.9x 56K DF PCI Modem
Dell Digital Jukebox Driver
Dell Networking Guide
Dell Solution Center
Dell Support Center (Support Software)
Digital Line Detect
doPDF 6.1 printer
Google Chrome
Google Toolbar for Internet Explorer
Google Updater
Help and Support Customization
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
HP Customer Participation Program 8.0
HP Driver Diagnostics
HP Imaging Device Functions 8.0
HP Memories Disc
HP OCR Software 8.0
hp officejet 6100 series
HP Officejet Pro All-In-One Series
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
HP Photo and Imaging 2.0 - hp officejet 6100 series
HP Photosmart Essential
HP Solution Center 8.0
HP Update
Intel® Extreme Graphics Driver
Intel® PRO Network Connections Drivers
Intel® PROSet
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Java™ 6 Update 12
Java™ 6 Update 7
Learn.com Player (Uninstall Only)
Linksys Dual-Band Wireless-N USB Network Adapter
Linksys Dual Band Wireless-N Notebook Adapter
Linksys WUSB600N Dual-Band Wireless-N USB Network Adapter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Default Manager
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Small Business Edition 2003
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MLS Passport
Modem Helper
MSN Messenger 7.0
MSN Toolbar
MSN Toolbar(01.02.5000.1021)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Norton Security Scan
Panda ActiveScan 2.0
Photo Story 3 for Windows
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Sophos Anti-Rootkit 1.3.1
Spybot - Search & Destroy
Spyware Doctor 6.0
Unlocker 1.8.7
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
Yahoo! Anti-Spy
Yahoo! Toolbar

==== End Of File ===========================

#2 shelf life

shelf life

Posted 06 March 2009 - 04:54 PM

hi maxnix,

Sorry for delay, no shortage of posters. If you still need help you can do this:

Please download Malwarebytes' Anti-Malware (MBAM) to your desktop:


* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click **Remove Selected.**
*A restart may be required to finish the clean up process*
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

please post the MBAM log in reply

How Can I Reduce My Risk to Malware?

