Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

All searchengines hijacked - redirected to Scour, Happili, etc...


  • This topic is locked This topic is locked
4 replies to this topic

#1 mikebellman

mikebellman

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:54 PM

Posted 29 December 2010 - 06:23 PM

Both IE8 & Firefox 3 are hijacked when clicking a search result.
I have blocked most of the redirection by installing "Browser Hijack Real\aliator 4.5" and installling MVPS.org's HOSTS file.

However, I still can't pull off a search.
Malwarebytes will not load
Avast loads & runs clean. TDSS killer ran, found one infection, but I am still infected.
Rootkit buster does not kill it
AWIL, SAS-Super Antispyware standalone apps run and scan, but come up clean.

Here is the DDS.txt

DDS (Ver_10-12-12.02) - NTFSx86
Run by New at 17:00:36.73 on Wed 12/29/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.480 [GMT -6:00]

AV: avast! Internet Security *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\afwServ.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\New\My Documents\Downloads\Defogger.exe
C:\Documents and Settings\New\Desktop\Virus Removal\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = localhost;*.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [SetDefPrt] c:\program files\brother\brmfl06b\BrStDvPt.exe
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [BHR] c:\program files\zamaan's software\browser hijack retaliator 4.5\BHR.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\new\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\datavi~1.lnk - c:\program files\common files\dataviz\DvzIncMsgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\backWeb-7288971.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1284772166505
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\new\applic~1\mozilla\firefox\profiles\b9oy7k6q.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\Ext

============= SERVICES / DRIVERS ===============

R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [2010-8-17 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [2010-8-17 190416]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [2010-8-17 99792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2010-8-17 340048]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-17 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-17 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
R2 avast! Firewall;avast! Firewall;c:\program files\alwil software\avast5\afwServ.exe [2010-8-17 119200]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\new\locals~1\temp\sas_selfextract\sasdifsv.sys --> c:\docume~1\new\locals~1\temp\sas_selfextract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\new\locals~1\temp\sas_selfextract\saskutil.sys --> c:\docume~1\new\locals~1\temp\sas_selfextract\SASKUTIL.SYS [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-12 136176]

=============== Created Last 30 ================

2010-12-29 22:51:29 77912 ----a-w- c:\windows\system32\drivers\klmdb.sys
2010-12-29 22:51:29 75264 ----a-w- c:\windows\system32\drivers\tsk93.tmp
2010-12-29 22:18:32 98816 ----a-w- c:\windows\sed.exe
2010-12-29 22:18:32 89088 ----a-w- c:\windows\MBR.exe
2010-12-29 22:18:32 256512 ----a-w- c:\windows\PEV.exe
2010-12-29 22:18:32 161792 ----a-w- c:\windows\SWREG.exe
2010-12-29 21:32:25 -------- d-----w- c:\windows\system32\PreInstall
2010-12-29 21:32:23 -------- d--h--w- c:\windows\$hf_mig$
2010-12-29 21:16:54 -------- d-----w- c:\docume~1\new\applic~1\abelhadigital.com
2010-12-29 21:16:54 -------- d-----w- c:\docume~1\alluse~1\applic~1\abelhadigital.com
2010-12-29 21:16:51 -------- d-----w- c:\program files\HostsMan
2010-12-29 21:08:40 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-29 21:08:39 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-12-29 21:08:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-29 21:08:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-29 21:00:04 -------- d-----w- c:\docume~1\new\locals~1\applic~1\Mozilla
2010-12-29 21:00:01 553696 ----a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2010-12-29 20:16:33 161296 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-12-29 20:13:51 -------- d-----w- c:\windows\system32\SoftwareDistribution
2010-12-29 20:06:14 -------- d-----w- c:\docume~1\new\applic~1\SUPERAntiSpyware.com
2010-12-29 20:06:14 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-12-18 11:34:10 -------- d-----w- c:\program files\iPod
2010-12-15 03:32:41 244024 ----a-w- c:\windows\system32\MSFLXGRD.OCX
2010-12-15 03:32:41 203976 ----a-w- c:\windows\system32\richtx32.ocx
2010-12-15 03:32:41 132880 ----a-w- c:\windows\system32\MSINET.OCX
2010-12-15 03:32:40 570128 ----a-w- c:\program files\common files\microsoft shared\dao\DAO350.DLL
2010-12-15 03:32:40 3584 ----a-w- c:\program files\common files\microsoft shared\dao\comcat.dll
2010-12-15 03:32:40 1338880 ----a-w- c:\program files\common files\microsoft shared\dao\shdocvw.dll
2010-12-15 03:32:39 -------- d-----w- c:\program files\Zamaan's Software
2010-12-15 02:49:57 -------- d-----w- C:\Downloads
2010-12-15 02:49:42 -------- d-----w- c:\program files\VS Revo Group
2010-12-12 13:22:25 -------- d-----w- c:\docume~1\new\locals~1\applic~1\Google
2010-12-12 13:22:05 -------- d-----w- c:\program files\common files\xing shared
2010-12-12 13:21:52 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-12 13:21:52 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-12-12 10:56:29 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2010-12-12 10:56:29 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2010-12-12 10:56:29 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2010-12-12 10:56:29 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2010-12-12 10:56:29 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2010-12-12 10:56:29 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2010-12-12 10:56:29 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2010-11-29 23:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts

==================== Find3M ====================


============= FINISH: 17:01:02.56 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 rigacci

rigacci

    Fiorentino


  • Members
  • 2,604 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 January 2011 - 07:43 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review your topic an do their best to resolve your issues.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


Thanks.

DR

#3 mikebellman

mikebellman
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:54 PM

Posted 09 February 2011 - 11:03 AM

The computer is running fine overall except she can not perform ANY searches. She is in a RURAL location so I have to hoof it down here to perform additional scans etc.

Attached Files



#4 sundavis

sundavis

  • Malware Response Team
  • 2,708 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:54 PM

Posted 10 February 2011 - 06:12 PM

Hi mikebellman,



Welcome to BleepingComputer Virus, Trojan, Spyware, and Malware Removal Logs Forum. :welcome:
My name is sundavis, I will be helping you to deal with your Malware problems today.

Go to Start > Run and copy/paste the following into the Run box and click OK:

C:\Combofix.txt

The Combofix text file should open. Please post the contents of that file in your next reply. After that, please do the following:



Step1

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\TDSSKiller folder). Please copy and paste the contents of that file here.

Step2

  • Please download OTL and save it to your desktop.
  • Double click on the icon on your desktop.
  • Under the Standard Registry box change it to All
  • Click the "Scan All Users" checkbox.
  • Under the Custom Scan box paste the following bolded text:



    /md5start
    explorer.exe
    winlogon.exe
    userinit.exe
    svchost.exe
    /md5stop
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90


  • Click the "Quick Scan" button.
  • The scan should take just a few minutes.
  • OTListIt.txt <-- Will be opened and Extra.txt <-- Will be minimized
  • Copy and paste both logs back here in your next reply.



In your next reply, please post back:

1.ComboFix log
2.TDSSKiller log
3.OTListIt.txt and Extra.txt Thanks

#5 sundavis

sundavis

  • Malware Response Team
  • 2,708 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:54 PM

Posted 15 February 2011 - 02:55 PM

Due to the lack of feedback, this topic is now Closed.

Everyone else please start a new topic in the Malware Removal forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users