also @ TechSpot: Leaked next generation iPhone casing photos validate multiple rumors

TechSpot

[Solved] Redirected in search engine even after reinstal

Discussion in 'Virus and Malware Removal' started by appleybridger, Nov 8, 2010.

Thread Status:
Not open for further replies.
  1. appleybridger Newcomer, in training

    Having trouble with bot cable modem and router.Will do asap.
  2. appleybridger Newcomer, in training

    Hi had to reset router and modem as I trouble accessing internet.Not tried any searches since I did this so don't know if I'm still getting redirected.But IE seems a bit sluggish loading my homepage (Google) and this forums page.

    Heres Combofix log.

    ComboFix 10-11-12.04 - Denis 13/11/2010 12:05:59.2.1 - FAT32x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.445.239 [GMT 0:00]
    Running from: c:\documents and settings\Denis\Desktop\ComboFix.exe
    AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .

    ((((((((((((((((((((((((( Files Created from 2010-10-13 to 2010-11-13 )))))))))))))))))))))))))))))))
    .

    2010-11-10 20:49 . 2010-11-10 20:49 -------- d-----w- C:\_OTL
    2010-11-10 11:06 . 2010-11-10 11:06 -------- d-----w- c:\program files\Common Files\Java
    2010-11-10 11:04 . 2010-11-10 11:04 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2010-11-10 11:04 . 2010-11-10 11:04 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2010-11-10 11:04 . 2010-11-10 11:04 -------- d-----w- c:\program files\Java
    2010-11-10 11:01 . 2010-11-10 11:01 -------- d-----w- c:\program files\Common Files\Adobe
    2010-11-09 14:20 . 2010-11-09 14:20 -------- d-----w- c:\program files\CCleaner
    2010-11-09 14:16 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2010-11-09 14:16 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2010-11-09 14:16 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2010-11-09 14:16 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2010-11-09 14:16 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2010-11-09 14:16 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2010-11-09 14:16 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2010-11-09 14:16 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
    2010-11-09 14:16 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
    2010-11-09 14:16 . 2010-11-09 14:16 -------- d-----w- c:\program files\Alwil Software
    2010-11-09 14:16 . 2010-11-09 14:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
    2010-11-09 14:12 . 2010-04-29 15:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-11-09 14:12 . 2010-11-09 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-11-09 14:12 . 2010-04-29 15:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-11-09 14:12 . 2010-11-09 14:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-11-09 14:08 . 2010-11-09 14:08 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-11-09 14:08 . 2010-11-09 14:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-11-09 14:06 . 2010-11-09 14:06 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
    2010-11-09 14:06 . 2010-11-09 14:06 -------- d-----w- c:\program files\SpywareBlaster
    2010-11-09 14:04 . 2004-08-04 05:00 26496 ----a-w- c:\windows\system32\dllcache\usbstor.sys
    2010-11-09 11:45 . 2010-08-16 08:45 590848 ------w- c:\windows\system32\dllcache\rpcrt4.dll
    2010-11-09 11:44 . 2010-09-18 06:53 974848 ------w- c:\windows\system32\dllcache\mfc42.dll
    2010-11-09 11:44 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
    2010-11-09 11:42 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
    2010-11-09 11:40 . 2010-06-18 13:36 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
    2010-11-09 11:40 . 2010-06-21 15:27 354304 ------w- c:\windows\system32\dllcache\srv.sys
    2010-11-09 11:39 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
    2010-11-09 11:37 . 2010-02-24 13:11 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
    2010-11-09 11:35 . 2010-08-27 08:02 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
    2010-11-09 11:35 . 2009-10-15 16:28 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
    2010-11-09 11:35 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
    2010-11-09 11:31 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
    2010-11-09 11:27 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
    2010-11-09 11:26 . 2008-05-01 14:33 331776 ------w- c:\windows\system32\dllcache\msadce.dll
    2010-11-09 11:26 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
    2010-11-09 11:26 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
    2010-11-09 10:59 . 2010-11-09 10:59 -------- d-----w- c:\windows\system32\scripting
    2010-11-09 10:59 . 2010-11-09 10:59 -------- d-----w- c:\windows\l2schemas
    2010-11-09 10:59 . 2010-11-09 10:59 -------- d-----w- c:\windows\system32\en
    2010-11-09 10:59 . 2010-11-09 10:59 -------- d-----w- c:\windows\system32\bits
    2010-11-09 10:57 . 2010-11-09 10:57 -------- d-----w- c:\windows\ServicePackFiles
    2010-11-09 10:50 . 2010-11-09 10:50 -------- d-----w- c:\windows\EHome
    2010-11-09 10:37 . 2004-08-03 22:41 13240 ------w- c:\windows\system32\drivers\slwdmsup.sys
    2010-11-09 10:37 . 2004-08-03 22:29 104960 ------w- c:\windows\system32\drivers\atinrvxx.sys
    2010-11-09 10:37 . 2004-08-03 22:41 685056 ------w- c:\windows\system32\drivers\hsfcxts2.sys
    2010-11-09 10:37 . 2004-08-03 22:41 220032 ------w- c:\windows\system32\drivers\hsfbs2s2.sys
    2010-11-09 10:37 . 2004-08-03 22:41 1309184 ------w- c:\windows\system32\drivers\mtlstrm.sys
    2010-11-09 10:37 . 2004-08-03 22:29 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
    2010-11-09 10:37 . 2004-08-03 22:29 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
    2010-11-09 10:37 . 2004-08-03 22:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
    2010-11-09 10:37 . 2004-08-03 22:29 36463 ------w- c:\windows\system32\drivers\ati1tuxx.sys
    2010-11-09 10:37 . 2004-08-03 22:29 31744 ------w- c:\windows\system32\drivers\atinxbxx.sys
    2010-11-09 10:37 . 2004-08-03 22:29 28672 ------w- c:\windows\system32\drivers\atinsnxx.sys
    2010-11-09 10:25 . 2007-07-27 23:11 26488 ----a-w- c:\windows\system32\spupdsvc.exe
    2010-11-09 10:22 . 2009-08-06 19:24 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
    2010-11-09 10:22 . 2009-08-06 19:24 44768 ----a-w- c:\windows\system32\wups2.dll
    2010-11-09 10:22 . 2009-08-06 19:24 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
    2010-11-09 10:22 . 2009-08-06 19:24 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
    2010-11-09 10:22 . 2009-08-06 19:24 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
    2010-11-09 07:07 . 2005-09-26 16:40 258048 ----a-w- c:\windows\system32\Uninstall_eRecovery.exe
    2010-11-09 07:06 . 2010-11-09 07:06 -------- d-----w- c:\program files\Launch Manager
    2010-11-09 07:06 . 2004-12-10 11:49 147456 ----a-w- c:\windows\UNINST32.EXE
    2010-11-09 07:06 . 2004-12-08 14:10 16896 ----a-w- c:\windows\system32\drivers\DKbFltr.SYS
    2010-11-09 07:06 . 2002-12-19 15:58 49152 ----a-w- c:\windows\system32\QtBtLib.dll
    2010-11-09 07:05 . 2010-11-09 07:05 -------- d-----w- c:\documents and settings\Denis
    2010-11-08 23:00 . 2001-08-17 13:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
    2010-11-08 23:00 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
    2010-11-08 22:17 . 2006-02-23 22:00 5010672 ----a-w- c:\windows\KB912945.EXE
    2010-11-08 22:17 . 2004-08-26 03:23 163840 ----a-w- c:\windows\AExec.exe
    2010-11-08 22:17 . 2004-08-24 22:48 589824 ----a-w- c:\windows\AntiV.EXE

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-11-08 22:17 . 2004-06-25 17:13 925 ----a-w- c:\windows\HotFix.bat
    2010-11-08 22:17 . 2005-03-10 12:12 657 ----a-w- c:\windows\CLEANUP.CMD
    2010-09-18 12:23 . 2004-08-04 05:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2010-09-18 06:53 . 2004-08-04 05:00 974848 ----a-w- c:\windows\system32\mfc42.dll
    2010-09-18 06:53 . 2004-08-04 05:00 954368 ----a-w- c:\windows\system32\mfc40.dll
    2010-09-18 06:53 . 2004-08-04 05:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
    2010-09-09 14:16 . 2004-08-04 05:00 81920 ----a-w- c:\windows\system32\ieencode.dll
    2010-09-08 16:49 . 2004-08-04 05:00 369664 ----a-w- c:\windows\system32\html.iec
    2010-09-01 11:51 . 2004-08-04 05:00 285824 ----a-w- c:\windows\system32\atmfd.dll
    2010-08-31 13:42 . 2004-08-04 05:00 1852800 ----a-w- c:\windows\system32\win32k.sys
    2010-08-27 08:02 . 2004-08-04 05:00 119808 ----a-w- c:\windows\system32\t2embed.dll
    2010-08-23 16:12 . 2004-08-04 05:00 617472 ----a-w- c:\windows\system32\comctl32.dll
    2010-08-17 13:17 . 2004-08-04 05:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
    2010-08-16 08:45 . 2004-08-04 05:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" [X]
    "SiSPower"="SiSPower.dll" [2005-02-25 49152]
    "SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
    "SoundMan"="SOUNDMAN.EXE" [2005-02-23 77824]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
    "PCMService"="c:\program files\Arcade\PCMService.exe" [2005-03-09 49152]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-29 26112]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-12-29 98304]
    "LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
    "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 393216]
    "avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Utility Tray.lnk - c:\windows\system32\sistray.exe [2005-1-4 331776]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [09/11/2010 14:16 165584]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09/11/2010 14:16 17744]
    R3 HSFHWSIS;HSFHWSIS;c:\windows\system32\drivers\HSFHWSIS.sys [15/12/2004 15:18 200576]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - INT15.SYS
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-11-13 12:09
    Windows 5.1.2600 Service Pack 3 FAT NTAPI

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(2972)
    c:\program files\CyberLink\Shared Files\CLRCEngine.dll
    c:\windows\system32\IEFRAME.dll
    c:\windows\system32\OneX.DLL
    c:\windows\system32\eappprxy.dll
    .
    Completion time: 2010-11-13 12:10:31
    ComboFix-quarantined-files.txt 2010-11-13 12:10

    Pre-Run: 30,027,415,552 bytes free
    Post-Run: 30,047,043,584 bytes free

    - - End Of File - - 62B9A9D392B82F16B3258A81A6C06579
  3. crunchie Malware Helper

    Please go to Jotti's or to virustotal and have these files scanned. Post the results back here.

    c:\windows\AExec.exe
    c:\windows\AntiV.EXE
  4. appleybridger Newcomer, in training

    Both files scanned and nothing found.
  5. appleybridger Newcomer, in training

    Just an update.Been browsing most of the afternoon and(Touch wood) had no redirects.Also deleted some cookies and temp files and IE seems a lot faster now.
  6. crunchie Malware Helper

    Sounds good. Just give it a little more time and let me know if anything changes :).
  7. appleybridger Newcomer, in training

    Had a week of use now and had no re directs.
  8. crunchie Malware Helper

    Good news. Thanks for getting back.

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC by OldTimer:
    Save it to your Desktop.
    Double click OTC.exe.
    Click the CleanUp! button.
    If you are prompted to Reboot during the cleanup, select Yes. The tool will delete itself once it finishes.
  9. appleybridger Newcomer, in training

  10. crunchie Malware Helper

    No worries. Safe surfing :)
  11. appleybridger Newcomer, in training

    Thank you for the help you gave me.If I could ask what the problem was and how it arose after I had refomatted one drive and reinstalled the os to another.Is it possible this problem will reoccur? Would it help if I made anew restore point and a new set of backup discs? Thanks
  12. crunchie Malware Helper

    It could have been there from a saved file or you just happened to get re-infected again from surfing the net.
    Set a new restore point after clearing all the old ones.
Thread Status:
Not open for further replies.