Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
I am having issues with Google redirecting to websites such as security-antivirus.com, nexplore.com, areaconnect.com, etc. (only in standard search mode, not advanced). I used Malwarebytes' Anti-Malware 1.31 and received the following log. Below are my DDS.txt and Attach.txt reports. Thanks!
Malwarebytes' Anti-Malware 1.33
Database version: 1673
Windows 5.1.2600 Service Pack 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\wkey (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
-------------------------------------------------------------------
DDS (Ver_09-01-18.01) - NTFSx86
Run by Grant at 19:23:49.04 on Wed 01/21/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3326.2658 [GMT -7:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-01-18.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 6/27/2008 6:12:31 PM
System Uptime: 1/21/2009 7:06:38 PM (0 hours ago)
C: is FIXED (NTFS) - 459 GiB total, 431.205 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is FIXED (FAT32) - 466 GiB total, 465.272 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP83: 10/23/2008 5:49:21 PM - System Checkpoint
RP84: 10/24/2008 9:35:25 PM - System Checkpoint
RP85: 10/26/2008 10:42:24 AM - System Checkpoint
RP86: 10/28/2008 6:05:41 PM - System Checkpoint
RP87: 10/30/2008 7:39:20 PM - System Checkpoint
RP88: 11/1/2008 4:48:09 PM - System Checkpoint
RP89: 11/3/2008 6:06:27 PM - System Checkpoint
RP90: 11/6/2008 6:30:51 PM - System Checkpoint
RP91: 11/12/2008 10:58:05 AM - System Checkpoint
RP92: 11/12/2008 12:20:39 PM - Removed Adobe Reader 8.1.2
RP93: 11/14/2008 6:04:31 PM - System Checkpoint
RP94: 11/16/2008 10:53:32 AM - System Checkpoint
RP95: 11/17/2008 12:05:18 PM - System Checkpoint
RP96: 11/20/2008 10:12:10 PM - Installed Windows Live Messenger
RP97: 11/22/2008 9:32:34 AM - System Checkpoint
RP98: 11/23/2008 10:04:50 AM - System Checkpoint
RP99: 11/24/2008 6:24:25 PM - System Checkpoint
RP100: 11/26/2008 6:21:15 PM - System Checkpoint
RP101: 11/28/2008 11:04:09 AM - Remove AnyDVD
RP102: 11/29/2008 5:45:48 PM - System Checkpoint
RP103: 12/1/2008 11:32:27 AM - Removed Safari
RP104: 12/1/2008 11:35:16 AM - Removed Apple Mobile Device Support
RP105: 12/2/2008 12:41:18 PM - System Checkpoint
RP106: 12/4/2008 5:59:16 PM - System Checkpoint
RP107: 12/6/2008 11:09:55 AM - System Checkpoint
RP108: 12/7/2008 1:31:50 PM - System Checkpoint
RP109: 12/10/2008 7:02:53 PM - System Checkpoint
RP110: 12/12/2008 4:21:42 PM - System Checkpoint
RP111: 12/13/2008 5:54:59 PM - System Checkpoint
RP112: 12/15/2008 8:08:29 PM - System Checkpoint
RP113: 12/16/2008 8:33:59 PM - System Checkpoint
RP114: 12/18/2008 11:23:04 AM - System Checkpoint
RP115: 12/23/2008 7:40:36 PM - System Checkpoint
RP116: 12/25/2008 1:55:02 PM - System Checkpoint
RP117: 12/26/2008 7:04:15 PM - System Checkpoint
RP118: 12/27/2008 6:02:20 PM - Installed Google SketchUp 7
RP119: 12/29/2008 8:26:50 PM - System Checkpoint
RP120: 12/31/2008 5:31:36 PM - System Checkpoint
RP121: 1/2/2009 9:56:00 AM - System Checkpoint
RP122: 1/3/2009 10:40:33 AM - System Checkpoint
RP123: 1/4/2009 10:58:24 AM - System Checkpoint
RP124: 1/5/2009 6:32:52 PM - System Checkpoint
RP125: 1/6/2009 7:16:09 PM - System Checkpoint
RP126: 1/10/2009 12:43:15 PM - System Checkpoint
RP127: 1/11/2009 1:54:43 PM - System Checkpoint
RP128: 1/12/2009 6:35:29 PM - System Checkpoint
RP129: 1/14/2009 6:49:34 PM - System Checkpoint
RP130: 1/16/2009 7:19:16 AM - System Checkpoint
RP131: 1/17/2009 10:56:18 AM - System Checkpoint
RP132: 1/18/2009 5:20:59 PM - System Checkpoint
RP133: 1/19/2009 5:44:51 PM - System Checkpoint
RP134: 1/20/2009 6:40:32 PM - System Checkpoint
==== Installed Programs ======================
Actiontec Gateway
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Photoshop Elements 6.0
Adobe Premiere Elements 4.0
Adobe Premiere Elements 4.0 Templates
Adobe Reader 8.1.3
Adobe Shockwave Player
Advanced Audio FX Engine
Advanced Video FX Engine
AICP 2.2.2.1
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Control Center
ATI Display Driver
Bonjour
Browser Address Error Redirector
Dell DataSafe Online
Dell Driver Reset Tool
Dell Support Center
Dell System Restore
Dell Webcam Center
Dell Webcam Manager
Documentation & Support Launcher
Games, Music, & Photos Launcher
Google Desktop
Google Earth
Google SketchUp 6
Google SketchUp 7
Google Updater
GoToAssist 8.0.0.514
High Definition Audio Driver Package - KB835221
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB908673)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB924455)
Hotfix for Windows XP (KB934428-v2)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
Intel(R) PRO Network Connections Drivers
Internet Service Offers Launcher
iTunes
Java(TM) 6 Update 5
Live! Cam Avatar Creator
Live! Cam Avatar v1.0
Malwarebytes' Anti-Malware
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Software Update for Web Folders (English) 12
MobileMe Control Panel
Monitor Webcam (SP2208WFP) Driver (1.00.08.0720)
Move Networks Media Player for Internet Explorer
MSN
MSXML 6.0 Parser (KB933579)
Musicmatch for Windows Media Player
Paint.NET v3.36
PowerDVD
QuickConnect
QuickTime
Qwest QuickAssist Desktop Tools
Qwest QuickCare 2.2
Realtek High Definition Audio Driver
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Update Manager
Safari
SearchAssist
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
SpiralFrog Download Manager 0.8.25
Update for Windows XP (KB896256)
Update for Windows XP (KB898461)
Update for Windows XP (KB912945)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
WD Diagnostics
WebFldrs XP
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB891781
==== End Of File ===========================
Didn't find the information you thought to find? Check out these Similar Threads
Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button. Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log here.
Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.
**NOTE - I recommend you allow the Recovery Console to be downloaded and installed if or when prompted.
ComboFix 09-01-21.04 - Grant 2009-01-26 21:12:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3326.2799 [GMT -7:00]
Running from: c:\documents and settings\Grant\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Grant\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
. ADS - WINDOWS: deleted 48 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\wdmaud.sys
I:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-12-27 to 2009-01-27 )))))))))))))))))))))))))))))))
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
Click Start>Run and type cmd then hit enter to open a command window. Right click in the command window and select paste. The command window will close on it's own.
Click Accept, when prompted to download and install the program files and database of malware definitions.
Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
Click View scan report at the bottom.
Click the Save Report As... button.
Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
**Note**
To optimize scanning time and produce a more sensible report for review:
Close any open programs.
Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
Post the Kaspersky log here. Let me know how your computer is behaving.
Below is the Kaspersky log. The Google redirect issue appears to have been eliminated.
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, January 27, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, January 27, 2009 19:28:31
Records in database: 1711107
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan statistics:
Files scanned: 85617
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 00:44:09
No malware has been detected. The scan area is clean.
Looks great! Open MBAM and remove any items quarantined. Do the same with your resident antivirus.
Click Start>Run and type ComboFix /u then hit Enter to uninstall ComboFix and remove the files it has quarantined. This action will also reset the System Restore points, removing any infected files there as well.
Verify the C:\Qoobox and C:\ComboFix folders were removed, as well as the C:\ComboFix.txt file.
Delete dds.scr on the desktop.
Delete gmer.zip and the gmer folder.
You can delete any other logs that were created/saved too.
Empty the recycle bin when done.
Uninstall Java(TM) 6 Update 5 via the Add/Remove programs list then install the latest version from here.
Click Start>Run and type or paste the following command then hit enter to uninstall gmer.
%systemroot%\gmer_uninstall.cmd
Restart the computer to complete the uninstallation of gmer.
That should finish things up. If things are working normally I'll mark this topic resolved.
Glad I could help. You're quite welcome. Geri has posted some very helpful information and recommendations regarding future protection in the following link.