WUGNET, the Windows User Group Network
Your Complete Resource Center for "The Best" in Shareware, Computing Tips and Support, Windows Industry News... and much more!
Home Forums Shareware Windows Tips Hot Offers FREE Newsletters Arcade Contact Us About Partners
Search WUGNET: RSS Feeds RSS Feeds Advertise with WUGNET    |    Shareware eBooks
HomeHome FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Google search results redirected??

 
   Home -> Security -> General Discussions RSS
Next:  How do I ignore a file in AVG?  
Author Message
Steve

External


Since: Feb 27, 2008
Posts: 3



(Msg. 1) Posted: Wed Feb 27, 2008 8:54 pm
Post subject: Google search results redirected??
Archived from groups: alt>comp>virus (more info?)

I am trying to help someone that is having a problem with Google search
results being redirected to other pages. For instance if I try a Google
search for Microsoft and click on a link I get a page that takes me to
Microsoft search results on Ebay. Some search results go to pages for other
lesser known search engine pages. other results take the user to pages with
lots of advertisements. If I enter a URL in the address bar it takes me to
the right place. Google is the user's homepage and in IE properties it shows
http://www.google.com . Intersting is that when http://www.google.com shows
in the address bar instead of the Internet Explorer symbol just to the left
of the http there is a different symol which is red in color.

The computer is XP Pro SP2 using Internet Explorer 7 with all current
Microsoft security updates and default IE settings. The AV was Symantec AV
that had expired in 10/07. I replaced with Trend Micro 2008 AV and using
Spyware Doctor from http://pack.google.com . The problem does not happen
with Firefox but the user still wants to use IE for some things. Otherwise
the computer performs well with no other know issues.

Things I have tried:

Booting into Bart's PE, deleted temp files and scanned with Trend Micro
Sysclean and McAfee command line using latest definition files. A few
trojans were found and removed by each. Reran each to make sure nothing else
was found. Booted into Safe Mode and used Autoruns to check everything shown
including dlls removing anything suspicious other than Microsoft items. Did
the same with hijack this. Disabled all addons in IE. Checked Control Panel
add and remove programs and removed anything not needed and suspicious and
checked services.msc for anything suspicious. Ran full scans with AdAware
SE. Spyware Sweeper, Spyware Doctor, and AVG spyware all of which found
some things that were removed. Reran programs again until they came up as
clean and also did in regualr mode. In Safe mode ran Smitfraudfix, Vundofix,
Winsockfix, CWshredder, and Fixwareout. Checked hosts file which was default
anyhow after Winsockfix and the trusted zone in IE for anything that should
not be there.

As of now all spyware and AV scans come up clean yet the Google search
redirect problem still exists. There are no pop ups or other problems seen
on the computer. One thing I forgot to do which I will try next time is to
reinstall Interent Explorer and see if the problem exists in Safe Mode with
networking. I may also try creating a new profile for the user. Anyone have
any idea what is causing the Google search redirects or what else to try to
remove the problem or to try and identify it?? Unfortuneatly I am not going
to be able to try repairs again until later next week so I can't report back
any results sonner than that but I would appreciate any advice, experience,
or ideas. The user can not correlate any events such as software install,
downloads, or any updates to the time that the problem began.

Thanks Steve
Back to top
Login to vote
Russg

External


Since: Apr 25, 2007
Posts: 43



(Msg. 2) Posted: Thu Feb 28, 2008 3:04 am
Post subject: Re: Google search results redirected?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Steve" <> wrote in message
snip
I didn't see where you disabled system restore.
Disable system restore, do your clean boot and
command line virus/spyware/trojan scan.
Now boot to normal and do another scan.
Finally, re-boot and enable system restore, if
symptoms are gone.
Back to top
Login to vote
Steve

External


Since: Feb 27, 2008
Posts: 3



(Msg. 3) Posted: Thu Feb 28, 2008 3:04 am
Post subject: Re: Google search results redirected?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks for that tip. I will try it.

Steve


"Russg" wrote in message

>
> "Steve" <> wrote in message
> snip
> I didn't see where you disabled system restore.
> Disable system restore, do your clean boot and
> command line virus/spyware/trojan scan.
> Now boot to normal and do another scan.
> Finally, re-boot and enable system restore, if
> symptoms are gone.
>
>
Back to top
Login to vote
Buzzard

External


Since: Dec 11, 2007
Posts: 16



(Msg. 4) Posted: Fri Feb 29, 2008 5:00 pm
Post subject: Re: Google search results redirected?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Steve wrote:
> I am trying to help someone that is having a problem with Google search
> results being redirected to other pages. For instance if I try a Google
> search for Microsoft and click on a link I get a page that takes me to
> Microsoft search results on Ebay. Some search results go to pages for other
> lesser known search engine pages. other results take the user to pages with
> lots of advertisements. If I enter a URL in the address bar it takes me to
> the right place. Google is the user's homepage and in IE properties it shows
> http://www.google.com . Intersting is that when http://www.google.com shows
> in the address bar instead of the Internet Explorer symbol just to the left
> of the http there is a different symol which is red in color.
>

I've noticed myself that some of the links that google provides
lead to other search engines, and many of them lead to web pages that
dont have what google's synopsis said they had. Before you click a
link in google, hover the mouse over it and look at the status bar
to see where it will lead. And if the link, once you click it, leads
to something stupid, try going back to the googlesearch and glick on
"cached", to see the page that existed when google scanned the site.
The problem might just be web sites that change after google scans
them, or which have misleading keywords causing google to mislist them.
(Or, i suppose its possible you might have malware directing you to a
fake version of google)
Back to top
Login to vote
Steve

External


Since: Feb 27, 2008
Posts: 3



(Msg. 5) Posted: Fri Mar 07, 2008 3:32 am
Post subject: Re: Google search results redirected?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Well I finally fixed it. I found a suspicious O21 - SSODL entry in the
HijackThis for a file named zip.dll. I tried to remove it via HijackThis and
it kept coming back. I found the file, renamed it, rebooted, logged on as
the user and the Google redirected searches via Internet Explorer went away.
After reading more about HijackThis it seems any O21 - SSODL entry found
should be suspected as malicious.

Steve




"Steve" wrote in message

>I am trying to help someone that is having a problem with Google search
>results being redirected to other pages. For instance if I try a Google
>search for Microsoft and click on a link I get a page that takes me to
>Microsoft search results on Ebay. Some search results go to pages for other
>lesser known search engine pages. other results take the user to pages with
>lots of advertisements. If I enter a URL in the address bar it takes me to
>the right place. Google is the user's homepage and in IE properties it
>shows http://www.google.com . Intersting is that when http://www.google.com
>shows in the address bar instead of the Internet Explorer symbol just to
>the left of the http there is a different symol which is red in color.
>
> The computer is XP Pro SP2 using Internet Explorer 7 with all current
> Microsoft security updates and default IE settings. The AV was Symantec AV
> that had expired in 10/07. I replaced with Trend Micro 2008 AV and using
> Spyware Doctor from http://pack.google.com . The problem does not happen
> with Firefox but the user still wants to use IE for some things. Otherwise
> the computer performs well with no other know issues.
>
> Things I have tried:
>
> Booting into Bart's PE, deleted temp files and scanned with Trend Micro
> Sysclean and McAfee command line using latest definition files. A few
> trojans were found and removed by each. Reran each to make sure nothing
> else was found. Booted into Safe Mode and used Autoruns to check
> everything shown including dlls removing anything suspicious other than
> Microsoft items. Did the same with hijack this. Disabled all addons in IE.
> Checked Control Panel add and remove programs and removed anything not
> needed and suspicious and checked services.msc for anything suspicious.
> Ran full scans with AdAware SE. Spyware Sweeper, Spyware Doctor, and AVG
> spyware all of which found some things that were removed. Reran programs
> again until they came up as clean and also did in regualr mode. In Safe
> mode ran Smitfraudfix, Vundofix, Winsockfix, CWshredder, and Fixwareout.
> Checked hosts file which was default anyhow after Winsockfix and the
> trusted zone in IE for anything that should not be there.
>
> As of now all spyware and AV scans come up clean yet the Google search
> redirect problem still exists. There are no pop ups or other problems seen
> on the computer. One thing I forgot to do which I will try next time is to
> reinstall Interent Explorer and see if the problem exists in Safe Mode
> with networking. I may also try creating a new profile for the user.
> Anyone have any idea what is causing the Google search redirects or what
> else to try to remove the problem or to try and identify it??
> Unfortuneatly I am not going to be able to try repairs again until later
> next week so I can't report back any results sonner than that but I would
> appreciate any advice, experience, or ideas. The user can not correlate
> any events such as software install, downloads, or any updates to the time
> that the problem began.
>
> Thanks Steve
>
>
>
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 3510



(Msg. 6) Posted: Fri Mar 07, 2008 3:32 am
Post subject: Re: Google search results redirected?? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Steve"

| Well I finally fixed it. I found a suspicious O21 - SSODL entry in the
| HijackThis for a file named zip.dll. I tried to remove it via HijackThis and
| it kept coming back. I found the file, renamed it, rebooted, logged on as
| the user and the Google redirected searches via Internet Explorer went away.
| After reading more about HijackThis it seems any O21 - SSODL entry found
| should be suspected as malicious.
|
| Steve
|


Please submit the renamed DLL to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN

When you get the report, please post back the exact results.



--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
Login to vote
ldog




Joined: Apr 28, 2009
Posts: 1



(Msg. 7) Posted: Mon Apr 27, 2009 11:59 pm
Post subject: help [Login to view extended thread Info.]

Having the same issue, but I cannot isolate a file yet that seems to be causing the issue. Below is my log file from hijackthis. Any help would be GREATLY appreciated. As you'll see, have tried many programs to eradicate this nuisance.

C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:Program FilesWebrootWebrootSecurityWRConsumerService.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCommon FilesBitDefenderBitDefender Update Servicelivesrv.exe
C:Program FilesBitDefenderBitDefender 2009vsserv.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32wltrysvc.exe
C:WINDOWSSystem32bcmwltry.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:PROGRA~1AVGAVG8avgwdsvc.exe
C:Program FilesBonjourmDNSResponder.exe
C:WINDOWSExplorer.EXE
C:Program FilesJavajre6binjqs.exe
c:program filesmcafee.comagentmcdetect.exe
c:PROGRA~1mcafee.comvsomcshield.exe
c:PROGRA~1mcafee.comagentmctskshd.exe
c:PROGRA~1mcafee.comvsoOasClnt.exe
C:PROGRA~1McAfee.comPERSON~1MPFSERVICE.exe
C:Program FilesDellNICCONFIGSVCNICCONFIGSVC.exe
c:program filesmcafee.comvsomcvsshld.exe
C:PROGRA~1mcafee.comvsomcvsescn.exe
C:Program FilesSunbelt SoftwareCounterSpySBAMSvc.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesSmith MicroStuffItArcNameService.exe
C:Program FilesWebrootWebrootSecuritySpySweeper.exe
C:Program FilesSunbelt SoftwareCounterSpySBAMTray.exe
C:Program FilesSynapticsSynTPSynTPLpr.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesIntelPROSetWiredNCSPROSetPRONoMgr.exe
C:Program FilesDellQuickSetquickset.exe
C:WINDOWSsystem32WLTRAY.exe
C:PROGRA~1mcafee.comagentmcagent.exe
C:Program FilesCyberLinkPowerDVDDVDLauncher.exe
C:WINDOWSsystem32hkcmd.exe
C:WINDOWSsystem32igfxpers.exe
C:PROGRA~1AVGAVG8avgrsx.exe
C:WINDOWSsystem32dlatfswctrl.exe
C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
C:PROGRA~1AVGAVG8avgnsx.exe
C:WINDOWSsystem32igfxsrvc.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesJavajre6binjusched.exe
C:Program FilesBitDefenderBitDefender 2009bdagent.exe
C:PROGRA~1AVGAVG8avgtray.exe
C:Program FilesWebrootWebrootSecuritySpySweeperUI.exe
C:PROGRA~1McAfee.comPERSON~1MpfAgent.exe
C:Program FilesDellSupportDSAgnt.exe
C:Program FilesMessengermsmsgs.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
C:Documents and SettingsAll UsersApplication DataDellTransferAgentTransferAgent.exe
C:Documents and SettingsLarry WondolowskiLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe
C:Program FilesThe Weather Channel FWDesktopDesktopWeather.exe
C:Program FilesDigital Line DetectDLG.exe
C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
c:progra~1mcafee.comvsomcvsftsn.exe
C:Documents and SettingsLarry WondolowskiDesktopiPodbiniPodService.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesAheadLibNMIndexingService.exe
C:WINDOWSsystem32wuauclt.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:Program FilesSTOPzilla!SZSG.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:Program FilesRealRealPlayerrpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program FilesAVGAVG8avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:WINDOWSsystem32dlatfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre6binssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.1.1309.3572swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:Program FilesSTOPzilla!SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:progra~1mcafee.comvsomcvsshl.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:Program FilesCanonEasy-WebPrintToolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:WINDOWSsystem32TwcToolbarIe7.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:Program FilesSTOPzilla!SZSG.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:Program FilesBitDefenderBitDefender 2009IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar.dll
O4 - HKLM..Run: [SynTPLpr] "C:Program FilesSynapticsSynTPSynTPLpr.exe"
O4 - HKLM..Run: [SynTPEnh] "C:Program FilesSynapticsSynTPSynTPEnh.exe"
O4 - HKLM..Run: [PRONoMgrWired] "C:Program FilesIntelPROSetWiredNCSPROSetPRONoMgr.exe"
O4 - HKLM..Run: [Dell QuickSet] "C:Program FilesDellQuickSetquickset.exe"
O4 - HKLM..Run: [Dell Wireless Manager UI] "C:WINDOWSsystem32WLTRAY"
O4 - HKLM..Run: [UpdateManager] "C:Program FilesCommon FilesSonicUpdate Managersgtray.exe" /r
O4 - HKLM..Run: [VSOCheckTask] "C:PROGRA~1McAfee.comVSOmcmnhdlr.exe" /checktask
O4 - HKLM..Run: [MCAgentExe] "c:PROGRA~1mcafee.comagentmcagent.exe"
O4 - HKLM..Run: [VirusScan Online] "C:Program FilesMcAfee.comVSOmcvsshld.exe"
O4 - HKLM..Run: [MPFExe] "C:PROGRA~1McAfee.comPERSON~1MpfTray.exe"
O4 - HKLM..Run: [OASClnt] "C:Program FilesMcAfee.comVSOoasclnt.exe"
O4 - HKLM..Run: [DVDLauncher] "C:Program FilesCyberLinkPowerDVDDVDLauncher.exe"
O4 - HKLM..Run: [MCUpdateExe] "C:PROGRA~1mcafee.comagentMcUpdate.exe"
O4 - HKLM..Run: [igfxtray] "C:WINDOWSsystem32igfxtray.exe"
O4 - HKLM..Run: [igfxhkcmd] "C:WINDOWSsystem32hkcmd.exe"
O4 - HKLM..Run: [igfxpers] "C:WINDOWSsystem32igfxpers.exe"
O4 - HKLM..Run: [dla] "C:WINDOWSsystem32dlatfswctrl.exe"
O4 - HKLM..Run: [NeroFilterCheck] "C:Program FilesCommon FilesAheadLibNeroCheck.exe"
O4 - HKLM..Run: [Google Desktop Search] "C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe" /startup
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [RoxWatchTray] "C:Program FilesCommon FilesRoxio Shared9.0SharedCOMRoxWatchTray9.exe"
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre6binjusched.exe"
O4 - HKLM..Run: [SBAMTray] "C:Program FilesSunbelt SoftwareCounterSpySBAMTray.exe"
O4 - HKLM..Run: [BDAgent] "C:Program FilesBitDefenderBitDefender 2009bdagent.exe"
O4 - HKLM..Run: [BitDefender Antiphishing Helper] "C:Program FilesBitDefenderBitDefender 2009IEShow.exe"
O4 - HKLM..Run: [AVG8_TRAY] "C:PROGRA~1AVGAVG8avgtray.exe"
O4 - HKLM..Run: [SpySweeper] "C:Program FilesWebrootWebrootSecuritySpySweeperUI.exe" /startintray
O4 - HKCU..Run: [DellSupport] "C:Program FilesDellSupportDSAgnt.exe" /startup
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [ctfmon.exe] "C:WINDOWSsystem32ctfmon.exe"
O4 - HKCU..Run: [swg] "C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe"
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe"
O4 - HKCU..Run: [DellTransferAgent] "C:Documents and SettingsAll UsersApplication DataDellTransferAgentTransferAgent.exe"
O4 - HKCU..Run: [Google Update] "C:Documents and SettingsLarry WondolowskiLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe" /c
O4 - HKCU..Run: [DW6] "C:Program FilesThe Weather Channel FWDesktopDesktopWeather.exe"
O4 - HKCU..Run: [AROReminder] "C:Program FilesAdvanced Registry Optimizeraro.exe" -rem
O4 - HKCU..Run: [Adware_ProMFCT] "C:Program FilesAdware_ProAdware_Pro.exe"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:WINDOWSsystem32GPhotos.scr/200
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:Program FilesCanonEasy-WebPrintResource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:Program FilesCanonEasy-WebPrintResource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:Program FilesCanonEasy-WebPrintResource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:Program FilesCanonEasy-WebPrintResource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre6binjp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre6binjp2iexp.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSsystem32Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O10 - Unknown file in Winsock LSP: c:program filescommon filesis3anti-spywareis3lsp.dll
O10 - Unknown file in Winsock LSP: c:program filescommon filesis3anti-spywareis3lsp.dll
O10 - Unknown file in Winsock LSP: c:program filescommon filesis3anti-spywareis3lsp.dll
O10 - Unknown file in Winsock LSP: c:program filescommon filesis3anti-spywareis3lsp.dll
O10 - Unknown file in Winsock LSP: c:program filescommon filesis3anti-spywareis3lsp.dll
O10 - Unknown file in Winsock LSP: c:program filescommon filesis3anti-spywareis3lsp.dll
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!commonyinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://world.chamberlaingroup.com/whalecom8e74f8feec057e/whalecom0/iNotes6W.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1195444576531 (http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cli.../wuweb_)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://world.chamberlaingroup.com/InternalSite/WhlCompMgr.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://world.chamberlaingroup.com/whalecom8e74f8feec057e/whalecom0/dwa7W.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program FilesAVGAVG8avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:PROGRA~1GoogleGOOGLE~4GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:WINDOWSSYSTEM32avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - Unknown owner - C:Program FilesCommon FilesBitDefenderBitDefender Arrakis ServerbinArrakis3.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:PROGRA~1AVGAVG8avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:Program FilesDellSupportbrkrsvc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:Documents and SettingsLarry WondolowskiDesktopiPodbiniPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:Program FilesJavajre6binjqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:Program FilesCommon FilesBitDefenderBitDefender Update Servicelivesrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:program filesmcafee.comagentmcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:PROGRA~1mcafee.comvsomcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:PROGRA~1mcafee.comagentmctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:PROGRA~1McAfee.comAgentmcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:PROGRA~1McAfee.comPERSON~1MPFSERVICE.exe
O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:Program FilesIntelPROSetWiredNCSSyncNetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:Program FilesDellNICCONFIGSVCNICCONFIGSVC.exe
O23 - Service: NMIndexingService - Nero AG - C:Program FilesCommon FilesAheadLibNMIndexingService.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:Program FilesRoxioDigital Home 9RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:Program FilesRoxioDigital Home 9RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:Program FilesCommon FilesRoxio Shared9.0SharedCOMRoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:Program FilesCommon FilesRoxio Shared9.0SharedCOMRoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:Program FilesCommon FilesRoxio Shared9.0SharedCOMRoxWatch9.exe
O23 - Service: CounterSpy Antispyware (SBAMSvc) - Sunbelt Software - C:Program FilesSunbelt SoftwareCounterSpySBAMSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware DoctorpctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware DoctorpctsSvc.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:Program FilesSmith MicroStuffItArcNameService.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:Program FilesCommon FilesiS3Anti-SpywareSZServer.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:Program FilesBitDefenderBitDefender 2009vsserv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:Program FilesWebrootWebrootSecuritySpySweeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:WINDOWSSystem32wltrysvc.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:Program FilesWebrootWebrootSecurityWRConsumerService.exe

--
End of file - 19319 bytes
Back to top
Login to vote
robertguero




Joined: Jun 03, 2009
Posts: 1



(Msg. 8) Posted: Wed Jun 03, 2009 9:59 am
Post subject: [Login to view extended thread Info.]

How to fix Google search results redirect redirected

I am using Windows XP and Mozilla Firebird as browser

Also affects all users names on computer.


IF you are being redirected to random ad sites then this is the fix that I got after 3 days. Have tried AdWare, S&D, MalWareBytes, SmitFraudFix, 7770Finder, ESET NOD32, CCleaner and a few other scrubs and probably a few I cant remember.

HijackThis did nothing and showed nothing as you can see from ppls post above. NOT to say its not good cause in the past it has worked. Just thik for one this is to new and two its in the registry.

Symptoms: Do a Google search in an actual browser window, NOT THE TOOL BAR %&*$. I would get the results I was looking for with the correct URLs under each result. Like searched Microsoft and it would come up with addresses from microsoft like: http://www.microsoft.com/ - 76k or http://www.microsoft.com/DOWNLOADS/en/default.aspx - 44k -

BUT when clicking a link I would usually get the page that it said the first time but when going back to the search results the next link would be some ad site with usually no WWW at the beginning. And this would last about 4 clicks. That is, by going to stupid ad site then back to results 4x then finally getting the page it was suppose to show.

Reason I am giving you whole speal is because there are alot of so similar ones out there.

Heres the fix. Wish I could give thanks to where I found it but cant find page now. Can remember the guy found it on his own and his last words are something like "kick the computer, format the drive, tell landlady she aint gettin money" or something like that .

Never mind found it with what I said above about his quote in Google that now works correctly. Maybe it did not fix his and thats the reason he said it. But it gave me the direction to fix it, after days of trying everything. http://emptees.com/posts/14105-f-ing-gogoogle-redirection-malware-problem-resolved (http://emptees.com/posts/14105-f-ing-gogoogle-redirection-malware-prob...-resolv)

So DLed the TR software http://www.simplysup.com/ it came up with this registry key. It came up with below registry location with the Kungs...thing.

IF YOU SCREW UP AND MESS SOMETHING UP IN THE REGISTRY YOU CAN HOSE THE WHOLE COMPUTER. SO IF YOU DONT UNDERSTAND OR KNOW WHAT YOU ARE DOING GET SOMEONE THAT DOES.

Heres the key it came up with:
HKEY_CURRENT_USERSoftwareMicrosoftSearch AssistantACMru5603

And the values that were bad:
kungsfaswwqlmq.sys and tdssserv.sys

Now two different ways to do this, you can either delete the key or just he values. "Delete the key. To prevent keeping a history altogether, right click ACMru/Permissions/Deny all users and groups listed." This is from another website: http://www.kellys-korner-xp.com/xp_tweak_bookmarks.htm AND even has a script to do above for you: http://www.kellys-korner-xp.com/ClearRecent.Exe

I really hope this helps. Honestly could not find this anywhere. I guess its something new.
Back to top
Login to vote
Display posts from previous:   
       Home -> Security -> General Discussions All times are: Eastern Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Categories:
 Windows XP
 Windows Vista
 Windows Other
 Office
 Office Other
  Security
  • Home |
  • Shareware |
  • Windows Tips |
  • Hot Offers |
  • FREE Newsletters |
  • Arcade |
  • Forums |
  • eBooks |
  • About WUGNET |
  • Partners |
  • Contact

  • WUGNET Privacy Policy |
  • Help Forum Terms of Service |
  • Link to WUGNET |
  • IT Support