It is currently Tue Sep 01, 2026 4:37 pm


Google search affected - please help

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Google search affected - please help

Postby ZooS » Thu Dec 24, 2009 6:24 pm

Hi Gecko

First of 2 home computers affected by different malware/virus.

This computer was infected with 'Security Tool' malware - I used Malwarebytes to fix it.

I then installed AVG full for general protection, and then noticed that none of Google's search results were appearing. Google was loading OK as start homepage, and websites can be accessed manually via address bar, but typing anything into Google search bar results in blank white screen every time. Same in both IE8 and Firefox.

I turned off all AVG settings, no change, uninstalled AVG, no change - therefore I assume there is still malicious software running. I also ran Search & Destroy, and then Spyware Doctor.

Spyware Doctor found many more problems, and was able to fix all but one - which I assume is the culprit for affecting Google search results.

Figured out I can now achieve internet search results by switching to Ask.com, so the malware seems to be attacking Google only on both IE8 and Firefox.

Here is HJT log, greatly appreciate any help in removing this problem - thank you:-


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:15:30, on 24/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\Program Files\WinPcap\rpcapd.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: 78.159.110.51 www.google.com
O1 - Hosts: 78.159.110.51 www.google.de
O1 - Hosts: 78.159.110.51 www.google.fr
O1 - Hosts: 78.159.110.51 www.google.co.uk
O1 - Hosts: 78.159.110.51 www.google.com.br
O1 - Hosts: 78.159.110.51 www.google.it
O1 - Hosts: 78.159.110.51 www.google.es
O1 - Hosts: 78.159.110.51 www.google.co.jp
O1 - Hosts: 78.159.110.51 www.google.com.mx
O1 - Hosts: 78.159.110.51 www.google.ca
O1 - Hosts: 78.159.110.51 www.google.com.au
O1 - Hosts: 78.159.110.51 www.google.nl
O1 - Hosts: 78.159.110.51 www.google.co.za
O1 - Hosts: 78.159.110.51 www.google.be
O1 - Hosts: 78.159.110.51 www.google.gr
O1 - Hosts: 78.159.110.51 www.google.at
O1 - Hosts: 78.159.110.51 www.google.se
O1 - Hosts: 78.159.110.51 www.google.ch
O1 - Hosts: 78.159.110.51 www.google.pt
O1 - Hosts: 78.159.110.51 www.google.dk
O1 - Hosts: 78.159.110.51 www.google.fi
O1 - Hosts: 78.159.110.51 www.google.ie
O1 - Hosts: 78.159.110.51 www.google.no
O1 - Hosts: 78.159.110.51 search.yahoo.com
O1 - Hosts: 78.159.110.51 us.search.yahoo.com
O1 - Hosts: 78.159.110.51 uk.search.yahoo.com
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1801674531-343818398-1177238915-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Administrator')
O4 - HKUS\S-1-5-21-1801674531-343818398-1177238915-500\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: &Search - ?p=ZNxuk101YYGB
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 8223513765
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 8709 bytes
ZooS
Newbie
Newbie
 
Posts: 6
Joined: Mon Apr 20, 2009 7:25 pm

Thanks given:0
Thanks received:0
Top

Re: Google search affected - please help

Postby Gecko » Sat Dec 26, 2009 12:36 pm

ZooS,

Please download and save it to your desktop.
Do not run WinsockFix yet you may need it later!

Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.


After the reboot you my loose your internet access
If you do, then run the WinsockFix.exe. file you saved to your desktop.

Launch WinsockFix.exe making sure that you click the "Reg Backup" button first.
Now click the "Fix" button and follow the onscreen instruction ending with rebooting your system.

After this last restart please create a new hijackthis log and post it in your reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Google search affected - please help

Postby ZooS » Mon Jan 04, 2010 5:07 pm

First ComboFix as instructed, then HijackThis log after reboot.

Running ComboFix: I allowed this program to update when it prompted newer version before running, and also allowed the installation of Recovery Console.

After subsequent reboot, normal service of Google was restored [now shows all search results] and no problems with internet connection - therefore I did not run WinsockFix.

ComboFix 10-01-03.05 - Owner 04/01/2010 8:31.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.767.360 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\Combolatest.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-12-04 to 2010-01-04 )))))))))))))))))))))))))))))))
.

2009-12-24 16:04 . 2009-12-24 16:04 -------- d-----w- c:\documents and settings\Owner\Application Data\Registry Mechanic
2009-12-24 15:40 . 2009-12-24 15:40 -------- d-----w- c:\windows\system32\xircom
2009-12-24 15:40 . 2009-12-24 15:40 -------- d-----w- c:\windows\system32\wbem\snmp
2009-12-24 15:40 . 2009-12-24 15:40 -------- d-----w- c:\windows\system32\oobe
2009-12-24 15:40 . 2009-12-24 15:40 -------- d-----w- c:\program files\microsoft frontpage
2009-12-24 15:30 . 2009-12-24 15:30 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Threat Expert
2009-12-24 15:25 . 2009-10-08 17:31 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-12-24 15:25 . 2009-10-08 17:31 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-12-24 15:25 . 2009-10-08 17:31 1636304 ----a-w- c:\windows\PCTBDCore.dll
2009-12-24 15:25 . 2009-10-08 17:31 767952 ----a-w- c:\windows\BDTSupport.dll
2009-12-24 15:25 . 2009-10-02 20:19 1152470 ----a-w- c:\windows\UDB.zip
2009-12-24 15:25 . 2008-11-26 18:08 131 ----a-w- c:\windows\IDB.zip
2009-12-24 15:24 . 2009-09-24 14:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-24 15:24 . 2009-10-06 22:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-24 15:24 . 2009-09-23 22:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-24 15:24 . 2009-09-03 15:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-24 15:24 . 2010-01-04 14:25 -------- d-----w- c:\program files\Spyware Doctor
2009-12-24 15:24 . 2009-12-24 15:36 -------- d-----w- c:\program files\Common Files\PC Tools
2009-12-24 15:24 . 2009-12-24 15:24 -------- d-----w- c:\documents and settings\Owner\Application Data\PC Tools
2009-12-24 15:24 . 2009-12-24 15:24 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-24 15:23 . 2010-01-04 14:35 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-23 18:36 . 2009-12-23 18:36 0 ----a-w- c:\windows\nsreg.dat
2009-12-23 18:36 . 2009-12-23 18:36 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
2009-12-22 21:31 . 2009-12-23 19:02 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-22 19:03 . 2009-12-22 19:03 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-12-22 19:03 . 2009-12-03 22:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-22 19:03 . 2009-12-22 19:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-22 19:03 . 2009-12-22 19:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-22 19:03 . 2009-12-03 22:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-22 15:16 . 2009-12-22 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-22 15:16 . 2009-12-22 15:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-10 18:45 . 2009-12-11 19:13 -------- d-----w- C:\Westwood
2009-12-10 17:49 . 2009-12-10 17:49 230432 ----a-w- C:\PA207.DAT
2009-12-09 16:13 . 2009-10-21 05:38 75776 ------w- c:\windows\system32\dllcache\strmfilt.dll
2009-12-09 16:13 . 2009-10-21 05:38 25088 ------w- c:\windows\system32\dllcache\httpapi.dll
2009-12-09 16:13 . 2009-10-20 16:20 265728 ------w- c:\windows\system32\dllcache\http.sys
2009-12-09 16:13 . 2009-10-12 13:28 79872 ------w- c:\windows\system32\dllcache\raschap.dll
2009-12-09 16:12 . 2009-10-13 10:38 270336 ------w- c:\windows\system32\dllcache\oakley.dll
2009-12-09 16:12 . 2009-08-25 09:27 354816 ------w- c:\windows\system32\dllcache\winhttp.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-28 23:41 . 2009-10-25 20:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-28 23:40 . 2009-10-25 20:04 -------- d-----w- c:\program files\Microsoft Works
2009-12-22 19:30 . 2009-10-22 19:49 -------- d-----w- c:\program files\ATI
2009-12-22 16:32 . 2009-10-21 21:41 -------- d-----w- c:\program files\Windows Media Connect 2
2009-11-30 21:52 . 2009-10-23 00:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-30 21:52 . 2009-11-30 21:52 -------- d-----w- c:\program files\Common Files\PAC207
2009-11-30 21:52 . 2009-11-30 21:52 -------- d-----w- c:\program files\Trust
2009-11-30 21:51 . 2009-10-23 00:14 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-29 23:43 . 2009-10-28 03:30 -------- d-----w- c:\program files\Virgin Broadband Wireless
2009-11-29 23:43 . 2009-10-28 03:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Affinegy
2009-11-18 15:06 . 2009-11-14 18:45 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-11-18 15:06 . 2009-11-14 18:45 -------- d-----w- c:\program files\DVDVideoSoft
2009-11-17 21:42 . 2009-10-28 00:03 90352 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-15 12:15 . 2009-10-25 20:04 -------- d-----w- c:\program files\MSBuild
2009-11-15 12:15 . 2009-11-15 12:15 -------- d-----w- c:\program files\Reference Assemblies
2009-11-15 12:10 . 2009-10-21 21:38 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-29 07:45 . 2009-07-19 16:02 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-23 03:15 . 2009-10-23 03:15 10134 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{D08AEED9-BA1B-27EF-B365-9AA5BFA8BC4F}\ARPPRODUCTICON.exe
2009-10-23 00:14 . 2009-10-23 00:14 315392 ----a-w- c:\windows\HideWin.exe
2009-10-23 00:11 . 2009-10-21 22:00 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-22 21:47 . 2009-10-21 21:41 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-21 21:40 . 2009-10-21 21:40 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-21 05:38 . 2008-04-14 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2008-04-14 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 12:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:38 . 2009-07-19 16:01 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-13 00:58 . 2009-07-19 16:02 150016 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:28 . 2008-04-14 12:00 79872 ----a-w- c:\windows\system32\raschap.dll
.

------- Sigcheck -------

[-] 2009-07-19 . BA8C046D98345129723E6BCAA1E8AB99 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys


c:\windows\System32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-10-14 3217368]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-07-19 128512]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 ahci6xx;ahci6xx;c:\windows\system32\drivers\ahci6xx.sys [19/07/2009 10:48 123392]
R0 amdide1;amdide1;c:\windows\system32\drivers\amdide1.sys [19/07/2009 10:48 9096]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/12/2009 09:24 207280]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [24/12/2009 09:25 112592]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [24/12/2009 09:36 583640]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14/05/2007 10:26 508288]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [24/12/2009 09:24 358600]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com/
IE: &Search - ?p=ZNxuk101YYGB
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kbe2cgxs.default\
FF - prefs.js: browser.startup.homepage - www.ask.com
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-04 08:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(956)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1976)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Virgin Broadband Wireless\AffinegyService.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Completion time: 2010-01-04 08:38:09 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-04 14:38

Pre-Run: 147,825,324,032 bytes free
Post-Run: 147,843,284,992 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - BF44A7679F99617FF5D2831F06A145C3

REBOOT - THEN HIJACK THIS:-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:45:01, on 04/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1801674531-343818398-1177238915-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Administrator')
O4 - HKUS\S-1-5-21-1801674531-343818398-1177238915-500\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: &Search - ?p=ZNxuk101YYGB
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 8223513765
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 6272 bytes
ZooS
Newbie
Newbie
 
Posts: 6
Joined: Mon Apr 20, 2009 7:25 pm

Thanks given:0
Thanks received:0
Top

Re: Google search affected - please help

Postby Gecko » Tue Jan 05, 2010 1:56 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron