My Google Search seems to be Hijacked - in any browser i use. However, Yahoo! search etc is fine.
If i google 'BBC' for example, it will return results with vaild headers (BBC Homepage, BBC Sport, BBC Shop) but when you look at the links underneath it points to a random address (e.g. 208.194.50.10:w
www.blinkx.com)
i have entered safe mode and carried out the following:
- ran ccleaner
- ran malwarebytes
- ran spybot S&D
- ran full virus scan
These returned few results, mostly tracking cookies.
any ideas?
i've also ran HijackThis - see log below:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:43:24, on 20/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.e
xe
C:\Program Files\Bonjour\mDNSResponde
r.exe
C:\WINDOWS\system32\DWRCS.
EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService
.exe
C:\Program Files\Network Associates\VirusScan\Mcshi
eld.exe
C:\Program Files\Network Associates\VirusScan\VsTsk
Mgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\3dsMax2009\mentalray\sa
tellite\ra
ysat_3dsMa
x2009_32se
rver.exe
C:\3dsMax8\mentalray\satel
lite\raysa
t_3dsmax8s
erver.exe
C:\3dsMax9\mentalray\satel
lite\raysa
t_3dsmax9_
32server.e
xe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.e
xe
C:\WINDOWS\system32\Tablet
.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\WINDOWS\system32\DWRCST
.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTA
T.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\CyberLink\PowerDVD\P
DVDServ.ex
e
C:\WINDOWS\system32\RunDLL
32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\system32\rundll
32.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\DOCUME~1\MICHAE~1.BUS\L
OCALS~1\Te
mp\LogonAp
p.exe
C:\WINDOWS\system32\WTable
t\TabUserW
.exe
X:\tools_release\gta_bin\S
ysTrayRfs.
exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\toolstar\Toolstar.exe
C:\toolstar\coreapp.exe
C:\WINDOWS\system32\svchos
t.exe
C:\3dsMax2009\3dsmax.exe
C:\DOCUME~1\MICHAE~1.BUS\L
OCALS~1\Te
mp\AdskCle
anup.0001
C:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe
C:\Program Files\Java\jre6\bin\jqs.ex
e
C:\Documents and Settings\michael.bush\Loca
l Settings\Application Data\Google\Update\GoogleU
pdate.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.google.co.uk/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre6\bin\ssv.dl
l
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
164760863C
6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files\Java\jre6\bin\jp2ssv
.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-E
ABFE594F69
C} - C:\Program Files\Java\jre6\lib\deploy
\jqs\ie\jq
s_plugin.d
ll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTA
T.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\P
DVDServ.ex
e"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
JPMIG.EXE"
/Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
KRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PI
NTLGNT\ImS
cInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TI
NTLGNT\TIN
TSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TI
NTLGNT\TIN
TSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
d.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\1
.2.1128.54
62\GoogleT
oolbarNoti
fier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\michael.bush\Loca
l Settings\Application Data\Google\Update\GoogleU
pdate.exe"
/c
O4 - HKUS\S-1-5-21-2058701503-2
78224256-1
06310748-1
4619\..\Ru
n: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe (User 'admsharkey')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
lientMsiTr
ans\tscuin
st.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
lientMsiTr
ans\tscuin
st.vbs" (User 'Default user')
O4 - Startup: Launch Microsoft Outlook.lnk = C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
E
O4 - Startup: Map Drive for alienbrain.lnk = C:\WINDOWS\system32\MapDri
ve.exe
O4 - Startup: rag.exe.lnk = X:\tools_release\gta_bin\r
ag\rag.exe
O4 - Startup: SysTrayRfs.exe.lnk = X:\tools_release\gta_bin\S
ysTrayRfs.
exe
O4 - Startup: ToolStar Startup.lnk = C:\Program Files\Rockstar North\Toolstar\ToolStar.ex
e
O4 - Startup: ToolStar.lnk = C:\toolstar\Toolstar.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTable
t\TabUserW
.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.t2.local
O15 - Trusted Zone: softwareupdate.veritas.com
O15 - Trusted Zone: softwareupdate.veritas.com
(HKLM)
O15 - ESC Trusted Zone:
http://www.cnn.comO15 - ESC Trusted Zone:
http://runonce.msn.comO15 - ESC Trusted Zone:
http://www.ntpsoftware.comO15 - ESC Trusted Zone:
http://www.cnn.com (HKLM)
O15 - ESC Trusted Zone:
http://runonce.msn.com (HKLM)
O15 - ESC Trusted Zone:
http://www.ntpsoftware.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-3
14DEE697D8
3} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cabO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {31B7EB4E-8B4B-11D1-A789-0
0A0CC6651A
8} (Cult3D ActiveX Player) -
http://www.cult3d.com/download/cult.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2
D05CB95953
7} (MSN Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-2
91D84DBD4A
0} (Facebook Photo Uploader 4 Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader3.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-6
2B522420EC
C} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154613809433O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A
704AD929EE
E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = rockstar.t2.corp
O17 - HKLM\Software\..\Telephony
: DomainName = rockstar.t2.corp
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = rockstar.t2.corp
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = rockstar.t2.corp
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.e
xe
O23 - Service: ##Id_String1.6844F930_1628
_4223_B5CC
_5BB94B879
762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.
EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
ice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1150\Inte
l 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.ex
e
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService
.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshi
eld.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTsk
Mgr.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit (mi-raysat_3dsMax2009_32) - Unknown owner - C:\3dsMax2009\mentalray\sa
tellite\ra
ysat_3dsMa
x2009_32se
rver.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\3dsMax8\mentalray\satel
lite\raysa
t_3dsmax8s
erver.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\3dsMax9\mentalray\satel
lite\raysa
t_3dsmax9_
32server.e
xe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.ex
e
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.ex
e
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.e
xe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet
.exe
--
End of file - 11924 bytes