i found C:\Windows\system32\wdmaud
please find attached my combofix log file.
the problem seems to have been fixed by running combo fix.exe
Main Topics
Browse All TopicsMy Google Search seems to be Hijacked - in any browser i use. However, Yahoo! search etc is fine.
If i google 'BBC' for example, it will return results with vaild headers (BBC Homepage, BBC Sport, BBC Shop) but when you look at the links underneath it points to a random address (e.g. 208.194.50.10:wwww.blinkx.
i have entered safe mode and carried out the following:
- ran ccleaner
- ran malwarebytes
- ran spybot S&D
- ran full virus scan
These returned few results, mostly tracking cookies.
any ideas?
i've also ran HijackThis - see log below:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:43:24, on 20/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.e
C:\Program Files\Bonjour\mDNSResponde
C:\WINDOWS\system32\DWRCS.
C:\Program Files\Network Associates\Common Framework\FrameworkService
C:\Program Files\Network Associates\VirusScan\Mcshi
C:\Program Files\Network Associates\VirusScan\VsTsk
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\3dsMax2009\mentalray\sa
C:\3dsMax8\mentalray\satel
C:\3dsMax9\mentalray\satel
C:\WINDOWS\system32\nvsvc3
C:\Program Files\Analog Devices\SoundMAX\spkrmon.e
C:\WINDOWS\system32\Tablet
C:\Program Files\iPod\bin\iPodService
C:\WINDOWS\system32\DWRCST
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTA
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\CyberLink\PowerDVD\P
C:\WINDOWS\system32\RunDLL
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.
C:\WINDOWS\system32\ctfmon
C:\WINDOWS\system32\rundll
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\DOCUME~1\MICHAE~1.BUS\L
C:\WINDOWS\system32\WTable
X:\tools_release\gta_bin\S
C:\WINDOWS\system32\wuaucl
C:\toolstar\Toolstar.exe
C:\toolstar\coreapp.exe
C:\WINDOWS\system32\svchos
C:\3dsMax2009\3dsmax.exe
C:\DOCUME~1\MICHAE~1.BUS\L
C:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe
C:\Program Files\Java\jre6\bin\jqs.ex
C:\Documents and Settings\michael.bush\Loca
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
R0 - HKCU\Software\Microsoft\In
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-E
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTA
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\P
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PI
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TI
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TI
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\michael.bush\Loca
O4 - HKUS\S-1-5-21-2058701503-2
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
O4 - Startup: Launch Microsoft Outlook.lnk = C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
O4 - Startup: Map Drive for alienbrain.lnk = C:\WINDOWS\system32\MapDri
O4 - Startup: rag.exe.lnk = X:\tools_release\gta_bin\r
O4 - Startup: SysTrayRfs.exe.lnk = X:\tools_release\gta_bin\S
O4 - Startup: ToolStar Startup.lnk = C:\Program Files\Rockstar North\Toolstar\ToolStar.ex
O4 - Startup: ToolStar.lnk = C:\toolstar\Toolstar.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTable
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O15 - Trusted Zone: *.t2.local
O15 - Trusted Zone: softwareupdate.veritas.com
O15 - Trusted Zone: softwareupdate.veritas.com
O15 - ESC Trusted Zone: http://www.cnn.com
O15 - ESC Trusted Zone: http://runonce.msn.com
O15 - ESC Trusted Zone: http://www.ntpsoftware.com
O15 - ESC Trusted Zone: http://www.cnn.com (HKLM)
O15 - ESC Trusted Zone: http://runonce.msn.com (HKLM)
O15 - ESC Trusted Zone: http://www.ntpsoftware.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-3
O16 - DPF: {17492023-C23A-453E-A040-C
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-0
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-2
O16 - DPF: {5F8469B4-B055-49DD-83F7-6
O16 - DPF: {6414512B-B978-451D-A0D8-F
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS2\Services\T
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.e
O23 - Service: ##Id_String1.6844F930_1628
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.ex
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshi
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTsk
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit (mi-raysat_3dsMax2009_32) - Unknown owner - C:\3dsMax2009\mentalray\sa
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\3dsMax8\mentalray\satel
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\3dsMax9\mentalray\satel
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.ex
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.ex
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.e
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet
--
End of file - 11924 bytes
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: rpggamergirlPosted on 2009-01-21 at 02:46:19ID: 23428381
Does the redirect happens with both IE and Firefox?
2\wdmaud.s ys io.sys drv
Check if these files are present in the system32 folder, delete if present.
C:\Windows\system3
C:\Windows\system32\sysaud
c:\windows\system32\ntnet.
Or download ComboFix by sUBs:
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.