Hi experts -
I've tried to do as much leg work as possible before posting, please let me know what else you need.
I am helping a relative with his computer. I believe he must have been infected with a virus or trojan which is hijacking some of his web activity. This happens in both IE and Firefox: He is able to browse to google.com for instance, but then his search results links redirect to unwanted pages when clicked. I ran hijackthis and analyzed it through the automatic analyzer on hijackthis.de. By comparing those results with some google searching I think I've identified a number of suspicious entries, but as I'm not very knowledgable about such things I'd like someone to help make sure I know what I'm doing before I destroy his computer! I've attached the full hijackthis log and the hijackthis startup log for review. Please let me know what I've missed, and especially if I should NOT have hijackthis fix the following entries!:
R3 - URLSearchHook: (no name) - {A4B8AF35-783A-9A9C-C1A9-B
422E0576CB
2} - teqq32.dll (file missing)File Missing
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
A8D5E23E04
5} - (no file)File Missing
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exeCtfmon
.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
ger.exe" AcRdB7_0_9 -reboot 1UpdateMgr
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\m
sntabres.d
ll.mui/230
?cf7be09ab
032493ba7e
a5154fce75
2a6
O17 - HKLM\System\CCS\Services\T
cpip\..\{5
BE4801C-25
66-491C-8C
E5-29B21CE
8C5D0}: NameServer = 69.50.161.132,85.255.112.1
5Internet Settings
O17 - HKLM\System\CCS\Services\T
cpip\..\{B
74CF85C-89
3A-4D7D-93
24-DF8EDDF
DA503}: NameServer = 69.50.161.132,85.255.112.1
5Internet Settings
O17 - HKLM\System\CCS\Services\T
cpip\..\{C
B585ED0-E2
2F-42FC-95
E9-8F61F89
ED041}: NameServer = 69.50.161.132,85.255.112.1
5Internet Settings
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
2\GOEC62~1
.DLLAppIni
t_DLLs Registry value autorun.
O22 - SharedTaskScheduler: OLE Object - {9E9F0BCD-366B-44BA-AA12-3
14C9F9E839
A} - blank (file missing)File Missing
O22 - SharedTaskScheduler: OLE Module - {190EE07F-D388-410c-A42D-1
1BD588E10F
E} - blank (file missing)File Missing
P.S. does anyone know what trojan or virus his computer is infected with which would cause these symptoms? I've had no luck identifying it. Thanks!