Hi All,
My browsers are acting up - I use Opera9.64 and IE7. Opera has started opening all new pages in new tabs and every so often a google search link will open up a random search engine page.
The behaviour in IE7 is pretty much the same except a new window instead of tab is opened.
The Hijackthis log file is below;
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:16:43, on 10/04/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\tasken
g.exe
C:\Windows\system32\Dwm.ex
e
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynT
PStart.exe
C:\Acer\Empowering Technology\eDataSecurity\x
86\eDSLoad
er.exe
C:\Acer\Empowering Technology\eAudio\eAudio.e
xe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\mobsyn
c.exe
C:\Program Files\MobilityPass\Extend3
60\e360sys
Tray.exe
C:\Windows\system32\wbem\u
nsecapp.ex
e
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Windows\WindowsMobile\w
mdc.exe
C:\Program Files\Brother\Brmfcmon\BrM
fcWnd.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Windows\System32\igfxtr
ay.exe
C:\Windows\System32\hkcmd.
exe
C:\Windows\System32\igfxpe
rs.exe
C:\Program Files\Nitro PDF\Professional\NitroPDFP
rinterMoni
tor.exe
C:\Windows\system32\igfxex
t.exe
C:\Program Files\Java\jre6\bin\jusche
d.exe
C:\Users\Toby\AppData\Loca
l\Microsof
t\Live Mesh\Bin\Servicing\0.9.342
4.31\MoeMo
nitor.exe
C:\Windows\ehome\ehtray.ex
e
C:\Windows\system32\igfxsr
vc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.ex
e
C:\Windows\ehome\ehmsas.ex
e
C:\Program Files\Brother\ControlCente
r3\brccMCt
l.exe
C:\Windows\system32\igfxsr
vc.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EX
E
C:\Acer\Empowering Technology\EPOWER\EPOWER_D
MC.EXE
C:\Program Files\Opera\opera.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING
.FRAMEWORK
.SUPERVISO
R.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGE
NT.EXE
C:\Program Files\Brother\Brmfcmon\BrM
fimon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Users\Toby\AppData\Loca
l\Microsof
t\Live Mesh\GacBase\Moe.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EX
E
C:\Program Files\QuickTime\QuickTimeP
layer.exe
C:\Users\Toby\AppData\Loca
l\Google\U
pdate\Goog
leUpdate.e
xe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Search
FilterHost
.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://maps.live.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://en.uk.acer.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://en.uk.acer.yahoo.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F
A578C2EBDC
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lperShim.d
ll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A
0F997BA588
C} - C:\Program Files\Skype\Toolbars\Inter
net Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
A8D5E23E04
5} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files\Java\jre6\bin\jp2ssv
.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-3
96DB0476E2
9} - C:\Acer\Empowering Technology\eDataSecurity\x
86\eDStool
bar.dll
O3 - Toolbar: Athens Toolbar - {2E560504-B9C8-48AA-982A-0
8B79C3FD40
E} - C:\Program Files\Eduserv Technologies Limited\Athens Toolbar\AthensToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.
dll,nvsvcS
tart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchCli
ent.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynT
PStart.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x
86\eDSload
er.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.e
xe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgA
cer.EXE
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFD
efSetting
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg
_PopUp.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmd
c.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrM
fcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCente
r3\brctrce
n.exe /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
" -atboottime
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.
exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpe
rs.exe
O4 - HKLM\..\Run: [kdx] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [Nitro PDF Printer Monitor] "C:\Program Files\Nitro PDF\Professional\NitroPDFP
rinterMoni
tor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
d.exe"
O4 - HKCU\..\Run: [MoeMonitor.exe] "C:\Users\Toby\AppData\Loc
al\Microso
ft\Live Mesh\Bin\Servicing\0.9.342
4.31\MoeMo
nitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.ex
e
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [Google Update] "C:\Users\Toby\AppData\Loc
al\Google\
Update\Goo
gleUpdate.
exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCe
nter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.ex
e
O4 - Global Startup: SETAUDIO.EXE
O4 - Global Startup: SETRES.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\
GPhotos.sc
r/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office12\
EXCEL.EXE/
3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.h
tm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Windows\WindowsMobile\
INetRepl.d
ll,-222 - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Windows\WindowsMobile\I
NetRepl.dl
l
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Windows\WindowsMobile\I
NetRepl.dl
l
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\
INetRepl.d
ll,-223 - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} -
C:\Windows\WindowsMobile\I
NetRepl.dl
l
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D
32B190E9B0
7} - C:\Program Files\Skype\Toolbars\Inter
net Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\Offic
e12\REFIEB
AR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5
C8D4460577
F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5
C8D4460577
F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-A
C9BF37916A
7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{B
FB1CB23-B1
EA-4822-82
05-4537217
80D1D}: NameServer = 85.255.112.180,85.255.112.
173
O17 - HKLM\System\CCS\Services\T
cpip\..\{F
61E37AE-C7
82-41EA-B1
EC-6D3E6D7
64C6C}: NameServer = 85.255.112.180,85.255.112.
173
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: NameServer = 85.255.112.180,85.255.112.
173
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: NameServer = 85.255.112.180,85.255.112.
173
O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: NameServer = 85.255.112.180,85.255.112.
173
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
830C7DD7F5
D} - C:\PROGRA~1\COMMON~1\Skype
\SKYPE4~1.
DLL
O20 - Winlogon Notify: FLWLEvents - C:\Program Files\MobilityPass\Extend3
60\Fiberli
nkNetProv.
dll
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0
) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0
\PhotoshopElementsFileAgen
t.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc
.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Extend360 Enforcement Agent (BESClient) - BigFix Inc. - C:\Program Files\BigFix Enterprise\BES Client\BESClient.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\Windows\system32\brsvc0
1a.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x
86\eDSServ
ice.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\e
LockServ.e
xe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eReco
veryServic
e.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Servi
ce\capuser
v.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet
Publisher\FNPLicensingServ
ice.exe
O23 - Service: System Connect Util Service (FLUtilsSvc) - Fiberlink Communications Corp. - C:\Program Files\MobilityPass\Extend3
60\FLUtils
Svc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common
Files\LightScribe\LSSrvc.e
xe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Extend360 Agent (ServiceMgr) - Fiberlink Communications Corp. - C:\Program Files\MobilityPass\Extend3
60\Service
Mgr.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSv
c.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVER
S\xaudio.e
xe
--
End of file - 12891 bytes