URL forwarding in browser, svchost being accessed

When I go to Google.com and click one of the search results, it forwards me to a different page than what I clicked. And when I use the Google search box in Firefox, it forwards me to a fake Google page that is just a bunch of advertisments.

Every once in a while, ad-aware blocks svchost.exe from accessing a malicious website. This is the URL of the website that is being blocked by ad-aware in the svchost.exe process, and also when I click a link on the Google search results: 66.230.188.67

Here's the hijackthis.log: http://www.mydatadump.com/hijackthis.log
gmk1212Asked:
Who is Participating?
 
geowrianConnect With a Mentor Commented:
I did see a number of bad items in your HT log:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKLM\..\Run: [kwnlidlb] C:\Documents and Settings\gk\Local Settings\Application Data\mfmydbpfu\snmxrwhshdw.exe
O4 - HKLM\..\Run: [vshnfswb] C:\Documents and Settings\gk\Local Settings\Application Data\fhvwemqrf\sdcfdoqshdw.exe
O4 - HKLM\..\Run: [Qwimoru] rundll32.exe "C:\WINDOWS\etokivegohekeva.dll",Startup
O4 - HKCU\..\Run: [kwnlidlb] C:\Documents and Settings\gk\Local Settings\Application Data\mfmydbpfu\snmxrwhshdw.exe
O4 - HKCU\..\Run: [Fkeru] rundll32.exe "C:\WINDOWS\welu16.dll",Startup
O4 - HKCU\..\Run: [vshnfswb] C:\Documents and Settings\gk\Local Settings\Application Data\fhvwemqrf\sdcfdoqshdw.exe

(maybe?) O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

0
 
geowrianConnect With a Mentor Commented:
Please try the following guide. It could be any number of malware items doing this, but I've seen the ones noted in this guide as being pretty common for what you are seeing. Make sure to try each item - the wording implies multiples solutions, but they are really each a solution to different causes.

http://www.review-buddy.com/spyware-removers/how-to-remove-google-redirect-virus.html

0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.