savak Posted December 14, 2010 Report Share Posted December 14, 2010 Hi allI'm experiencing som redireting issues. I have ran Msconfig, Spybot, Adaware and done virus scans (AVG Free 2011) to try to cure the problem and cleared anything in the Startup folder on the Start Menu and still get occasional redirects.Below is the latest Hijackthis log, I would appreciate comments if there is anything there that shouldn't be.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 21:53:40, on 14/12/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\PROGRA~1\AVG\AVG10\avgchsvx.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\hkcmd.exeC:\Program Files\AVG\AVG10\avgtray.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\Microsoft ActiveSync\wcescomm.exeC:\PROGRA~1\MI3AA1~1\rapimgr.exeC:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exeC:\Program Files\AVG\AVG10\avgwdsvc.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exeC:\Program Files\AVG\AVG10\avgnsx.exeC:\Program Files\AVG\AVG10\avgemcx.exeC:\Program Files\Trusteer\Rapport\bin\RapportService.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware\AAWTray.exeC:\PROGRA~1\AVG\AVG10\avgrsx.exeC:\Program Files\AVG\AVG10\avgcsrvx.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\WINDOWS\system32\notepad.exeC:\Documents and Settings\Home\My Documents\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exeO2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dllO2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dllO3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dllO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXEO4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO16 - DPF: {5D2CF9D0-113A-476B-986F-288B54571614} (DevalVR Control) - http://www.devalvr.com/instalacion/plugin/devalocx.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dllO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dllO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exeO23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exeO23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exeO23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe--End of file - 6979 bytesThanksGraeme Quote Link to comment Share on other sites More sharing options...
Boris Posted December 14, 2010 Report Share Posted December 14, 2010 We don't have any accredited HJT specialists here any more :(.I am not by any means an expert, but as far as I can see there is nothing obviously wrong.Have you tried running the free version of Malwarebytes' Anti-Malware ?/>http://www.malwarebytes.org/mbam-download.phpDouble click the downloaded file to install the application on your computer. Once the application is installed, double click on the Malwarebytes' Anti-Malware icon to start the program. When the application is open, Update it, then select the Scan Tab and do a Full Scan.Let it kill whatever it finds. Quote Link to comment Share on other sites More sharing options...
savak Posted December 20, 2010 Author Report Share Posted December 20, 2010 I ran MalWarebites and fixed the trojans it found. Further to this I've run Adaware,Spybot Search & Destroy and carried out several sweeps with AVG2011. All have come up clean.However, when I run MSconfig I get two entries that have sqaures for the file name but the line endings finish as detailed in the attached file. I get very suspicous of such entries as I try to keep things to a minimum but I am extremely concerned about these entries. When I deselect them and restart that automatically become selected and Windows compalins it cant find the files.Please indicate if there is anything wrong or even if it's OK!ThanksGraeme Quote Link to comment Share on other sites More sharing options...
savak Posted December 20, 2010 Author Report Share Posted December 20, 2010 Sorry forgot to add the two lines end with:\Currentversion\Windows:Run\Currentversion\Windows:LoadGraeme Quote Link to comment Share on other sites More sharing options...
bludgard Posted December 20, 2010 Report Share Posted December 20, 2010 Whatever these entries are they are embedded in your kernel/running with administrative priviliges..Do you have a listing of the trojans that MBAM found and disposed of?There should be a log filed in the Log tab on Malwarebytes' User Interface.Also if you can navigate to the registry entries mentioned and post a screenshot of the expanded view of them I would appreciate it. edit:appears suspect to me as well.... Quote Link to comment Share on other sites More sharing options...
savak Posted December 23, 2010 Author Report Share Posted December 23, 2010 HiSorry for not getting back earlier. Most of the issues have been resolved but both IE8 and Firefox (latest version) open two windows on startup one with my home page and one blank. ANy ideas about this. I still get some redirection but canlive with that.Maybe someday over the holidays I will just reinstall everything and have a clean system.Graeme Quote Link to comment Share on other sites More sharing options...
bludgard Posted December 23, 2010 Report Share Posted December 23, 2010 Thank you for keeping the thread updated.I must ask....Did you find any pertinent information on those mysterious entries?I am dying to know what is going on with that.:lol: edit:Something tells me that it is related to AVG,but....Also,the opening of multiple browsers sounds like what happens when I use "Reopen Last Browsing Session" on IE8 and under Firefox there is a default configuration for this as well.Maybe just needs a little adjustment....? Quote Link to comment Share on other sites More sharing options...
savak Posted December 23, 2010 Author Report Share Posted December 23, 2010 No idea what the two entries were but no longer appear in MSconfig.Both IE8 and Firefox start with only one window but another balnk one eventually opens. Although I mainly use Firefox and set it to open new tabs only.Strangly when using Google as a search engine when I click for the 2nd page of results the current set goes slightly opaque and nothing happens. Could this be related to something.Further in a recent HJT scan an BHO showed Wormradar.com, so I checked it and fixed it and it went away the result being nothing changed.I tried Stopzilla thinking it was free but needed a registration key so I didn't buy it. Is there anything else like it other than Superantispyware?Graeme Quote Link to comment Share on other sites More sharing options...
bludgard Posted December 23, 2010 Report Share Posted December 23, 2010 Is there anything else like it other than Superantispyware?Our Deranged Member has compiled quite a list of options just for you....Free AntiVirus Software list .;) Merry Christmas,Graeme.You might try ESET Online Scanner if you wish.edit:And Stopzilla has quite the bad rep anyway.Screenshot of WOT ratings of Stopzilla. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.