|
google redirect
|
|
01-03-2009, 00:40
Bericht: #1
|
|||
|
|||
|
- This seems to be the classic problem that everyone else is having. I do searches and they redirect to other websites.
- I have run all of the usual software (SpyBot, AdAware, Malware, Symantec). - I looked in my windows & system32 folder for the sysaudio and the wdmaud, but never found them. - I also cannot run regedit either from command prompt or from the icon, because it comes up with the statement that "The instruction at "0x73dd11c7" referenced memory at 0x0000004". The memory could not be "read"." HijackThis log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:09:19 PM, on 2/28/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Dantz\Retrospect\retrorun.exe C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe C:\WINDOWS\System32\TPHDEXLG.EXE C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Lenovo\Client Security Solution\cssauth.exe C:\Program Files\Lenovo\Client Security Solution\tvtpwm_tray.exe C:\WINDOWS\system32\WDBtnMgr.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\WINDOWS\system32\TpScrLk.exe C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe C:\WINDOWS\system32\RunDll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\TpShocks.exe C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe C:\Program Files\SpeedFan\speedfan.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [TP4EX] tp4ex.exe O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [TpShocks] TpShocks.exe O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe" O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BackgroundSwitcher] C:\Program Files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe O4 - Startup: SpeedFan (2).lnk = C:\Program Files\SpeedFan\speedfan.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\PkgMgr.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resourc...se6662.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Face...loader.cab O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BU...ofupld.cab O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing) O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe -- End of file - 12743 bytes |
|||
|
01-03-2009, 03:50
Bericht: #2
|
|||
|
|||
|
RE: google redirect
Hi,
Since you can't run regedit either since this variant crashes it, do next instead.. Download registrar manager: http://www.resplendence.com/download/rrtri.exe Install it and launch it. In the Addressfield on top in Registrar Manager, enter: HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 This will Highlight/select the key "Drivers32" on the left. Rightclick that key and select "Export". See the image below how it should look like: ![]() Save the export to your desktop. In registrar manager, it saves it by default as regfile.reg, so that file should be on your desktop now. Rightclick that file (regfile.reg) and select to edit. This will open it in notepad. Copy and paste the contents of it in your next reply. Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 03:57
Bericht: #3
|
|||
|
|||
|
RE: google redirect
Also, before we delete anything then, I would like to test some things while this infection is active. This because I can't test it myself since I cannot manage to install it or duplicate these problems.
So, if you agree, would you like to test some things while this infection is active? This because I have a better insight in it and can provide easier support for others without the use of extra tools. Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 04:18
Bericht: #4
|
|||
|
|||
|
RE: google redirect
Sure, I don't mind being a guinea pig. I would like to help other people get rid of this thing!
This is the regfile.reg: REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "midimapper"="midimap.dll" "msacm.imaadpcm"="imaadp32.acm" "msacm.msadpcm"="msadp32.acm" "msacm.msg711"="msg711.acm" "msacm.msgsm610"="msgsm32.acm" "msacm.trspch"="tssoft32.acm" "vidc.cvid"="iccvid.dll" "VIDC.I420"="msh263.drv" "vidc.iv31"="ir32_32.dll" "vidc.iv32"="ir32_32.dll" "vidc.iv41"="ir41_32.ax" "VIDC.IYUV"="iyuv_32.dll" "vidc.mrle"="msrle32.dll" "vidc.msvc"="msvidc32.dll" "VIDC.UYVY"="msyuv.dll" "VIDC.YUY2"="msyuv.dll" "VIDC.YVU9"="tsbyuv.dll" "VIDC.YVYU"="msyuv.dll" "wavemapper"="msacm32.drv" "msacm.msg723"="msg723.acm" "vidc.M263"="msh263.drv" "vidc.M261"="msh261.drv" "msacm.msaudio1"="msaud32.acm" "msacm.sl_anet"="sl_anet.acm" "msacm.iac2"="C:\\WINDOWS\\system32\\iac25_32.ax" "vidc.iv50"="ir50_32.dll" "msacm.l3acm"="C:\\WINDOWS\\system32\\l3codeca.acm" "wave"="wdmaud.drv" "midi"="wdmaud.drv" "mixer"="wdmaud.drv" "vidc.VP60"="C:\\WINDOWS\\system32\\vp6vfw.dll" "vidc.VP61"="C:\\WINDOWS\\system32\\vp6vfw.dll" "MSVideo8"="VfWWDM32.dll" "wave1"="wdmaud.drv" "midi1"="wdmaud.drv" "mixer1"="wdmaud.drv" "aux"="wdmaud.drv" "aux2"="C:\\WINDOWS\\system32\\..\\wuaurpo.wio" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server\RDP] "wave"="rdpsnd.dll" "mixer"="rdpsnd.dll" "MaxBandwidth"=dword:000056b9 "wavemapper"="msacm32.drv" "EnableMP3Codec"=dword:00000001 "midimapper"="midimap.dll" |
|||
|
01-03-2009, 04:25
(Dit bericht is het laatst bewerkt op 01-03-2009 om 04:28 door miekiemoes.)
Bericht: #5
|
|||
|
|||
|
RE: google redirect
Hi,
This is the cause: "aux2"="C:\\WINDOWS\\system32\\..\\wuaurpo.wio" Do not delete it, because I want to see how this one acts first. Are you familiar with taskmanager. Does it open when you use CTRL-ALT-DEL? If so, in taskmanager, select the tab processes and end the process explorer.exe Your taskbar etc will disappear. This is normal. Then, still in taskmanager, select the first tab and select new task. In the field, enter regedit. Let me know if regedit launches while explorer is killed. To launch explorer again, just enter explorer in the "new task" field. I know this one is launched under more processes since it's loaded under "aux*", but I *think* it's mainly explorer causing the extra issues. Anyway, not sure, but if you don't test, you won't know either. Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 04:30
Bericht: #6
|
|||
|
|||
|
RE: google redirect
I followed your instructions; I didn't see anything pop up when I entered regedit into the field, but I didn't get the error message that I got last time either.
|
|||
|
01-03-2009, 04:37
Bericht: #7
|
|||
|
|||
|
RE: google redirect
Ok, never mind then.
Try next... Open notepad and copy and paste next present in the quotebox below in it: (don't forget to copy and paste REGEDIT4) Citaat:REGEDIT4Save this as fix.reg Choose to save as *all files and place it on your desktop. It should look like this: ![]() Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok. It's important that you let me know if you get an error here. Then, once you've merged the key, REBOOT or Log Off. This is an important step. After reboot or log off, navigate to and delete the file wuaurpo.wio present in your Windows folder. Please check if it comes back right after you have deleted it. Let me know in your next reply. Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 04:40
Bericht: #8
|
|||
|
|||
|
RE: google redirect
Extra question.. Do you have any idea how/where you got infected?
Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 04:40
Bericht: #9
|
|||
|
|||
|
RE: google redirect
Unfortunately when I tried that, it came up with the same "The instruction at "0x73dd11c7" referenced memory at 0x0000004". The memory could not be "read"" message as before..
|
|||
|
01-03-2009, 04:47
(Dit bericht is het laatst bewerkt op 01-03-2009 om 04:48 door miekiemoes.)
Bericht: #10
|
|||
|
|||
|
RE: google redirect
That's what I thought. It's not explorer but winlogon.exe that is probably causing the error since the aux* ones are loaded under the Winlogon process as well. That makes more sense. Anyway, killing Winlogon.exe via taskmanager isn't a good idea since it will make your pc reboot (bsod) =)
Anyway, to make it easier for you, * Open hijackthis, click 'config' (bottom right) Choose the tab 'misc Tools' on top. Choose 'delete a file on reboot' In the field, copy and paste next: C:\Windows\wuaurpo.wio Click open. Hijackthis will tell you that this file will be deleted on next reboot and if you want to reboot now. Click Yes/ok Your system should reboot now. After reboot, check if the wuaurpo.wio file that was present in the Windows folder is gone. Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 04:50
Bericht: #11
|
|||
|
|||
|
RE: google redirect
Aaargg. I actually wanted to test something else first. so in case you have not proceeded with my instructions, let me know
Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 05:01
Bericht: #12
|
|||
|
|||
|
RE: google redirect
Nooo I'm sorry, I already deleted it and just came back from the reboot.
For what it's worth, the file is gone and from the few google searches I've done things *look* okay. Is there any other way I can help you out? Also, what steps do you suggest for me to take so I can prevent it from reinfecting my system? I don't really remember what website I was on when I noticed it happening, but I do remember that it was at least 3 or 4 weeks ago. The redirecting didn't actually happen and ramp up in % until this past week; the first sign that I noticed something was off was that my google searches seemed to take forever and I would see "7.7.7.0" in the lower status bar.. |
|||
|
01-03-2009, 05:08
Bericht: #13
|
|||
|
|||
|
RE: google redirect
That's Ok. i'm sure I'll find a few new "victims" in the next couple of days.
I just wanted to test some extra things, this so I can avoid the use of extra tools. The only way to prevent this is to use Firefox as a browser with the Noscript add-on. This because this one is being spread in 80% of the cases via legitimate sites which were hacked/compromised. We'll see this in most of the cases with websites that are hosted by IX Webhosting. I also blogged about this: http://miekiemoes.blogspot.com/2009/01/i...iable.html So I assume everything is OK now? Please run the fix.reg again to restore the value in the registry. This time you shouldn't get an error. Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
01-03-2009, 05:12
Bericht: #14
|
|||
|
|||
|
RE: google redirect
I was able to incorporate fix.reg into the registry and even was able to open regedit again! So yes, I guess everything is ok. I will let you know if I notice any problems and become your victim again.
(I'll also use the Noscript add-on). Thank you so much! And your pet is very cute (in your icon). |
|||
|
01-03-2009, 05:13
Bericht: #15
|
|||
|
|||
|
RE: google redirect
Good to hear everything is working Ok again and glad I could help
Microsoft MVP - Consumer Security Assistant Director of Research @ Malwarebytes AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Preventie---Help! Mijn computer is traag!---Mijn Blog---Volg me op Twitter. Hebben we je geholpen? Uw bijdrage wordt op prijs gesteld om BlueMedicine het gevecht tegen malware te laten voortzetten. Dit is vrijblijvend uiteraard.
|
|||
|
|






![[Afbeelding: drivers32.gif]](http://users.telenet.be/bluepatchy/miekiemoes/images/drivers32.gif)
![[Afbeelding: mvp.gif]](http://users.telenet.be/bluepatchy/miekiemoes/linksimages/mvp.gif)
![[Afbeelding: mbammini.png]](http://users.telenet.be/bluepatchy/miekiemoes/linksimages/mbammini.png)
![[Afbeelding: MiekiemoesBlog.2.gif]](http://feeds.feedburner.com/MiekiemoesBlog.2.gif)

![[Afbeelding: reg.gif]](http://users.telenet.be/bluepatchy/miekiemoes/images/reg.gif)