willietaylor
(regular)
Thu Jun 25 2009 07:41 PM
Google Gets Redirected ?

Can anyone help me with the below?

When I am using google and put a search in, and when I click on the link, why is it i get another webpage load up from

If i close this page down and then reclick on the link, the actual page loads fine.

I have ran virus check etc and nothing found.

I use Windows Xp and IE 7

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:53, on 24/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\­smss.exe
C:\WINDOWS\system32\­winlogon.exe
C:\WINDOWS\system32\­services.exe
C:\WINDOWS\system32\­lsass.exe
C:\WINDOWS\system32\­Ati2evxx.exe
C:\WINDOWS\system32\­svchost.exe
C:\WINDOWS\System32\­svchost.exe
C:\Program Files\Lavasoft\Ad-Aw­are\aawservice.exe
C:\WINDOWS\Explorer.­EXE
C:\windows\system\hp­sysdrv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.­EXE
C:\WINDOWS\ALCWZRD.E­XE
C:\WINDOWS\system32\­spoolsv.exe
C:\WINDOWS\ALCMTR.EX­E
C:\WINDOWS\system32\­ps2.exe
C:\Program Files\Common Files\InstallShield\­UpdateService\issch.e­xe
C:\WINDOWS\system32\­spool\drivers\w32x86\­3\hpztsb12.exe
C:\Program Files\QuickTime\QTTa­sk.exe
C:\Program Files\iTunes\iTunesH­elper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\­ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBg­Monitor.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.e­xe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMob­ileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Bonjour\mDNSRe­sponder.exe
C:\WINDOWS\system32\­cisvc.exe
C:\WINDOWS\System32\­svchost.exe
C:\Program Files\iolo\common\li­b\ioloServiceManager.­exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.­EXE
C:\WINDOWS\system32\­svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.­exe
C:\WINDOWS\system32\­SearchIndexer.exe
C:\WINDOWS\system32\­svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIn­dexingService.exe
C:\Program Files\iPod\bin\iPodS­ervice.exe
C:\Program Files\Common Files\Ahead\Lib\NMIn­dexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\­SearchProtocolHost.ex­e
C:\Program Files\Trend Micro\HijackThis\Hij­ackThis.exe

R0 - HKCU\Software\Micros­oft\Internet Explorer\Main,Start Page = http://www.google.co­.uk/
R1 - HKLM\Software\Micros­oft\Internet Explorer\Main,Defaul­t_Page_URL = http://go.microsoft.­com/fwlink/?LinkId=69­157
R1 - HKLM\Software\Micros­oft\Internet Explorer\Main,Defaul­t_Search_URL = http://go.microsoft.­com/fwlink/?LinkId=54­896
R1 - HKLM\Software\Micros­oft\Internet Explorer\Main,Search Page = http://go.microsoft.­com/fwlink/?LinkId=54­896
R0 - HKLM\Software\Micros­oft\Internet Explorer\Main,Start Page = http://go.microsoft.­com/fwlink/?LinkId=69­157
R1 - HKCU\Software\Micros­oft\Windows\CurrentVe­rsion\Internet Settings,ProxyOverri­de = localhost;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-­892F-0090271D4F88} - (no file)
O1 - Hosts: 221.135.111.121 download.mcafee.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-­B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\­ActiveX\AcroIEHelper.­dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-­A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\­ActiveX\AcroIEHelperS­him.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-­89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\­bin\askBar.dll
O2 - BHO: Sopcast Toolbar - {3b5aaea6-ae6d-45ab-­a626-99ac24fd105b} - C:\Program Files\Sopcast\tbSopc­.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-­A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-­9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlcht­c.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-­9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dl­l
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-­B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_­06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-­8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogi­n.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-­8333-CF10577473F7} - c:\program files\google\googlet­oolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-­B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleT­oolbarNotifier\3.1.80­7.1746\swg.dll
O3 - Toolbar: Slide - {F25D0054-4CA2-49D5-­A8B0-D79B7829D14E} - C:\Program Files\Slide\SlideBar­.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-­9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dl­l
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-­9B18-009027A5CD4F} - c:\program files\google\googlet­oolbar1.dll
O3 - Toolbar: Sopcast Toolbar - {3b5aaea6-ae6d-45ab-­a626-99ac24fd105b} - C:\Program Files\Sopcast\tbSopc­.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-­b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\­bin\askBar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hp­sysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RE­CGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\­ps2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1­\INSTAL~1\UPDATE~1\IS­USPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\­UpdateService\issch.e­xe" -start
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\­spool\drivers\w32x86\­3\hpztsb12.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyn­cNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTa­sk.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesH­elper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl­.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\­ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04­-7C6C-4d9f-84C7-88D8A­56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBg­Monitor.exe"
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.e­xe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run­: [CTFMON.EXE] C:\WINDOWS\system32\­CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run­: [CTFMON.EXE] C:\WINDOWS\system32\­CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run­: [swg] C:\Program Files\Google\GoogleT­oolbarNotifier\Google­ToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run­: [swg] C:\Program Files\Google\GoogleT­oolbarNotifier\Google­ToolbarNotifier.exe (User 'Default user')
O6 - HKCU\Software\Polici­es\Microsoft\Internet Explorer\Restriction­s present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\sys­tem32\GPhotos.scr/200
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­CustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI­CROS~3\Office12\EXCEL­.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­FillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­ShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­SavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-­AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_­06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-­AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_­06\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-­9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-­ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­FillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-­ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­FillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-­ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­SavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-­ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­SavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-­9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­ShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-­9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormCom­ShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-­B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3­\OFFICE11\REFIEBAR.DL­L
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-­B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\­HELPCTR\Vendors\CN=He­wlett-Packard,L=Cuper­tino,S=Ca,C=US\IEButt­on\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-­B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\­HELPCTR\Vendors\CN=He­wlett-Packard,L=Cuper­tino,S=Ca,C=US\IEButt­on\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-­82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag­.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-­82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag­.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-­BB9E-00C04F795683} - C:\Program Files\Messenger\msms­gs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-­BB9E-00C04F795683} - C:\Program Files\Messenger\msms­gs.exe (file missing)
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {02BF25D5-8C17-4B23-­BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama­i.net/7/1540/52/20061­205/qtinstall.info.ap­ple.com/qtactivex/qtp­lugin.cab
O16 - DPF: {0835BC90-6ABC-4F52-­A103-4FC3A61F2C33} (A18X Control) - http://www.albatross­18.com/season2/cabs/A­18X.ocx
O16 - DPF: {0CCA191D-13A6-4E29-­B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebo­ok.com/controls/2008.­10.10_v5.5.8/Facebook­PhotoUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-­8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop­.com/betapit/PCPitSto­p.CAB
O16 - DPF: {164B406B-0FD6-4E7F-­BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwe­bbooks.com/reader/dbp­lugin.cab
O16 - DPF: {1DB93715-3B60-43EE-­93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://213.169.41.21­2/cab/OCXChecker_6110­.cab
O16 - DPF: {406B5949-7190-4245-­91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish­.co.uk/SnapfishUKActi­via.cab
O16 - DPF: {474F00F5-3853-492C-­AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.goo­gle.com/s/v/19.11/upl­oader2.cab
O16 - DPF: {4C39376E-FA9D-4349-­BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg­.com/eps/wl/activex/e­Bay_Enhanced_Picture_­Control_v1-0-24-0.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-­9335-5A1EDB1D8A21} -
O16 - DPF: {4F1E5B1A-2A80-42CA-­8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.­com/mail/w3/pr01/reso­urces/MSNPUpld.cab
O16 - DPF: {55027008-315F-4F45-­BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.­com/uploader/SlideIma­geUploader.cab
O16 - DPF: {5C6698D9-7BE4-4122-­8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebo­ok.com/controls/Faceb­ookPhotoUploader3.cab
O16 - DPF: {6BEA1C48-1850-486C-­8F58-C7354BA3165E} (Install Class) - http://updates.lifes­capeinc.com/installer­s/pinstall/pinstall.c­ab
O16 - DPF: {6E32070A-766D-4EE6-­879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros­oft.com/microsoftup...b?1146058114906
O16 - DPF: {6F750200-1362-4815-­A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgall­ery.com/downloads/BUM­/BUM_WIN_IE_1/axofupl­d.cab
O16 - DPF: {6F750203-1362-4815-­A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgall­ery.com/downloads/BUM­/BUM_WIN_IE_2/axofupl­d.cab
O16 - DPF: {9600F64D-755F-11D4-­A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterf­ly.com/downloads/Uplo­ader.cab
O16 - DPF: {A90A5822-F108-45AD-­8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c­om/controls/cpcScanne­r.cab
O16 - DPF: {ADACAA8F-3595-47FE-­9C31-9C7471B9BEC7} (OCXDownloadChecker Control) - http://213.169.41.38­/cab/OCXChecker_8000.­cab
O16 - DPF: {B38870E4-7ECB-40DA-­8C6A-595F0A5519FF} (MsnMessengerSetupDo­wnloadControl Class) - http://messenger.msn­.com/download/MsnMess­engerSetupDownloader.­cab
O16 - DPF: {C9386579-3C0F-4713-­82C6-5BA8088C7C8D} (Windows Live SkyDrive Upload Tool) - https://secure.share­d.live.com/Pa6vGqB728­AxD-ckvrPc0A/etc/Micr­osoft.Live.Folders.Ri­chUpload.cab
O16 - DPF: {CE69F98F-2AF3-4306-­BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.g­ames.yahoo.com/zylom/­activex/zylomloader.c­ab
O16 - DPF: {CF40ACC5-E1BB-4AFF-­AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-­96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m­acromedia.com/get/sho­ckwave/cabs/flash/swf­lash.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-­B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebo­ok.com/controls/Faceb­ookPhotoUploader4_5.c­ab
O16 - DPF: {E504EE6E-47C6-11D5-­B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.co­m/cab/yvwrctl.cab
O16 - DPF: {F04A8AE2-A59D-11D2-­8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay10­1.hotmail.msn.com/act­ivex/HMAtchmt.ocx
O16 - DPF: {FFB3A759-98B1-446F-­BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcp­itstop.com/Optimize2/­pcpitstop2.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1­\KASPER~1\mzvkbd.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aw­are\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMob­ileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\­Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSRe­sponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\­Google Updater\GoogleUpdate­rService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\­Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\li­b\ioloServiceManager.­exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\li­b\ioloServiceManager.­exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodS­ervice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.e­xe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIn­dexingService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV­.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.­exe

--
End of file - 15794 bytes


Contact Us | Privacy statement Main website



Search

© Copyright IPC Media Limited 2009, All rights reserved