PDA

View Full Version : All browsers hijacked! :( like:t=53675



hopleton
2011-03-30, 08:58
Hi

I have a problem very similar to closed topic: http://forums.spybot.info/showthread.php?t=53675

...search links (e.g. google results)are randomly made to redirect, in both IE and Firefox. Very annoying.

Have run several search/remove/reset/search-on-boot cycles on SS-SD
and avast! - the first cycle removed a malware program called 'ms removal' but haven't found anything significant subsequently.

Have uninstalled firefox and opera(which wouldn't run anyway) and installed chrome which is working so far - but I'm probably still infected :(

below is latest ss-sd fix report - is this the log you need?

many thanks,
h.


--- Report generated: 2011-03-30 05:06 ---

DoubleClick: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)


WebTrends live: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)


Adviva: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)



--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-03-29 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-03-22 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2010-11-30 Includes\Hijackers.sbi (*)
2011-03-08 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-02-24 Includes\Malware.sbi (*)
2011-03-22 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-03-15 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2011-03-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-03-15 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2011-03-22 Includes\TrojansC-02.sbi (*)
2011-03-03 Includes\TrojansC-03.sbi (*)
2011-03-08 Includes\TrojansC-04.sbi (*)
2011-03-21 Includes\TrojansC-05.sbi (*)
2011-03-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

tashi
2011-03-30, 16:10
Hello hopleton,



below is latest ss-sd fix report - is this the log you need?

--- Report generated: 2011-03-30 05:06 ---

DoubleClick: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)

WebTrends live: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)

MediaPlex: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)

MediaPlex: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)

Adviva: Tracking cookie (Firefox: Alec Hole (default)) (Cookie, fixed)

--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126)
That part yes. :)

Also, in case you missed it please see the forum FAQ which includes guidelines for this forum and instructions on posting preliminary "DDS" logs for analysis.
"BEFORE You POST"(Please read this Procedure Before Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start a new topic providing the logs and a volunteer analyst will advise you when available. :)

Best regards.