Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Redirected from google

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Redirected from google

Unread postby tigerdog » November 8th, 2009, 12:29 am

When I do a google search and click on a result, I am redirected to shopping or other sites. Some of the ones I remember are lifeforsearch.net and shopzilla. I don't have any popup issues that I am aware of. Here's my hijack file. Thank you for any support you can provide.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26:33 PM, on 11/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Tivoli\baclient\dsmcsvc.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.auburn.edu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: www.securesoftwarebill.com
O1 - Hosts: getantivirusplusnow.com
O1 - Hosts: secure-plus-payments.com
O1 - Hosts: www.getantivirusplusnow.com
O1 - Hosts: www.secure-plus-payments.com
O1 - Hosts: secure.paysecuresystem.com
O1 - Hosts: paysoftbillsolution.com
O1 - Hosts: google.ae
O1 - Hosts: google.as
O1 - Hosts: google.at
O1 - Hosts: google.az
O1 - Hosts: google.ba
O1 - Hosts: google.be
O1 - Hosts: google.bg
O1 - Hosts: google.bs
O1 - Hosts: google.ca
O1 - Hosts: google.cd
O1 - Hosts: google.com.gh
O1 - Hosts: google.com.hk
O1 - Hosts: google.com.jm
O1 - Hosts: google.com.mx
O1 - Hosts: google.com.my
O1 - Hosts: google.com.na
O1 - Hosts: google.com.nf
O1 - Hosts: google.com.ng
O1 - Hosts: google.ch
O1 - Hosts: google.com.np
O1 - Hosts: google.com.pr
O1 - Hosts: google.com.qa
O1 - Hosts: google.com.sg
O1 - Hosts: google.com.tj
O1 - Hosts: google.com.tw
O1 - Hosts: google.dj
O1 - Hosts: google.de
O1 - Hosts: google.dk
O1 - Hosts: google.dm
O1 - Hosts: google.ee
O1 - Hosts: google.fi
O1 - Hosts: google.fm
O1 - Hosts: google.fr
O1 - Hosts: google.ge
O1 - Hosts: google.gg
O1 - Hosts: google.gm
O1 - Hosts: google.gr
O1 - Hosts: google.ht
O1 - Hosts: google.ie
O1 - Hosts: google.im
O1 - Hosts: google.in
O1 - Hosts: google.it
O1 - Hosts: google.ki
O1 - Hosts: google.la
O1 - Hosts: google.li
O1 - Hosts: google.lv
O1 - Hosts: google.ma
O1 - Hosts: google.ms
O1 - Hosts: google.mu
O1 - Hosts: google.mw
O1 - Hosts: google.nl
O1 - Hosts: google.no
O1 - Hosts: google.nr
O1 - Hosts: google.nu
O1 - Hosts: google.pl
O1 - Hosts: google.pn
O1 - Hosts: google.pt
O1 - Hosts: google.ro
O1 - Hosts: google.ru
O1 - Hosts: google.rw
O1 - Hosts: google.sc
O1 - Hosts: google.se
O1 - Hosts: google.sh
O1 - Hosts: google.si
O1 - Hosts: google.sm
O1 - Hosts: google.sn
O1 - Hosts: google.st
O1 - Hosts: google.tl
O1 - Hosts: google.tm
O1 - Hosts: google.tt
O1 - Hosts: google.us
O1 - Hosts: google.vu
O1 - Hosts: google.ws
O1 - Hosts: google.co.ck
O1 - Hosts: google.co.id
O1 - Hosts: google.co.il
O1 - Hosts: google.co.in
O1 - Hosts: google.co.jp
O1 - Hosts: google.co.kr
O1 - Hosts: google.co.ls
O1 - Hosts: google.co.ma
O1 - Hosts: google.co.nz
O1 - Hosts: google.co.tz
O1 - Hosts: google.co.ug
O1 - Hosts: google.co.uk
O1 - Hosts: google.co.za
O1 - Hosts: google.co.zm
O1 - Hosts: google.com
O1 - Hosts: google.com.af
O1 - Hosts: google.com.ag
O1 - Hosts: google.com.ar
O1 - Hosts: google.com.au
O1 - Hosts: google.com.bn
O1 - Hosts: google.com.br
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Novell Messenger] "C:\Novell\Messenger\NMCL32.exe"
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Novell Messenger - {3C3171BC-1025-43d1-8D1D-61CF4B38A28F} - C:\Novell\MESSEN~1\NMCL32.exe
O9 - Extra 'Tools' menuitem: Novell Messenger - {3C3171BC-1025-43d1-8D1D-61CF4B38A28F} - C:\Novell\MESSEN~1\NMCL32.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.auburn.edu
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 1278202781
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = auburn.edu
O17 - HKLM\Software\..\Telephony: DomainName = ad.auburn.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = auburn.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = auburn.edu
O20 - AppInit_DLLs: c:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\WINDOWS\system32\rpcnet.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: tsm scheduler - IBM Corporation - C:\Program Files\Tivoli\baclient\dsmcsvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

End of file - 11789 bytes
Active Member
Posts: 3
Joined: November 8th, 2009, 12:18 am
Register to Remove

Re: Redirected from google

Unread postby Dakeyras » November 11th, 2009, 6:52 pm

Hi. :)

Is this computer your own personal machine and or the property of Auburn University on loan?
User avatar
MRU Honors Graduate
MRU Honors Graduate
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Redirected from google

Unread postby tigerdog » November 12th, 2009, 11:24 pm

It belongs to Auburn but is assigned to me. I use it mostly at home or when traveling. I have used this forum to fix a desktop in my office before and was hoping to find some assistance for this laptop.
Active Member
Posts: 3
Joined: November 8th, 2009, 12:18 am

Re: Redirected from google

Unread postby Dakeyras » November 13th, 2009, 3:35 am

Hi. :)

What you have mentioned about this laptop falls within the borderline of this forums policy(and my own personal one) with regard to what is termed a business machine.

The various applications and tools I use are geared to-wards home use only computers and may either break/interfere with the settings and software that is presently installed for this machine to gain access to the University's network.

With this in mind my best suggestion would be to contact the IT Dept of the University and have them repair the laptop as necessary.
User avatar
MRU Honors Graduate
MRU Honors Graduate
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Redirected from google

Unread postby Gary R » November 13th, 2009, 4:29 am

As this computer is not your property, you do not have the authority to give permission for any work to be done on it.

I strongly recommend you to follow the advice given to you by Dakeyras.

This topic is now closed
User avatar
Gary R
Posts: 21809
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire
Register to Remove

  • Similar Topics
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!

Who is online

Users browsing this forum: No registered users and 9 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware