Google keeps getting re-directed every time i try and search

Unread postby dansen » August 4th, 2011, 2:22 pm

Hi, I was trying to download a torrent a couple of days ago and by accident seemed to have installed what i think is a really annoying malware virus! Since then instead of it saying www.google.co.uk in the address bar it says http://www.searchqu.com/406 and everytime i try and search on google it re-directs me to a site called uk.search-results.com???
Below is a copy of the 2 logs produced by DDS. I would really appreciate your time to take a look at these, thanks so much in advance!!


DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 7.0.6000.16448
Run by Administrator at 18:50:39 on 2011-08-04
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.3034.1438 [GMT 1:00]
============== Running Processes ===============
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Norton 360\Engine\\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Norton 360\Engine\\ccSvcHst.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\Program Files\GameBox\vprot.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.searchqu.com/406
uWindow Title = Internet Explorer Provided By Sky Broadband
uDefault_Page_URL = hxxp://www.sky.com
uInternet Settings,ProxyOverride = *.local
BHO: iGamesBar Toolbar: {0fef2d2c-cda6-45e4-b2ed-9df7c50c95ff} - c:\program files\gamebox\gamebox_toolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\\ips\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\window~3\datamngr\toolbar\searchqudtx.dll
BHO: UrlHelper Class: {a40dc6c5-79d0-4ca8-a185-8ff989af1115} - c:\progra~1\window~3\datamngr\IEBHO.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\\coIEPlg.dll
TB: iGamesBar Toolbar: {0fef2d2c-cda6-45e4-b2ed-9df7c50c95ff} - c:\program files\gamebox\gamebox_toolbar.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\window~3\datamngr\toolbar\searchqudtx.dll
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe"
uRun: [DriverScanner] "c:\program files\uniblue\driverscanner\launcher.exe" delay 20000
uRun: [Registry Reviver] c:\program files\reviversoft\registry reviver\RegistryReviver.exe
uRun: [vProt] c:\program files\gamebox\vprot.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DATAMNGR] c:\progra~1\window~3\datamngr\DATAMN~1.EXE
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
uPolicies-explorer: NoSMHelp = 1 (0x1)
uPolicies-explorer: NoSMBalloonTip = 1 (0x1)
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: Start_ShowMyMusic = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
dPolicies-explorer: NoSMHelp = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office10\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL
TCP: DhcpNameServer =
TCP: Interfaces\{52C13BC8-6833-473C-9EB5-9220670BA7E4} : DhcpNameServer =
TCP: Interfaces\{B9762E62-7A51-4901-A283-702B5DEC2776} : DhcpNameServer =
TCP: Interfaces\{D99FD116-716E-4695-BFF9-BD5A9E9F4AB4} : DhcpNameServer =
TCP: Interfaces\{E2281D01-DB38-4809-8236-289616B1E270} : DhcpNameServer =
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: gameboxchrome - {494D4E3B-FA53-4487-8AF6-3F50FE1167A9} - c:\program files\gamebox\gamebox_toolbar.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\window~3\datamngr\datamngr.dll c:\progra~1\window~3\datamngr\iebho.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\administrator\appdata\roaming\mozilla\firefox\profiles\jlf3jset.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/sli ... ie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ff ... mid=406&q=
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\ipsffplgn\components\IPSFFPl.dll
FF - component: c:\users\administrator\appdata\roaming\mozilla\firefox\profiles\jlf3jset.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\users\administrator\appdata\roaming\mozilla\firefox\profiles\jlf3jset.default\extensions\gamebox@toolbar\components\toolbarhomewmp.dll
FF - plugin: c:\program files\google\update\\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\3.0.40818.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-5-26 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-5-26 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20110723.001\BHDrvx86.sys [2011-7-23 815736]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20110803.030\IDSvix86.sys [2011-8-4 367736]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-5-26 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys [2011-5-26 331384]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-17 366640]
R2 N360;Norton 360;c:\program files\norton 360\engine\\ccSvcHst.exe [2011-5-26 130008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-7-28 105592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-17 22712]
R3 ucgnsta;BUFFALO WLI-UC-GN Series Wireless LAN Driver;c:\windows\system32\drivers\ucgnsta.sys [2010-9-8 662016]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-29 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-29 136176]
S3 WlanUIG;EDUP 802.11g Wireless LAN USB Adapter Driver;c:\windows\system32\drivers\WlanUIG.sys [2009-9-25 376224]
=============== Created Last 30 ================
2011-07-18 18:00:56 -------- d-----w- c:\program files\uTorrent
2011-07-18 17:58:01 -------- d-----w- c:\users\administrator\appdata\roaming\uTorrent
2011-07-18 17:58:01 -------- d-----w- c:\users\administrator\appdata\local\uTorrent
2011-07-17 15:37:45 -------- d-----w- c:\users\administrator\appdata\roaming\Malwarebytes
2011-07-17 15:37:08 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-17 15:37:04 -------- d-----w- c:\programdata\Malwarebytes
2011-07-17 15:37:01 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-17 15:37:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-16 15:47:32 -------- d-----w- c:\users\administrator\appdata\local\Ilivid Player
2011-07-16 15:45:01 -------- d-----w- c:\program files\iLivid
2011-07-16 15:43:04 -------- d-----w- c:\programdata\boost_interprocess
2011-07-16 15:42:53 -------- d-----w- c:\program files\Windows iLivid Toolbar
2011-07-16 15:41:31 -------- d-----w- c:\users\administrator\appdata\local\PackageAware
==================== Find3M ====================
2011-06-01 06:47:17 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-26 11:45:57 126584 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
============= FINISH: 18:53:11.61 ===============

and finally Attach.txt

DDS (Ver_2011-06-23.01)
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 9/25/2009 2:07:46
System Uptime: 8/4/2011 12:15:35 (6 hours ago)
Motherboard: Dell Inc. | | 0G848F
Processor: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz | Microprocessor | 2000/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 149 GiB total, 26.854 GiB free.
D: is CDROM ()
E: is Removable
==== Disabled Device Manager Items =============
Class GUID:
Description: Network Controller
Device ID: PCI\VEN_14E4&DEV_4315&SUBSYS_000C1028&REV_01\4&1B317842&0&00E1
Name: Network Controller
PNP Device ID: PCI\VEN_14E4&DEV_4315&SUBSYS_000C1028&REV_01\4&1B317842&0&00E1
Class GUID:
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_2930&SUBSYS_02AA1028&REV_03\3&18D45AA6&0&FB
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_2930&SUBSYS_02AA1028&REV_03\3&18D45AA6&0&FB
==== System Restore Points ===================
==== Installed Programs ======================
ABBYY FineReader 6.0 Sprint
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.3
Apple Software Update
Camera RAW Plug-In for EPSON Creativity Suite
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
EPSON Attach To Email
EPSON Easy Photo Print
EPSON File Manager
EPSON Scan Assistant
EPSON Stylus SX200_SX400_TX200_TX400 Manual
EPSON Stylus SX400 Series Printer Uninstall
Google Chrome
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Deskjet 1050 J410 series Basic Device Software
HP Deskjet 1050 J410 series Help
HP Deskjet 1050 J410 series Product Improvement Study
HP Photo Creations
HP Update
iGamesBar Toolbar
Intel(R) Graphics Media Accelerator Driver
Malwarebytes' Anti-Malware version
Marvell Miniport Driver
Microsoft .NET Framework 3.5 SP1
Microsoft Office 2000 SR-1 Premium
Microsoft Office Professional Edition 2003
Microsoft Office XP Professional with FrontPage
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox 5.0.1 (x86 en-US)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Norton 360
OLYMPUS Master 2
OLYMPUS muvee theaterPack
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio 3
Sky Broadband
Sky Broadband Browser Branding
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VideoLAN VLC media player 0.8.6f
WIDCOMM Bluetooth Software
Winamp Detector Plug-in
Windows iLivid Toolbar
Windows Live ID Sign-in Assistant
WinRAR archiver
==== Event Viewer Messages From Past Week ========
8/4/2011 12:16:06, Error: EventLog [6008] - The previous system shutdown at 8:04:39 PM on 8/3/2011 was unexpected.
8/3/2011 14:01:51, Error: EventLog [6008] - The previous system shutdown at 9:34:10 PM on 8/2/2011 was unexpected.
8/2/2011 18:42:15, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease for the Network Card with network address 0024A57F7541 has been denied by the DHCP server (The DHCP Server sent a DHCPNACK message).
8/2/2011 18:42:09, Error: EventLog [6008] - The previous system shutdown at 3:19:21 AM on 8/2/2011 was unexpected.
8/1/2011 21:03:43, Error: EventLog [6008] - The previous system shutdown at 6:05:36 PM on 8/1/2011 was unexpected.
7/28/2011 16:27:31, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
==== End Of File ===========================
Active Member
Posts: 1
Joined: August 4th, 2011, 1:46 pm
Re: Google keeps getting re-directed every time i try and se

Unread postby askey127 » August 5th, 2011, 7:34 pm

Hi dansen,
Please Note Our Policy on the Use of P2P (Person to Person / Peer to Peer) file sharing programs
It is posted here: http://malwareremoval.com/forum/viewtopic.php?p=491394#p491394
As a condition of receiving our help, I have included the P2P program µTorrent in the removal instructions below, so we are not wasting our time.
If you have used this, and your computer is infected, you can be fairly confident this is a principal reason.

It's really important, if you value your PC at all, to stay away from P2P file sharing programs, like utorrent, Bittorrent, Azureus, Frostwire, Vuze, Shareaza, Bitlord.
(Limewire has been shut down by the courts).
Criminals have "planted" thousands upon thousands of infections in the "free" shared files.
Virtually all of these recent infections will compromise your Security, and some can turn your machine into a useless "doorstop".
Remove Programs Using Control Panel
From Start, Control Panel, click on Uninstall a program under the Programs heading.
Right click each Entry, as follows, one by one, if it exists, choose Uninstall/Change, and give permission to Continue:


Take extra care in answering questions posed by any Uninstaller.
Download the OTL Scanner
Please download OTL.exe by OldTimer and save it to your desktop.
Run a Scan with OTL
    Right click the OTL icon and choose "Run as administrator"
    Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, choose Scan All Users.
  • In the Standard Registry box, choose All.
  • Make sure the boxes beside LOP Check and Purity Check are checked.
  • Copy the text in the code box below and paste it into the Custom Scans/Fixes box (under the cyan line at the bottom of the window)
    Code: Select all
    c:|Fun4IM;true;true;true; /FP
    c:|Bandoo;true;true;true; /FP
    c:|Searchqu;true;true;true; /FP
    c:|iLivid;true;true;true; /FP
    c:|whitesmoke;true;true;true; /FP
    c:|sweetIM;true;true;true; /FP
    |Fun4IM /RS
    |Bandoo /FP
    |Searchqu /RS
    |iLivid /RS
    |whitesmoke /RS
    |sweetIM /RS
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. (desktop)
The Extras.txt file will only appear the very first time you run OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them as a reply. Use separate replies if more convenient.
User avatar
Posts: 13901
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Google keeps getting re-directed every time i try and se

Unread postby askey127 » August 9th, 2011, 7:32 am

Due to Lack of Response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
Posts: 13901
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

