Jump to content

Mediashifting redirect/hijacker

Recommended Posts

Got this, malware, trojan type fellow sneaking around my Sys32, constantly redirects my search results to crappy advertisement websites and stuff. Makes it difficult to counteract because the best way to find solutions tends to be through troubleshooting with everyone's favorite search engine x3 Well, anyways. It appears that every restart it comes back, MBAM can delete it again, and it'll just come back, yet again. So some help would be greatly appreciated :)

A snip from MBAM log, where i believe it had removed the malware one time.

Files Infected:

c:\program files\Opera\sname (Spyware.Agent) -> Quarantined and deleted successfully.

c:\documents and settings\Owner\local settings\Temp\0.272254941475362.exe (Malware.Packer) -> Quarantined and deleted successfully.

c:\documents and settings\Owner\local settings\Temp\0.9535693099873207.exe (Malware.Packer) -> Quarantined and deleted successfully.

It had previously also removed some files from Sys32 labelled as Trojans.

Anddddd, onto the DDS logs;


DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18702

Run by Owner at 17:33:27 on 2011-12-22

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2559.1912 [GMT -5:00]



============== Running Processes ===============



C:\WINDOWS\system32\svchost -k DcomLaunch








C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\TP-LINK\TL-WN321G\COMMON\RegistryWriter.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files\Opera\opera.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs


C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Windows Live\Contacts\wlcomm.exe



C:\Program Files\Winamp\winamp.exe


============== Pseudo HJT Report ===============


uStart Page = hxxp://www.google.com/

uSearch Page = hxxp://www.google.com/

uDefault_Search_URL = hxxp://www.google.com/

uDefault_Page_URL = hxxp://www.google.com/

uInternet Settings,ProxyOverride = *.local

mWinlogon: SfcDisable=-99 (0xffffff9d)

BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll

uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background

uRun: [steam] "c:\program files\steam\steam.exe" -silent

uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c

uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun

uRun: [Akamai NetSession Interface] "c:\documents and settings\owner\local settings\application data\akamai\netsession_win.exe"

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

mRun: [PlusService] c:\program files\yuna software\messenger plus!\PlusService.exe

mRun: [startCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun

mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"

mRun: [iMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC

mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC

mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [bCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices

mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"

mRun: [Freecorder FLV Service] "c:\program files\freecorder\FLVSrvc.exe" /run

mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" --auto-start

mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript

dRun: [ctfmon.exe] ctfmon.exe

dRun: [iDMan] c:\program files\internet download manager\IDMan.exe /onboot

dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tl-wn3~1.lnk - c:\program files\tp-link\tl-wn321g\common\TWCU.exe

uPolicies-explorer: NoResolveTrack = 1 (0x1)

uPolicies-explorer: NoInstrumentation = 1 (0x1)

uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)

uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)

mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)

dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)

dPolicies-explorer: NoResolveTrack = 1 (0x1)

dPolicies-explorer: NoInstrumentation = 1 (0x1)

dPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)

dPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)

IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\owner\start menu\programs\imvu\Run IMVU.lnk

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

LSP: mswsock.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab

DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab

TCP: Interfaces\{AEDD8D55-F093-4110-B9B8-B439E4ED4B70} : DhcpNameServer =

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL

Notify: AtiExtEvent - Ati2evxx.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SecurityProviders: schannel.dll, credssp.dll, digest.dll


================= FIREFOX ===================


FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\tvcxw9wy.default\

FF - prefs.js: browser.startup.homepage - chrome://foxtab/content/homepage.html

FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll

FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\\npGoogleUpdate3.dll

FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL

FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll



FF - user.js: network.protocol-handler.warn-external.dnupdate - false

============= SERVICES / DRIVERS ===============


R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-8-26 232512]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-9-16 366152]

R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\tp-link\tl-wn321g\common\RegistryWriter.exe [2011-6-30 69632]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-9-16 22216]

R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [2011-8-9 27136]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2011-8-15 1361288]

S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]

S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]

S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]

S3 TunngleService;TunngleService;c:\program files\tunngle\TnglCtrl.exe [2011-12-7 747880]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

S3 XDva390;XDva390;\??\c:\windows\system32\xdva390.sys --> c:\windows\system32\XDva390.sys [?]

S3 XDva391;XDva391;\??\c:\windows\system32\xdva391.sys --> c:\windows\system32\XDva391.sys [?]


=============== Created Last 30 ================


2011-12-22 22:21:46 54016 ----a-w- c:\windows\system32\drivers\ubgec.sys

2011-12-22 22:14:23 54016 ----a-w- c:\windows\system32\drivers\vivedpii.sys

2011-12-22 18:53:41 26176 ---ha-w- c:\windows\system32\hamachi.sys

2011-12-22 10:12:06 28160 ----a-w- c:\windows\system32\dll.dll

2011-12-22 10:12:01 295042 ----a-w- c:\windows\system32\shimg.dll

2011-12-22 10:12:00 -------- d-sh--w- c:\documents and settings\owner\local settings\application data\2b1987dd

2011-12-20 18:58:55 -------- d-----w- c:\documents and settings\owner\application data\PriceGong

2011-12-20 11:00:34 -------- d-----w- c:\program files\Conduit

2011-12-20 11:00:26 -------- d-----w- c:\documents and settings\owner\local settings\application data\Temp

2011-12-20 11:00:26 -------- d-----w- c:\documents and settings\owner\local settings\application data\Conduit

2011-12-20 11:00:12 -------- d-----w- c:\documents and settings\owner\local settings\application data\FLVService

2011-12-18 17:44:01 -------- d-----w- c:\documents and settings\owner\local settings\application data\Winamp Toolbar

2011-12-18 17:39:04 -------- d-----w- c:\documents and settings\owner\local settings\application data\Chromium

2011-12-18 16:51:16 -------- d-----w- c:\documents and settings\owner\local settings\application data\Overwolf

2011-12-18 14:25:04 -------- d-----w- c:\documents and settings\owner\application data\FOG Downloader

2011-12-16 10:27:10 -------- d-----w- c:\program files\Winamp Detect

2011-12-16 10:27:07 -------- d-----w- c:\program files\Winamp Toolbar

2011-12-16 10:27:07 -------- d-----w- c:\documents and settings\all users\application data\Winamp Toolbar

2011-12-15 04:42:29 -------- d-----w- c:\program files\Microsoft Synchronization Services

2011-12-15 04:41:31 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition

2011-12-15 04:41:31 -------- d-----w- c:\documents and settings\all users\Microsoft

2011-12-15 04:39:08 -------- d-----w- c:\documents and settings\owner\local settings\application data\Microsoft Help

2011-12-13 10:40:14 -------- d-----w- c:\program files\SystemRequirementsLab

2011-12-12 02:05:14 421200 ----a-w- c:\windows\system32\msvcp100.dll

2011-12-12 02:05:12 768848 ----a-w- c:\windows\system32\msvcr100.dll

2011-12-09 17:23:32 12800 ----a-w- c:\program files\mozilla firefox\plugins\npwachk.dll

2011-12-08 08:01:22 -------- d-----w- c:\documents and settings\owner\local settings\application data\APN

2011-12-08 00:39:29 -------- d-----w- c:\program files\Tunngle

2011-12-07 08:05:52 -------- d-----w- c:\program files\mIRC

2011-12-07 08:05:52 -------- d-----w- c:\documents and settings\owner\application data\mIRC

2011-12-07 07:03:15 -------- d-----w- c:\documents and settings\owner\.irssi

2011-11-29 09:13:10 -------- d-----w- c:\documents and settings\owner\application data\.spoutcraft


==================== Find3M ====================


2011-11-15 11:30:55 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-11-01 06:08:37 151552 ----a-w- c:\windows\system32\nvRegDev.dll

2011-10-01 18:01:20 2205064 ----a-w- c:\documents and settings\all users\application data\shs_setup_4059-354328.exe

2011-09-26 04:04:13 73216 ----a-w- c:\windows\ST6UNST.EXE

2011-09-26 04:04:13 249856 ------w- c:\windows\Setup1.exe


============= FINISH: 17:33:55.45 ===============





DDS (Ver_2011-08-26.01)


Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 6/30/2011 6:25:05 AM

System Uptime: 12/22/2011 4:51:19 PM (1 hours ago)


Motherboard: Hewlett-Packard | | 085Ch

Processor: Intel® Pentium® 4 CPU 2.60GHz | XU1 PROCESSOR | 2593/800mhz


==== Disk Partitions =========================


A: is Removable

C: is FIXED (NTFS) - 75 GiB total, 14.757 GiB free.

D: is CDROM ()

G: is CDROM ()


==== Disabled Device Manager Items =============


Class GUID:

Description: Ethernet Controller

Device ID: PCI\VEN_14E4&DEV_1696&SUBSYS_12BC103C&REV_03\4&3A321F38&0&10F0


Name: Ethernet Controller

PNP Device ID: PCI\VEN_14E4&DEV_1696&SUBSYS_12BC103C&REV_03\4&3A321F38&0&10F0



Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}

Description: PS/2 Compatible Mouse

Device ID: ACPI\PNP0F13\4&369939D9&0

Manufacturer: Microsoft

Name: PS/2 Compatible Mouse

PNP Device ID: ACPI\PNP0F13\4&369939D9&0

Service: i8042prt


==== System Restore Points ===================


No restore point in system.


==== Installed Programs ======================



3dsmax ancillary install

Ace of Spades

Adobe AIR

Adobe Community Help

Adobe Flash Player 11 Plugin

Adobe Photoshop CS5.1

Adobe Shockwave Player 11.6

Age of Empires Online

Apple Application Support

Apple Mobile Device Support

Apple Software Update

ATI - Software Uninstall Utility

ATI Catalyst Control Center

ATI Display Driver



Bandisoft MPEG-1 Decoder

Blender (remove only)


Canon CanoCraft CS-P 3.8

Canon ScanGear Toolbox CS 2.2

Catalyst Control Center - Branding

Catalyst Control Center Core Implementation

Catalyst Control Center Graphics Full Existing

Catalyst Control Center Graphics Full New

Catalyst Control Center Graphics Light

Catalyst Control Center Graphics Previews Common

Catalyst Control Center HydraVision Full

Catalyst Control Center Localization All




CCC Help Chinese Standard

CCC Help Chinese Traditional

CCC Help Czech

CCC Help Danish

CCC Help Dutch

CCC Help English

CCC Help Finnish

CCC Help French

CCC Help German

CCC Help Greek

CCC Help Hungarian

CCC Help Italian

CCC Help Japanese

CCC Help Korean

CCC Help Norwegian

CCC Help Polish

CCC Help Portuguese

CCC Help Russian

CCC Help Spanish

CCC Help Swedish

CCC Help Thai

CCC Help Turkish


Command and Conquer: Red Alert 3

Compatibility Pack for the 2007 Office system

Counter-Strike: Source

DAEMON Tools Lite

DDS Thumbnail Viewer


FileZilla Client 3.5.1

Foxit Reader 5.0

Fraps (remove only)

FrostWire 4.21.8

GoldWave v5.58

Google Chrome

Harvest: Massive Encounter

Hero Editor V0.95

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Windows XP (KB954550-v5)

IMVU Avatar Chat Software

IrfanView (remove only)


Java 6 Update 24

JDownloader 0.9

Junk Mail filter update

League of Legends

Livestream Procaster

LogMeIn Hamachi



Malwarebytes' Anti-Malware version

Messenger Plus! 5

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 2

Microsoft .NET Framework 3.5 SP1

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Application Error Reporting

Microsoft Choice Guard

Microsoft Games for Windows - LIVE Redistributable

Microsoft Games for Windows Marketplace

Microsoft Office Excel Viewer

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (Spanish) 2010

Microsoft Office Proofing (English) 2010

Microsoft Office Shared MUI (English) 2010

Microsoft Office Shared Setup Metadata MUI (English) 2010

Microsoft Office Word 2010

Microsoft Office Word MUI (English) 2010

Microsoft Office Word Viewer 2003

Microsoft Silverlight

Microsoft Software Update for Web Folders (English) 14

Microsoft VC9 runtime libraries

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - SP1 x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Microsoft Windows Journal Viewer

Microsoft Word 2010

Microsoft XNA Framework Redistributable 4.0










Mozilla Firefox 8.0 (x86 en-US)



MSXML 6.0 Parser

Mumble 1.2.3

Nexon Game Manager


NVIDIA Photoshop Plug-ins

Opera 11.60

Pando Media Booster

PDF Settings CS5

Python 2.6.6


S4 League_EU

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Windows Internet Explorer 8 (KB2510531)

Security Update for Windows Internet Explorer 8 (KB2530548)

Security Update for Windows Internet Explorer 8 (KB2544521)

Security Update for Windows XP (KB2412687)

Security Update for Windows XP (KB2476490)

Security Update for Windows XP (KB2485663)

Security Update for Windows XP (KB2503665)

Security Update for Windows XP (KB2506212)

Security Update for Windows XP (KB2506223)

Security Update for Windows XP (KB2507618)

Security Update for Windows XP (KB2508272)

Security Update for Windows XP (KB2508429)

Security Update for Windows XP (KB2509553)

Security Update for Windows XP (KB2524375)

Security Update for Windows XP (KB2535512)

Security Update for Windows XP (KB2536276)

Security Update for Windows XP (KB2544893)

Segoe UI


Skype™ 5.5

Source SDK

Source SDK Base 2007



System Requirements Lab CYRI

TeamSpeak 3 Client

TeamViewer 6


TL-WN321G Wireless Utility

Tunngle beta

Unlocker 1.9.0

Update for Windows XP (KB2541763)

Ventrilo Client

VLC media player 1.1.10

WebFldrs XP


Winamp Detector Plug-in

Winamp Toolbar

Windows Live Call

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Mail

Windows Live Messenger

Windows Live OneCare safety scanner

Windows Live Upload Tool

Windows Live Writer

WinRAR 4.00 (32-bit)

Worms Reloaded

Zune Desktop Theme


==== End Of File ===========================

Thanks for your assistance ahead of time. Looking forward to it :D

Link to post
Share on other sites

  • 1 month later...

Hello leminlyme,

Would you advise if you have resolved your issues or if you have sought help elsewhere?

If not resolved and you are not already seeking help elsewhere, I'd like for you to rerun a new (fresh) DDS and Copy & Paste the DDS.txt into a new reply.

Anyone other than original-poster who has similar issues, do not reply here. Start your own topic.

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.