Still redirects. It doesn't start doing it until I click about 4-6 search results, then from there on it keeps redirecting me. Nothing else though seems to be malfunctioning though.
I can't locate those lines. I noticed in the first hijack log I posted they're there, but the ones I posted after that don't show those lines anymore, here's a recent one;
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:37:09 PM, on 2/8/2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16916)
Boot mode: Normal
Click on the Report tab at the bottom of the program window
Click the Scan button
In the Select Scan dialog, check:
Drivers
Files
Processes
SSDT
Stealth Objects
Hidden Services
Click the OK button
In the next dialog, select all drives showing
Click OK to start the scan
Note: The scan can take some time. DO NOT run any other programs while the scan is running
When the scan is complete, the Save Report button will become available
Click this and save the report to your Desktop as RootRepeal.txt
Go to File, then Exit to close the program
Open RootRepeal.txt file with Notepad, copy, and paste all content into your next reply.
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.
Problem, Got an error upon start up (did not record the error) ran the scan and got an error about the drivers, then another error, and it finished with this log:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/02/08 13:02
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP0
==================================================
Here's one of the errors log, where it says "Could not read system registry, please contact the author"
13:02:46: DeviceIoControl Error! Error Code = 0x0
13:02:46: DeviceIoControl Error! Error Code = 0x0
13:02:46: DeviceIoControl Error! Error Code = 0x0
13:02:46: DeviceIoControl Error! Error Code = 0x0
13:02:46: DeviceIoControl Error! Error Code = 0x0
13:02:46: DeviceIoControl Error! Error Code = 0x0
13:02:46: Could not scan drive C (error 0xc0000024)
13:02:49: Could not scan drive D (error 0xc0000024)
13:02:50: Could not get the name for PID 4.
13:02:50: Could not get the name for PID 448.
13:02:50: Could not get the name for PID 512.
13:02:50: Could not get the name for PID 552.
13:02:50: Could not get the name for PID 560.
13:02:50: Could not get the name for PID 608.
13:02:50: Could not get the name for PID 616.
13:02:50: Could not get the name for PID 624.
13:02:50: Could not get the name for PID 688.
13:02:50: Could not get the name for PID 820.
13:02:50: Could not get the name for PID 892.
13:02:50: Could not get the name for PID 928.
13:02:50: Could not get the name for PID 1032.
13:02:50: Could not get the name for PID 1108.
13:02:50: Could not get the name for PID 1124.
13:02:50: Could not get the name for PID 1200.
13:02:50: Could not get the name for PID 1232.
13:02:50: Could not get the name for PID 1280.
13:02:50: Could not get the name for PID 1400.
13:02:50: Could not get the name for PID 1560.
13:02:50: Could not get the name for PID 1604.
13:02:50: Could not get the name for PID 1632.
13:02:50: Could not get the name for PID 1760.
13:02:50: Could not get the name for PID 1788.
13:02:50: Could not get the name for PID 1804.
13:02:50: Could not get the name for PID 1844.
13:02:50: Could not get the name for PID 1860.
13:02:50: Could not get the name for PID 1868.
13:02:50: Could not get the name for PID 1876.
13:02:50: Could not get the name for PID 1884.
13:02:50: Could not get the name for PID 1904.
13:02:50: Could not get the name for PID 1972.
13:02:50: Could not get the name for PID 1988.
13:02:50: Could not get the name for PID 1544.
13:02:50: Could not get the name for PID 1596.
13:02:50: Could not get the name for PID 1680.
13:02:50: Could not get the name for PID 964.
13:02:50: Could not get the name for PID 1520.
13:02:50: Could not get the name for PID 2360.
13:02:50: Could not get the name for PID 2372.
13:02:50: Could not get the name for PID 2424.
13:02:50: Could not get the name for PID 2604.
13:02:50: Could not get the name for PID 2692.
13:02:50: Could not get the name for PID 2720.
13:02:50: Could not get the name for PID 2772.
13:02:50: Could not get the name for PID 2840.
13:02:50: Could not get the name for PID 2864.
13:02:50: Could not get the name for PID 2936.
13:02:50: Could not get the name for PID 2952.
13:02:50: Could not get the name for PID 2976.
13:02:50: Could not get the name for PID 3248.
13:02:50: Could not get the name for PID 3288.
13:02:50: Could not get the name for PID 3428.
13:02:50: Could not get the name for PID 3968.
13:02:50: Could not get the name for PID 2620.
13:02:50: DeviceIoControl Error! Error Code = 0xc0000024
13:02:50: DeviceIoControl Error! Error Code = 0xc0000024
13:02:55: Warning - the number of SSDT entries from the kernel and the number on-disk are different (0 and 398).
13:02:55: DeviceIoControl Error! Error Code = 0x0
13:02:55: WARNING: The SSDT in our driver has been faked (0x00000250)!
13:02:55: DeviceIoControl Error! Error Code = 0x0
13:02:55: Could not get loaded modules!
13:02:55: DeviceIoControl Error! Error Code = 0xc0000024
13:02:55: FOPS - DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x000000d0)
13:02:55: Could not read system registry! Please contact the author!
* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* Under the Custom Scan box paste this in:
Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
Alternative downloads:
- http://majorgeeks.com/GMER_d5198.html
- http://www.softpedia.com/get/Interne...ers/GMER.shtml
Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
When scan is completed, click Save button, and save the results as gmer.log Warning ! Please, do not select the "Show all" checkbox during the scan. Zip the log, and attach zipped file to your next reply.