Browser Hijacker - Gone as far as I can go

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mimimak, Mar 20, 2013.

  1. mimimak

    mimimak Private E-2

    Hello!
    I am trying to help clean my sister in law's computer. The problem started about a month and a half ago. She could not connect to the internet then I believe she did a windows update where the computer screen went black and she could not boot up. I got into safe mode, did a system restore, then noticed the extra tool bars on her browser which made me think virus/trojan/etc. Had a lot of trouble running online scans as they were being blocked from running but finally managed over time to clean a significant amount of items off the system. I believe she had Sardu, Yontoo, and a host of other unwanteds. Now, the final annoyance (there may still be more stuff) is a browser hijacker that will not go away. A Searchqu/search.fantastigames.com popup message keeps popping up when first opening IE. It says "The original search engine Fantastigames.com was changed from being the default and will change back." You close out the popup and it takes you to the manage add ons window but you can not delete the searchqu selection which is in third position. Tried to clean remnants of searchqu in registry from all the "known" items I could find from internet searches but problem still exists. Any help you can provide would greatly be appreciated. I hope I followed all directions correctly. All logs requested are attached below.

    Thanks in advance, Mimi
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am only finding traces of it in your registry, so let's just do this:

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Tell me it things are improved now.
     
  3. mimimak

    mimimak Private E-2

    Hi Tim,
    Thanks for helping me. I got a successful message in updating the registry but the problem remains. I rebooted to see if that would help and it did not. Upon opening IE, I get a popup that tells me "a program on the computer corrupted my default search provider setting for IE, changing back to default (search.fantastigames.com). When I close or "x" out of it, it procedes to open the manage add ons window but I can't change or delete the default from search.fantastigames.com.

    Also, not sure if this is related but I could not find the accessories folder on this computer from clicking Start/All programs? I found notepad and wordpad in a c:\program files\win NT\accessories folder and in c:\windows\winsxs\amd64_microsoftwindows folder (duplicates)? But other tools are just missing altogether like calculator. The laptop is Lenovo with Windows 64bit. Is it possible it is just set up differently? I have not done anything to the computer since uploading my log files as requested but weeks ago I tried to do a partial restore where you look for just the folder you want and move it over but it was not there? My sister-in-law did not even know it was missing so she could not tell me how far back this goes. I am trying to avoid a complete restore for her but do not want to waste your time if I have to do that in the end?

    Please let me know next steps.

    Thanks,
    Mimi
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run MGTools by clicking on the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
    Attach the new C:\MGLogs.zip.
     
  5. mimimak

    mimimak Private E-2

    Re-ran the MG tools as requested. Here you go. Thanks.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Reboot and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new MGLogs.zip.
     
  7. mimimak

    mimimak Private E-2

    Hi Tim,

    Got a successful message when updating the registry. Ran MGTools again as requested. Pop up still showing up and redirection still occurs. In the middle of the scan, by the way, I got a message that Steelwerx stopped working. Once I closed out it continued and gave me the log file. See Attached.

    Thanks,
    Mimi
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How comfortable do you feel about editing your registry? We need to delete this key:
    Code:
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "Version"=dword:00000003
    "UpgradeTime"=hex:ae,ff,6f,88,b4,12,ce,01
    "DefaultScope"="{9BB47C17-9C68-4BB3-B188-DD9AF0FD2455}"
     
  9. mimimak

    mimimak Private E-2

    I am very comfortable with deleting out of the registry in fact I had to manually delete the parts of this virus/trojan from the registry as no scan was picking it up and I ran so many of them (eset, f-secure, spybot, malwarebytes, to name a few). I deleted the items requested but not sure if you wanted me to delete the whole searchscopes folder (there were 3 subfolders with a long string of numbers) as there were other items in there? I rebooted and checked and it is still popping up and redirecting after the first search. When I went back into the registry those keys you asked me to delete are populated with new entries (if I am saying it correctly).

    Thanks,
    Mimi
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After doing the below, re-run C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  11. mimimak

    mimimak Private E-2

    Hello!

    I edited the registry as instructed and got a successful message. Attached is the log file requested. FYI, The pesky little buggar still popped up when I opened IE.

    Thanks Tim,
    Mimi
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Pesky little devil.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Look through your registry for {9BB47C17-9C68-4BB3-B188-DD9AF0FD2455}.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new log.
     
  13. mimimak

    mimimak Private E-2

    Hello,

    The registry was edited instructed and I got a successful message. Attached is the log file requested. No change in IE.

    Thanks,
    Mimi
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  15. mimimak

    mimimak Private E-2

    Hi Tim,

    I edited the registry as instructed. Did not run MGtools as you did not request this last time. Please let me know if you need an updated log. I wish I had good news but the stupid thing is still in there.....hijacking!! :confused

    Thanks,
    Mimi
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now please follow the instructions in the below link to Reset IE back to defaults.

    http://windows.microsoft.com/en-us/windows7/reset-internet-explorer-settings-in-internet-explorer-9

    Make sure you now exit IE.

    Now reopen IE and tell us your status.

    If you still have a problem with IE, please download System Repair Engineer from the below site:

    System Repair Engineer


    Extract the files from the ZIP file you downloaded to your Desktop. And then right click on the SREngLdr.EXE file and select Run As Administrator. If you get any warnings from protection software, please just allow it to run.
    • Once it opens, select the Smart Scan icon in the left colum.
      • Now leave all check boxes selected as they are by default
      • Then click the Scan button on the bottom and a scan will begin
      • Wait for it to finish scanning ( be patient as it can take awhile to complete all scans). If you get any warnings from protection software while it is scanning, please ignore them.
      • When it finishes the scan, a Detail Reports form will pop up. Click the Save Reports button.
      • Save the SREngLOG.log file to your Desktop to make it easy to find and attach it to your next message.
      • Now close the Detail Reports form with the Close button.
    • Now click the System Repair icon in the left column.
    • On the next form select the Browser Add-ons tab along the top.
    • Does it list any of the items you are having a problem with?
    • If yes, select the item line and then click the Delete Selected button on the bottm of the form.
    • If you found any items to delete, did it delete or did you get an error message.
    • Now exit System Repair Engineer.
    • Also shutdown ALL browser sessions ( including the one where you are reading this )and then restart IE.
    • Does the problem still occur?
    Attach the SREngLOG.log file to your next message and explain what happened if you had any problems with the above.
     
    Last edited: Mar 31, 2013
  17. mimimak

    mimimak Private E-2

    Hello. I reset IE as instructed then opened IE and the popup still came up. Searchqu is still in there as a search option unable to delete. I then downloaded the System Repair and followed your directions. Once Sys. Repair was done (I did not have any issues) I rebooted and the popup stil remained. Under the browser add-on tab, I did not delete anything as none of the selections said searchqu or search.fantistigames.com or datamanager. I did see an activex for Unity webplayer control (which I am not sure what this is) I think was something downloaded by my sister-in-law's 11yr old. Could the virus be attached to that? I also noticed activeX controls that had a CLSID number in the registry but no name associated. Attached is the log file from System Repair.

    Thank,
    Mimi
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Are you sure that when you did the Reset of IE that you did the below?
    • In the Reset Internet Explorer Settings dialog box, click Reset.
    • Click to select the Delete personal settings check box if you also want to remove browsing history, search providers, Accelerators, home pages, Tracking Protection, and ActiveX Filtering data.
    I need to understand better what you mean.
    • Does this mean when you first run IE that you really get an additional popup window/form? That is what popup means to us.
    • Or do you mean that when you first run IE that your start page ( home page ) opens up to something related to Searchqu ( or something else that you do not expect )?
    And by this, do I understand that this is a second problem from the above?

    Can you attach a snapshot of exactly what you are seeing because nothing is showing in your logs related to home page/start page issues. Nor is anything showing in search settings.
     
  19. mimimak

    mimimak Private E-2

    Sorry it took a while to respond. Was not able to do a screen capture as her accessories folder is missing. So no snipping tool, no paint program. Think this issue is from a windows update but that is for another forum. :eek So I tried resetting IE again since you thought maybe I didn't do it right and the third time it took!! So after resetting, now bing is the only search provider listed and Lenovo (what the system is) is the homepage. Upon opening IE though, I get the manage addons window popup every time. I rebooted and opened IE and still get the manage addons window popping up after the homepage loads (see attached afterresett.jpg). That makes me nervous that it is not entirely clean. I followed the reset by a system repair and will attach that new log just in case you need it. For the heck of it, I am attaching the other screen captures that happened previous to show you what I saw. Maybe it will help? Also, to answer your questions as to what was happening, I was getting a popup after homepage loaded, then the manageaddon window, then after doing a search or two from the URL field, I got the fantastigames metacrawler search. I try to keep it short so I may not have explained myself clearly. Hope that explains everything.

    Thanks, Mimi
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  21. mimimak

    mimimak Private E-2

    Well, not exactly. I don't get the manage add-on notification popup at the bottom of the screen as in the example you provided from worldstart but I still followed their directions on creating a new shortcut since I was gettting "a" manage add-on dialog box window popping up. I deleted IE off the start menu and from the desktop and created a new shortcut for both. The popup is occuring. In this case, it is an actual dialog box window for the manage addons selections. The same one you would see if you were in IE and clicked from the drop down menu "Manage Add-ons". What leads me to believe there may still be something going on, is because one it keeps popping up upon opening IE and two because it will now not let me delete bing as the search provider and use google or use google as the default provider. Look at the two attachments I provided. The first attachment called searchselection (posted yesterday, having trouble reattaching to this message) where the manage addon window popped up to show 3 choices. Searchqu/search.fantastigames was not an intentionally installed choice and when you look at the bottom, "Set as default" and "Remove" is grayed out, will not let me change. Since resetting IE, this selection is no longer there so we are getting better, but now bing is acting in the same manner, grayed out will not let me delete. See my second attachment (called managepopup) where I highlighted the bottom buttons? They are unavailable where previous I could delete Bing. When I select Google, I can remove but when I try to set as default (which is not grayed out by the way) it will not work, Bing remains the default.

    If you no longer see traces of any virus, could a .dll, .ocx, or other IE file be corrupted? Should I try to reinstall IE9? Will that help? If so, do I need to entirely remove traces of IE from the system? or just install over?

    Thanks,Mimi
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  23. mimimak

    mimimak Private E-2

    Hi Tim,

    I have been running explorer without addons. I get the notification window that lets me know plus when the manage addon window pops up you can see they are all disabled. I tried so many different things. However, I never disabled the way described below in your link provided. So, I followed their suggestions and when I opened IE using the method below, the popup still came up. Please don't give up on me. :(
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read this whole message before doing anything.

    Hold down the Windows log key while also pressing the R key. This should open up the Run box form. Copy and paste the below into the run box but DO NOT hit enter or click OK until you close ALL browsers sessions including what you are reading in right now.

    C:\Program Files\Internet Explorer\iexplore.exe


    The above will directly run Internet Explore without any command line options. When you ran it this way, do you still have a problem.
     
  25. mimimak

    mimimak Private E-2

    Hi,

    I copied and pasted the text as instructed. When I ran it this way, IE did open and the popup still opened up too.

    Thanks,
    Mimi
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is still not looking like a malware problem. Back in message number 21 you were trying to delete Bing. Don't do this. Instead just select the line with Google and right click on it and select Set As Default

    Which ever search engine you set as default will then show with the Set As Default and Remove buttons disabled.
     
  27. mimimak

    mimimak Private E-2

    Hi,

    It may no longer be a malware problem but it started out as one. This system had Strong Vault, Yontoo and a host of others. When I do a google search for search.fantastigames.com it comes up that this thing completely messes with your browser. That is why I think this popup will not go away. In message #21 I also mention that I can not select google as my default. It appears as if I can because it is not grayed out but when I press it nothing happens. Bing stays in first position and cannot be deleted. When the search.fantastigames.com selection was there it behaved the same way. Whatever is in that box should allow you to remove, set as default, move up or down. If it does not something is wrong. That is what is going on in addition to this box opening as soon as I open the browser. No matter how many times I close the browser and re-open, the manage add-on window keeps opening.

    Hope that helps to clarify a bit more.
    Mimi
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it, shutdown ALL Internet Explore browsers first and then double click fixme.reg and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Then reboot your PC.

    After reboot, now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  29. mimimak

    mimimak Private E-2

    I wanted to thank you guys for helping me with my sister-in-law's computer. You definitely helped me remove all remnants of the virus. Unfortunately she needed the system back as her other one got infected with a virus as well! LOL I was able to clean that one fairly quickly though. Before giving her back the laptop, I did do the final steps below and the pop-up remains but she is okay with just closing it out for now. If it continues to be a nuisance for her I might have to revisit the issue and maybe in different forum as there is no more virus but just wanted to let you know so you can close this out.

    Thanks,
    Mimi
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We can always revisit it later if it becomes a problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds