makemesearch internet explorer hijack!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rebellor, Sep 14, 2004.

  1. rebellor

    rebellor Private E-2

    Hi. This is my first post on a forum site.

    I've been hijacked! I am running Windows 2000. Troubles started 2 weeks ago. First my homepage was hijacked with a "www.makemesearch.com" webpage. Then my Norton SystemWorks 2004 stopped working. It kept on turning off on it's own...including the antivirus! I uninstalled it and re-installed it but it doesn't work, unless in safe mode. I also had a whole bunch of pop-ups and favorites added to my computer. I've tried everything. I have gone through all the steps provided on your website including all the virus checks and spyware checks. Spybot keeps detecting DSOEXploit but can't get rid of it. I have a HJT log and can post it if you want. Is there any hope here?? THanks for your help.

    rebellor
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ignore the DSO Exploit. It is a bug in SpyBot. If you have run everything from the READ ME and also have observed the requirements for HijackThis log posting in the tutorial for HJT, post your log as a .txt file attachment.
     
  3. rebellor

    rebellor Private E-2

    Hi.

    Here's the Hijack Log. I managed to get rid of the makemesearch hijack by deleting it in "Add/Remove Programs". However, I now have a blue pop-up toolbar at the bottom of my computer screen that I had gotten rid of before but it has re-appeared. Here's my HJT lock. Thanks again. Much appreciated.

    Rebellor
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.xxtypzznlpz.com/LPPy/dnBA6jkW7qDjNg7OAbgSUzV1dePrUS8H6cdWf1w3SpLK2s_rTblc_wAike6.html
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {D1E95FF4-2022-C6E1-41E4-19ACB2781A45} - C:\PROGRA~1\setup32\RoamArmy.exe
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    And unless you know what the two items below are for, fix them two:
    O4 - HKLM\..\Run: [drivepile] C:\PROGRA~1\BROWSE~1\DeleteFlawLicense.exe
    O4 - HKLM\..\Run: [Bike hope dale once] C:\Documents and Settings\All Users\Application Data\Manager Okay Bike Hope\aimmulti.exe

    Make sure you still have viewing of hidden files enable (per the tutorial).
    The boot into safe mode and delete the following:
    C:\PROGRA~1\setup32\RoamArmy.exe
    And if you fixed these above with HJT, delete these too:
    C:\PROGRA~1\BROWSE~1 <--- delete the whole directory
    C:\Documents and Settings\All Users\Application Data\Manager Okay Bike Hope <--- delete the whole directory

    Then reboot noraml and post a new HJT log attachment and tell me how things are working now.
     
  5. rebellor

    rebellor Private E-2

    Hi.

    I think things are working O.K.. THe blue pop-up bar at the bottom is gone. The pop-ups have stopped (at least for now). The home page is staying at what I've set it at. THings look great!!! Thank you so much. I've attached the HJT log since making the changes you suggested. Any thing else I should do (other than what's posted on the website??)

    rebellor
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds better. But I don't think we are done.

    This line is still there:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.qnucmzbaqc.net/LPPy/dnBA6jkW7qDjNg7OAbgSUzV1dePrUS8H6cdWf1za3apwJqpVjblc_wAike6.html


    And I asked you if you new what this was along with another item that is now gone:
    O4 - HKLM\..\Run: [drivepile] C:\PROGRA~1\BROWSE~1\DeleteFlawLicense.exe

    What is this? It does not look valid to me. Did you try to clean it up last time?
     
  7. rebellor

    rebellor Private E-2

    Hi.

    This line wouldn't go away.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.qnucmzbaqc.net/LPPy/dnBA...blc_wAike6.html

    I tried to fix it with HJT. Everytime I scanned with HJT the web address would change and it when I asked it to fix it and re-scanned a new line would be there

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http:// but witha different www address. I don't know what to do about it.


    Also I didn't know what this was:

    O4 - HKLM\..\Run: [drivepile] C:\PROGRA~1\BROWSE~1\DeleteFlawLicense.exe

    and I told HJT to delete it. I guess it didn't work.

    What should I do now?

    Also, my main original problem was that my Norton SYstemWorks 2004 stopped working with all this. With all the on-line virus checks and spyware checkers, I did find some worms and deleted them. I tried re-installing Systemworks but it can't do the LiveUpdate. IT says a program is waiting for a virus-scan of some files (HH.prg and alufixit.prg were two of programs it mentioned).

    I really apprecaite all your help. THanks again.

    rebellor
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have updated to Ad-Aware SE 1.05. And double check for Reference updates. Now also make sure you have the Ad-Aware VX2 Cleaner Plug-In installed.

    Then I want you to download FINDnFIX from here: http://downloads.subratam.org/FINDnFIX.exe

    Run FINDnFIX.exe, it will extract some files to a folder called c:\findnfix
    Don't do anything else with this for now.

    Print these instructions or save them locally because you need to be offline the rest of the way thru and do not open any browser windows until told to.
    1. Reboot into safe mode without networking support
    2. Disable your Anti Virus (AVPersonal)
    3. Open Adaware SE and click Scan now and then select Scan volume for ADS. Click the underlined word 'Select' and put a check mark on your C drive ( C:\ ) and uncheck the Search for negligible risk entries. Now perform the scan.
    4. Save the log to alog1.txt
    5. Check any object found and quarantine them
    6. Now using Ad-Aware SE again choose 'Perform a full scan' and save the log to alog2.txt
    7. Now in Ad-Aware SE click Add-ons, and double click the VX2 Cleaner to run it. If anything is found, clean it.
    8. Shut down Ad-Aware
    9. Run HijackThis try fixing those two lines we are having problems getting rid of (the R0 and O4 lines).
    10. Re-enable your virus scanner and perform a full scan. Make note of anything found (save exact names).
    11. Reset Web Settings by clicking Start, Control Panel (for some systems it may be Start, Settings, Control Pane) and select Internet Options. Then click Programs and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like (i.e., www.majorgeeks.com).

    12. Use Windows Explorer to bring up the c:\findnfix directory. In the c:\findnfix directory double click on the file !log!.bat This will run the program and it will create a log.txt file (it will also pop up in notepad when done). Be patient, it takes a little while for it to scan thru all the files it needs to look for.

    13. Reboot normal mode (still do not open any browsers)
    14. Run Ad-Aware SE again choose 'Perform a full scan' and save the log to alog3.txt
    15. Run HijackThis and save a new log
    16. Finally open up and browser and come back here and post all three Ad-Aware logs, the FindNFix log, and the HJT log (as text attachments)
     
    Last edited: Sep 18, 2004
  9. rebellor

    rebellor Private E-2

    I can only upload 2 attachments at any one time so I guess I'll make a few posts.

    Here's what happened:

    all 3 runs of Ad-aware (with plug-in) were clear. I can't upload alog1.txt because it is 398 Kb (exceeding the limit allowed on the forum).....what should I do about that??

    I ran HJT.....the R0 line was still there. I fixed it. It seems to be gone. The 04 line wasn't there this time (at least I couldn't see it).

    I ran ANti-vir XP and no viruses were detected. It did detect Worm/randon.ac.4 and TR/Dldr.Avis.1 on prior scans but was completely clear this time.

    I will attach the FindnFix log and HJT log on my next post.

    Thanks,

    Ryan
     

    Attached Files:

  10. rebellor

    rebellor Private E-2

    This is my second post so I can attach the other 2 logs (HJT and findnfix). I've included previous text. I can't send alog1.txt becuase it is too large.

    I can only upload 2 attachments at any one time so I guess I'll make a few posts.

    Here's what happened:

    all 3 runs of Ad-aware (with plug-in) were clear. I can't upload alog1.txt because it is 398 Kb (exceeding the limit allowed on the forum).....what should I do about that??

    I ran HJT.....the R0 line was still there. I fixed it. It seems to be gone. The 04 line wasn't there this time (at least I couldn't see it).

    I ran ANti-vir XP and no viruses were detected. It did detect Worm/randon.ac.4 and TR/Dldr.Avis.1 on prior scans but was completely clear this time.

    I will attach the FindnFix log and HJT log on my next post.

    Thanks,

    Ryan
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your log looks good now. We finally got rid of those R0 & O4 lines!

    How is everything working?
     
  12. rebellor

    rebellor Private E-2

    Things are working great! Thank you so much.

    I've given up with Norton Antivirus....after all this spyware and crap, it doesn't seem to be able to liveupdate virus definitions. My last question to you is....is AVpersonal (the free shareware version) good enough antivirus protection and if not which antivirus program do you recommend? AVPersonal doesn't seem to scan incoming/outgoing Outlook Express messages.

    Once again....I really appreciate your time and expertise.

    rebellor
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not happy with your AV try AVG Free Edition. It does have an email scanner too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds