Need help! IE search toolbar, reset homepages

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rooney, Jan 24, 2005.

  1. rooney

    rooney Private E-2

    I've been infected with something. My homepage keeps getting reset to something else, and my windows explorer has an IE search toolbar now. I went through all the steps to remove everything and even tried using hijack this to remove it. Then I would run it again and it would be gone. But then I restart my computer and it's back again. What do I do?!
     
  2. TheOldThug

    TheOldThug First Sergeant

    Hi

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)

    TheOldThug
     
  3. rooney

    rooney Private E-2

    Now I have a new problem. I'm not sure if it's related to what I had before, or if I'm just having really bad luck and it's happpening at the same time, but now my monitor won't start up. The last thing I did was use Hijackthis again to remove the IE search toolbar and the start pages to see if they would stay removed. Then I turned off my computer. And when I turned it on again, my monitor wouldn't start up. My computer would make all of it's usual noises like it's starting up, but I don't see anything on my screen. But the little monitor light is green and on. So then I turned it off and turned it on again hoping something would change. And now my little monitor light turns off too. Then I'd press the button to turn the monitor on and the light would stay green for a few seconds but then go black. This is REALLY stressing me out. Anyone have any insight?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't thing this is related to your previous problems!

    Try booting in safe mode by tapping the F8 key as it starts to boot. Select safe mode if it ever shows anything on the screen.

    Does it ever show anything on the screen? Like if you power everything down and then after about a minute power pack up. Do any messages from your BIOS or VIDEO card show?

    If not, either your monitor or your video card could be dead. Do you have another monitor you can plug in temporarily to test it?
     
  5. rooney

    rooney Private E-2

    No it never shows anything on the screen. The most it does is flicker a little bit, like a black screen to a grayish screen. I'm not near my computer at the moment, but when I do get a chance to test and plug in a different monitor, how do I tell if it's my monitor or my video card? Thanks in advance.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you see nothing even at power up, I would suspect one of the following:
    - loose cable from video card to monitor
    - video card problem (check if it is seated properly into the motherboard. If it is a built-in card then it cannot be a seating problem).

    If neither of those help, it is more than like your video card. Do you have another video card to try?

    I assume if you have another monitor to try, that you also have another PC where you can check this questionable monitor on. Perhaps you can do the same for the video cards.
     
  7. rooney

    rooney Private E-2

    Ok, my monitor is working now, but I'm STILL having issues with the IE Search Toolbar. I swear I've done EVERYTHING. This is extremely frustrating. Running all the programs and doing all the scans didn't really turn up anything except for Spybot turned up a few items I got rid of. Then I ran Hijackthis and checked off the two things I saw with IE Search Toolbar and had them fixed. Ran Hijack this again and they were gone. Then I deleted the folder from Program files. Restarted my computer and it seemed okay for a few minutes. But then I see the IE search toolbar in my windows explorer again! Ran Hijackthis and there it was again! Somebody PLEEEAAASE help me. I don't know what else to do.
     
  8. rooney

    rooney Private E-2

    Ok, I think I fixed it, in case anyone else is interested. I'm not sure why this worked, but after I ran Hijackthis and fixed the items, I restarted in safe mode and THEN I deleted the IE search toolbar folder from Program Files and emptied the recycle bin. I had my internet disconnected too just to be safe. And now I don't think it has come back. Yet.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds promising!

    What was the problem with your monitor?
     
  10. rooney

    rooney Private E-2

    Ok, problem not entirely solved. No longer showing any symptoms i.e. adding bookmarks, showing IE Search Toolbar in windows explorer, changing homepage. But there still seems to be a trace of it. I found an IE Search Toolbar folder in Program files again. It just keeps coming back. I also found it in my list of programs in the Control Panel. I clicked to uninstall it and it said it was already uninstalled and was going to be removed from the list. Then later it was there again. But this time it went through the process of uninstalling it. But the folder is still appearing in my Program Files after I delete it. I am extremely perplexed right now. Can anyone help me? Just tell me what you need to know.

    But with my monitor, I guess it wasn't plugged in correctly. I didn't touch anything between the time it worked and it didn't, and when I checked nothing seemed loose or anything, but I just unplugged and replugged some things and it worked!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  12. rooney

    rooney Private E-2

    Here's my log
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your versions of WinXP and IE are seriously out of date and represent a severe security risk. After fixing your current problems you must go to Windows update and get updated or you will continue to easily have problems like this again.

    You must also remember to exit all browsers before running HJT. You had the below running:

    C:\Program Files\Internet Explorer\iexplore.exe

    If you do not exit browsers (especially IE), it can interfere with proper cleanup of the problems.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\SYSTEM32\init32m.exe
    C:\WINDOWS\System32\mshelp32.exe
    C:\WINDOWS\sys346.exe
    C:\WINDOWS\sys422.exe
    C:\WINDOWS\sys52.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe init32m.exe
    O2 - BHO: IE Search Toolbar Helper - {2C5175A2-ADF3-4F57-AB70-BA90FD60A383} - C:\Program Files\IESearchToolbar\IESearchToolbar.dll
    O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL
    O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
    O3 - Toolbar: IE Search Toolbar - {EB381422-F797-4A98-A266-9DC490821907} - C:\Program Files\IESearchToolbar\IESearchToolbar.dll
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
    O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/149161da82b7ac74c002/netzip/RdxIE601.cab


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\IESearchToolbar <-- the whole folder
    C:\Program Files\WildTangent <-- the whole folder
    C:\WINDOWS\System32\DSMANA~1.DLL
    C:\WINDOWS\system32\javafix3.dll
    C:\WINDOWS\SYSTEM32\init32m.exe
    C:\WINDOWS\System32\mshelp32.exe
    C:\WINDOWS\sys346.exe
    C:\WINDOWS\sys422.exe
    C:\WINDOWS\sys52.exe
    c:\windows\jjfixer.exe

    If you have a problem deleting or finding any of these let me know which ones. If you find them but cannot delete them, bring up Windows Task Manager by pressing CTRL-ALT-DEL simultaneously and select Processes. Look for them in the process list and end them by right click on them and select End. Then try to delete them.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  14. rooney

    rooney Private E-2

    Ok, so here's the rundown. First off, I think the fact that iexplore.exe was running may have had to do something with whatever was affecting my computer. I'm pretty sure I closed everything the first time I ran hijackthis, and I explicitly checked this time, closing everything and emptying the taskbar except the volume control. But when I went to go do the first step, killing the processes, it was still there, but I went ahead and killed that too. Also sys346.exe, sys422.exe, and sys52.exe, were not there but 3 of them with different numbers were, but I went ahead and killed those also.

    Then after booting into safe mode, I deleted both a dsmanager32.dll and dsmanager.dll. And I couldn't find the javafix3.dll. When I went to find and delete the sys###.exe I found about 50 of them with them with different numbers that were all created around the same time. So I deleted all of those too. Hopefully that was okay to do.

    And so far everything looks good!

    Here's my new log.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log looks clean now. Any time you are not sure about deleting something you could always rename instead or you could move the files to another location where they would not be look for by the malware (like c:\junk ).

    You now need to follow the steps in the below link. The first step listed is MS Windows Update, but you should get one of the firewalls installed immediately before doing anything else.

    How to Protect yourself from malware!
     
  16. rooney

    rooney Private E-2

    Thanks for all your help chaslang!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds