Need Help - search bar dont go away

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Mirolha, Dec 28, 2004.

  1. Mirolha

    Mirolha Private E-2

    Hi there,

    I did everything the post: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal told me to do. But i cant remove the search bar.

    here is the picture of the search bar and the hijack log, please help me

    [​IMG]

    Look at the hijack, im pretty sure its the line:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jtiwpaufewychhymgj.com/4...lrc1Ct2JgbEeGR5D16dopdv/a0pVtopRT23Gh9dF.html

    but when i delete it(whith the hijack this) it comes back with another name of the http://....
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post HJT logs unless we ask you to post them.
    Also note the below items are browers:

    c:\arquiv~1\intern~1\iexplore.exe
    C:\Arquivos de programas\Internet Explorer\iexplore.exe
    C:\Arquivos de programas\Internet Explorer\iexplore.exe

    They MUST NOT be running anytime you use HijackThis. We specifically say that in the sticky threads. It is very important to follow those guidelines.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to go to Add/Remove programs and uninstall MessengerPlus3. It installs a load of malware on your PC including LOP.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jtiwpaufewychhymgj.com/4gc_192e_Fz_nBygk3SvUhnmlrc1Ct2JgbEeGR5D16dopdv/a0pVtopRT23Gh9dF.html
    O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINDOWS\Downloaded Program Files\gbieh.dll
    O4 - HKCU\..\Run: [Roadblue] C:\DOCUME~1\Pentium\DADOSD~1\ABOUTA~1\long less enc.exe
    O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
    Boot into safe mode and use Windows Explorer to delete:
    C:\DOCUME~1\Pentium\DADOSD~1\ABOUTA~1\long less enc.exe

    Additional step to delete gbieh.dll:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s gbieh.dll
    del gbieh.dll
    exit

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

     
  5. Mirolha

    Mirolha Private E-2

    thank you Chaslang

    I removed the MessengerPlus3 and the serach bar was removed with it :p .
    I could only remove gbieh.dll on the safe mod with prompt support.
    After deleting gbieh.dll i could fix the line:

    O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINDOWS\Downloaded Program Files\gbieh.dll

    I will show this topic to my sister and advice her not to install this crap anymore. It gave me a big headache.

    Thanks again
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds