mysearchdial squatter

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by smileycrossbones, Apr 22, 2014.

  1. smileycrossbones

    smileycrossbones Private E-2

    Dearly beloved Geeks,

    I've used your malware scan many times and never had to go so far as to post a scan, never say never, so here they are:

    the facts are these: Win7 64 bit, lenovo, Avast, java updated, uac off, as per your guidelines...

    Hitman pro offered a log but i couldn't find it.
    Malwarebytes quarantined some files but no log found...
    TDss killer came up negative...

    as per instructions i did not repeat...

    I have three scans for rogue killer and the MGlog.zip headed your way...and, again, I Loves you Geeks!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see the instructions for using them and run new scans and save the logs. We need them to continue

    Also note that the instructions specified not to fix anything with RogueKiller!!!!!
     
  3. smileycrossbones

    smileycrossbones Private E-2

    Thank you for your time. I've redone the missed scans. I post jpgs of hitmanpro screenshots as no log could be found for three scans...

    Thank you very much for your help. This computer serves our entire community and I'm hoping for the best here as so many folks can benefit from majorgeeks the way I have. You've been at this quite a while. I hope it's still fun when you win one...

    Thank you in advance for your kind attention.

    Tonasket Community Cultural Project
    Tonasket WA
     

    Attached Files:

  4. smileycrossbones

    smileycrossbones Private E-2

    Here's the Tdsskiller scan tagging along...and again many thanks...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    The instructions explain how to get the log. The snapshots are of no real help to us. Hitman is the most likely program that would catch hidden items related to myserachdial. Without the log, I may not find all of it, however I will finish looking at the logs and see what I can find now.
     
    Last edited: Apr 24, 2014
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java 7 Update 11

    Now install the current version of Sun Java from:

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\$avg
    C:\windows\TEMP\*.*
    C:\Users\CCC\AppData\Local\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. smileycrossbones

    smileycrossbones Private E-2

    Dear Chaslang,

    I finally got a hitman pro scan so here it is...

    I re-reinstalled java just to be sure, and OTM didn't show anything before I had to get off line. Thanks for the help, very much appreciated, your hard work. I will do the further scans as directed next chance unless I hear differently from you! Peace!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your'e welcome. Yes you need to finish my last instructions.
     
  9. smileycrossbones

    smileycrossbones Private E-2

    Dear Chaslang,

    Thank you for your help. Resolution will have to be a re-install due to time and access constraints on this end. The procedure has been very informative. As I said previously, between Avast's boot scan and your process early steps is always very effective. I had a difficult time getting a couple of the scans to leave logs, and I wonder if that was due to the malware, or my own clever handling...

    Again -- Thanks!!
     
    Last edited: May 2, 2014
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    The procedure I gave you would have been much much faster and easier. Searchdial is mild junkware and not worth a reinstall ever.
     
  11. smileycrossbones

    smileycrossbones Private E-2

    Dear Chaslang,

    Thank you for your input. Besides the time constraints I'm an xp throwback but I do have time to reorganize for another assault before the reinstall (I only have access a couple hours two days a week...) so I'm going to get my poop in a group and make another run at it fresh. I ran the scans and went looking for the logs afterwards, and I believe I'll try to be a little cleaner about that this time. I appreciate your help and straight up advice.

    Searching the forum about this particular bug doesn't include a lot of resolution information, so it's hard to tell how prolific the infection is, so I'm glad it's something easy. I wanna know everything about how it dies, too.

    If you feel you spent enough time on this just let me know. I won't be able to do anything until tomorrow at the earliest (Tues 5-6). Thanks again again.
     
  12. smileycrossbones

    smileycrossbones Private E-2

    I'm Back! Wow I missed a number of details the last round. Thank you for your patience.

    After acquiring these scans, the win7 64bit lenovo is still unable to connect to our regular link.

    By the way, a neighbor's router "connects" without any real connection. Our usual dlink has an exclamation point next to it. Searchdial is still in the mozilla search bar. Thank you for your patience...and your straight up advice.

    Please see the attached scans:
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still waiting for you to complete the instructions given in mesage # 6.


    Also note you never mentioned anything about network connection problems before and per your logs, it looks like you connect just fine.
     
  14. smileycrossbones

    smileycrossbones Private E-2

    Thank you very much for your patience, Chaslang. I've learned a lot and that's pretty good for an old guy.

    I've got the further scans now. Searchdial is gone!! Score one for the good gyz!!

    The connectivity issue is a further problem which I was hoping the malware process would magically repair as has happened so often in the past...

    Our main router shows an exclamation point in the "connect to:" dialogue box, while indicating a connection to the router next door. No actual connection exists.

    OTM didn't find anything or leave a log. Thank you very much again.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    OTM does not scan for anything! You have to run the fix I gave you inorder for it to produce a log. I did not see OTM.exe on your Desktop ( as requested ) so how could you have run it?

    Also you MGlogs (2).zip file is from 5 ( almost 6 ) days ago. You need to follow the instructions to produce a new log from today. You should not be renaming the file either. It is always named MGlogs.zip and it automatically updates the internal logs when the GetLogs.bat file is run properly ( i.e., protection disabled, Run As Administrator, UAC is disabled ).
     
  16. smileycrossbones

    smileycrossbones Private E-2

    Dear Chaslang,

    Thank you for bearing with me. I have finally been able to do the complete set of scans without interruption. Aside from my own foibles, I find I haven't been alone...

    attached are the requested scans, including the extra set from #6. OTM ran on the desktop and produced nothing. I also couldn't find a directory for it in either program file directories under "C".

    Connectivity indicated connection but there is none.
     

    Attached Files:

  17. smileycrossbones

    smileycrossbones Private E-2

    One more scan log...
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it does not look like your network connection issues are related to malware because your logs a clean now. And the items we removed previously were just junkware and they would not impact your connectivity. I suggest that you try a wired connection instead of wireless just to see if there is any difference. Also try your laptop from some other location ( not your home network ) to see if it works. If it does than it is not your laptop that is the problem.

    After that, post in the Software Forum if you still need help.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
    Note I did not have you toggle System Restore because it could be an option to try if your laptop is really still the problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds