Google search not working plus spyware removal ads are replacing google adsense

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dudethat, Apr 26, 2008.

  1. dudethat

    dudethat Private E-2

    Hello,
    Ive always used this site as an excellent resource for removing spyware and trojans using the procedures given. This time though im not getting results as i think this is a new problem. I cant access MSN Yahoo at all but can access google home page but when applying a search the page just loads and loads without displaying results. I couldnt even accesss major geeks from typing the url i has to click a link in an email. Also when i view one of my sites the google adsense is replaced by a spyware removal ad!!!

    I have attached the hijack this log file.
    Thanks in advance for any help
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!


    As you likely already know is that malware is a massive pest these days and does its level best to hide itself in any number of places, So just a Hijackthis log will not show all the malware that can be on your PC, the full guide of our steps below has a few other logs that show alot of the malware on your PC and where they are located,

    So please do run the full guide of our below and attach the reuested logs, do also take note to disable Spybots TeaTimer.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. dudethat

    dudethat Private E-2

    Hello,

    Ive run all the apps in the run this first section and attached the first three logs. The problem looks like its gone so thank you.:D just one thing though i get the following dialogue when windows boots which looks like spyware.rolleyes
    [​IMG]
    Many thanks
    The remaining two logs will follow
     

    Attached Files:

    Last edited: Apr 27, 2008
  4. dudethat

    dudethat Private E-2

    The remaining two logs

    Thanks again
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not download and run the version of MGtools in the READ & RUN ME. You are way out of date!!! Where or when did you get it. Please download and use the correct version now but do not attach a new log yet. Wait until after doing the below but make sure you use the current version.

    Based on your logs, I see no antivirus program installed. Why are you running without one?

    Is your copy of Sunbelt CounterSpy a paid version or free trial?

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {144d2590-85e9-4d63-93da-a0fd58c20968} - C:\WINDOWS\system32\dsilfarf.dll (file missing)
    O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [BM1717ae4b] Rundll32.exe "C:\WINDOWS\system32\ptsglojy.dll",s
    O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
    O4 - HKUS\S-1-5-21-606747145-1220945662-725345543-1002\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all (User '?')
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - AppInit_DLLs:

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. dudethat

    dudethat Private E-2

    Hello,
    Thanks for all info and procedure.
    The reason i didn't download and run the latest version of MGtools is because
    i was having trouble opening the download pages while the virus was still active
    so i used a version i had downloaded from Major Geeks last November.

    I thought i did have an antivirus program running as recently when i thought i
    didn't i tried to install a new one an received a message saying i already had Trend Micro Pc Cillin running and installing two could cause conflict
    So today i installed Pc tools antivirus and just ignored the message as i could find no reference to the above mentioned antivirus in the program files
    or in the start remove programs section.

    The version of CounterSpy i have is the free trial.

    When running the anylise.exe i did not come across the following

    O4 - HKLM\..\Run: [BM1717ae4b] Rundll32.exe "C:\WINDOWS\system32\ptsglojy.dll",s
    O4 - HKUS\S-1-5-21-606747145-1220945662-725345543-1002\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all (User '?')

    i assume as i updated yesterday my spybot search and destroy and ran it it got rid of them.

    I did get a success message when i ran fixme.exe

    many thanks as all seems to be working great with no more pop up dialogues either.
    Ive attached the requested two logs
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The you should uninstall it now.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds