Google redirecting every search

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jacobdet, Feb 6, 2009.

  1. Jacobdet

    Jacobdet Private E-2

    Hey,

    So I ran the "READ & RUN ME FIRST" and attached the logs. I didn't run combofix because it gave me an error message that I still have Dr Webb running, which I have thoroughly tried to remove it and I can't find any traces of it on my pc, but it still says it's there. So if yall say I should run it anyway I will.

    Anywho, on to my problem. Every time I do a google search it redirects all my results to ad sites. I see in the bottom right corner "wating for 7.7.7.0" which I think is what's doing it to my PC. After researching a bit I think it might have something to do with "$sys$DRMServer.exe" running in my processes. I'm not sure. Any help is appreciated!
    -Jacob
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One of your cd's from sony created this. It started these services on your computer:
    O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
    O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe

    Dr.webb exists in these places and we will remove it:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\Doctor Web

    You need to uninstall your old java:
    J2SE Runtime Environment 5.0 Update 6"
    "DisplayName"="Java(TM) 6 Update 2"
    "DisplayName"="Java(TM) 6 Update 3"
    "DisplayName"="Java(TM) 6 Update 4"
    "DisplayName"="Java(TM) 6 Update 5"
    "DisplayName"="Java(TM) 6 Update 7
    And:
    Viewpoint Media Player

    Now as far as the redirects. Uninstall all toolbars and add-ons.
    Run CCleaner.
    Does this happen in all browsers?
     
  3. Jacobdet

    Jacobdet Private E-2

    Thanks for the help so far. I did what you said and tried to remove:

    O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
    O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe

    via hijackthis, but to no avail. I added the registry file and deleted the application data and everything else you asked me to do. This does happen in IE and firefox...
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can remove the services by doing this:
    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Have you removed all toolbars and addons?
     
  5. Jacobdet

    Jacobdet Private E-2

    Sweet. Done and done. And yes I did uninstall all of the addons and tool bars.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you not having any more issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. Jacobdet

    Jacobdet Private E-2

    It was still giving me the message about Dr webb in combo fix, but I ran it anyway and it fixed my problem, I'm sure it did because of the things you helped me with. Thanks so much for all your help! It is really truly appreciated.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ..safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds