MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 12-17-08, 20:37
joe arnold joe arnold is offline
Private E-2
 
Join Date: Dec 2008
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default slirsredirect.search.aol.com

No matter what I enter into the IE address field, it changes to slirsredirect.search.aol.com on my PC w/ Vista and I can not get on the Internet. PC seems to runs O.K. otherwise. Can not run Norton 360 as it wants internet. AVG, Malwarebytes, Cleanup!, Adaware, defrag have been ineffective.
Reply With Quote
Sponsored links
  #2  
Old 12-19-08, 21:55
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,122
Thanks: 61
Thanked 7,565 Times in 4,066 Posts
Default Re: slirsredirect.search.aol.com

Welcome to Major Geeks!

Please begin by clicking Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
  • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
  • Then search forTDSSserv.sys
  • Let me know if you find this or not.
  • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
  • Also if TDSSserv.sys is found and you disable it, then reboot.
  • After reboot continue on with the below cleaning instructions.

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.
  • If something does not run, write down the info to explain to us later but keep on going.
  • Do not assume that because one step does not work that they all will not.
Notes:

  1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
  2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #3  
Old 12-20-08, 11:31
joe arnold joe arnold is offline
Private E-2
 
Join Date: Dec 2008
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: slirsredirect.search.aol.com

Thanks for help with this problem. I checked device manager in the Non-Plug and Play Drivers for TDSSserv.sys and it is not listed. So before I attempted any of the other steps that you listed, I stopped. I have not begun to follow the rest of your directions. Please advise if there is anything else I should do under Device Manager before I begin to follow the rest of your directions. Thanks Gizmo Joe
Reply With Quote
  #4  
Old 12-20-08, 18:14
joe arnold joe arnold is offline
Private E-2
 
Join Date: Dec 2008
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: slirsredirect.search.aol.com

Hi, I sent a post earlier,noting that I do not have the file in device manager that you wanted me to turn off. So, I ran all of the utilities and I still am not able to connect to the internet. However, instead of getting the slirsredirect.search.aol.com loading into my my browser address bar and a page not found error, now I get;
http://go.microsoft.com/fwlink/?LinkId=69157 and a page
not found error. This is the first of two posts with the error logs.
Attached Files
File Type: txt Combofix-log.txt (16.7 KB, 1 views)
File Type: txt mbam-log-2008-12-20 (16-57-53).txt (819 Bytes, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 12-20-2008 - 16-03-52.log (646 Bytes, 1 views)
Reply With Quote
  #5  
Old 12-20-08, 18:16
joe arnold joe arnold is offline
Private E-2
 
Join Date: Dec 2008
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: slirsredirect.search.aol.com

Post # 4
Hi, I sent a post earlier,with 3 of the logs, here is the fourth.
Attached Files
File Type: zip MGlogs.zip (126.4 KB, 1 views)
Reply With Quote
Sponsored links
  #6  
Old 12-22-08, 22:51
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,122
Thanks: 61
Thanked 7,565 Times in 4,066 Posts
Default Re: slirsredirect.search.aol.com

Quote:
Originally Posted by joe arnold View Post
and I still am not able to connect to the internet.
It may not be malware. You may have broken things when you installed AVG8 while still having Norton 360 installed. You must never ever install more than one antivirus at a time. I suggest that you delete the below from AVG now. We will clean up the rest in my fix.
Code:
"C:\Users\Mom and Dad\Desktop\"
AVG           Dec 18 2008              "AVG"
AVG-NEW       Dec 18 2008              "AVG-new"
avg_fr~1.exe  Dec 16 2008    53682216  "avg_free_stf_en_8_176a1399.exe"
That is unless your plans are to uninstall Norton 360 (which could be necessary anyway to fix your lost of internet).


In Internet Explorer -> Tools -> Internet Options -> Connections -> LAN Settings, make sure you are not set to use a Proxy Server...... that is unless you need to use a Proxy Server and in that case, make sure it is configured.


Now let's continue with your fixes!

Uninstall the below old versions of software:
Ad-Aware 2007 <-- out of date a not very useful anyway.
Java(TM) SE Runtime Environment 6

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

After clicking Fix, exit HJT.

Now we need to use ComboFix to remove a bunch of malware files.
  • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
  • Open Notepad and copy/paste the text in the below quote box into it:
Quote:
KILLALL::
Driver::
Viewpoint Manager Service

File::
C:\Users\Mom and Dad\AppData\Local\Temp\MAR53D3.tmp
C:\Users\Mom and Dad\AppData\Local\Temp\MAR557A.tmp

Folder::
C:\ProgramData\avg8
C:\ProgramData\Viewpoint
C:\Program Files\AVG
C:\$AVG8.VAULT$
  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below
Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.


After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

Now run Ccleaner!

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:
  • C:\ComboFix.txt
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter

Last edited by chaslang; 12-22-08 at 23:07..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Nasty Trojan virus home search, search extender, etc. RE Guru Malware Removal 3 06-19-05 01:06
Uninstall Shopping Wizard, Home Search Assistent, Search Extender training4life Malware Removal 71 06-07-05 23:09
Can't get rig of Cool web search, Shopping wizard and search assistant soozzanne Malware Removal 3 06-05-05 21:33
FINALLY! HOME SEARCH aka Search-to-Find IS GONE OFF OF MY FREAKING COMPUTER! Floater Malware Removal 8 07-16-04 11:39
Remove Home search assistent,search extender,shopping wizard, please help! thanks CompRookie Malware Removal 6 07-05-04 10:24


All times are GMT -5. The time now is 15:24.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger