![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi there,
I noticed last night that I was having problems whilst doing a search in yahoo for example. A List of the correctly searched items appears although when you click on the hyperlink it fails to open the webpage or will open up an alternative search engine website. I tried to run a spyware scan and all it came back with was some tracking cookies, the same result was also found in AVG Virus scanner and no virus' detected. I tried to run spybot search and destroy although it couldnt connect the the update server to check for updates ![]() I have attached a log of hijack this incase this helps, I am currently using Vista. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
Hi there,
Thank you very much for your assistance, I managed to run combofix last night which seemed to help clear the problem with the browser but I have run all the cleaning options in the link as requested. I am still going to run SuperAntiSpyware, Spybot S&D again to ensure there is nothing lurking in the background. Thanks ![]() |
|
#4
|
||||
|
||||
|
I advise you to attach all of the logs from the FIRST run as requested so we can check them out.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
Dear Chas,
Please find attached the first logs as requested. More to follow. Neil |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Please find attached further logs as requested.
Please advise me if you require any other log and where I would find it. Thanks ![]() |
|
#7
|
||||
|
||||
|
Please attach only the logs requested in the procedure. Those are:
And you have Teatimer enabled but temporarily disabled using MSconfig. Again see the READ & RUN ME and disable Teatimer properly. You will need to run MGtools again after doing this so you can attach a new and proper log.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#8
|
|||
|
|||
|
Dear Chas,
Please find attached the logs as requested, it would appear there is some form of adware in the form of Videoegg according to the mbam log. Regards, Neil |
|
#9
|
|||||
|
|||||
|
Quote:
Now complete the below instructions in the order written. First we have few questions to get answered. What is the below G Data stuff and did you install it? Code:
"C:\Users\neil\AppData\Local\" GDATA~1 28 Jan 2009 "G DATA" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=G Quote:
Quote:
I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing. Now uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME. Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file) O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file) After clicking Fix, exit HJT. You have left overs from Symantec that need to be cleaned up. Please run the below then reboot. After reboot run it one more time. Norton Removal Tool (SymNRT) Now we need to use ComboFix to remove a bunch of malware files.
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. Now run MSconfig and select Normal Startup as was originally requested in step 1 of the READ & RUN ME. Now run Ccleaner! Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one. Run MGtools.exe then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
Geezer7348 (02-08-09) | ||
|
#10
|
|||
|
|||
|
Dear Chas,
Thank you for your assistance, please note my following responses to your queries. Quote:
Quote:
Quote:
I have carried out the MGTools and Norton Removal Tool steps along with Combofix. Whilst using Combofix I had problems with my AVG virus scanner as Combofix kept detecting it regardless of which options I disabled so I temporarily uninstalled it to allow me to carry on with the scanning process. Whilst carrying out the CFscript.txt drag and drop into Combofix I received a message saying the OS was incompatible with "Error - Win32 Only", and also a message saing Combofix has expired and I could run it in reduced functionality mode, it turns out there was a new version I could download which I did and after carrying out the steps suggested it seemed to work without any further problems. fixme.reg, once I had double clicked this I got the following success message "the keys and values contained in C:\users\Neil\Desktop\fixme.reg have been successfully added to the registry. I proceeded to run ccleaner which fixed the registry keys it could not locate by removing them. I have also updated MgTools as detailed in the final step and have attached the following logs as requested. I have a couple of final queries for yourself. 1. Is it now safe to delete the fixme.reg from my desktop? 2. Can I now also delete the Norton_removal tool from my desktop? 3. In response to your comments about a cluttered desktop I have removed the documents to another portion of my HD, however there is one folder "FMFormation Database which I cannot delete or move from my desktop. Best wishes, Neil |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Quote:
c:\users\neil\AppData\Local\G DATA No! We still need to use it again. Quote:
Quote:
Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O4 - HKCU\..\Run: [?????????] ??????????????e O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe After clicking Fix, exit HJT. Now we need to use ComboFix to remove a bunch of malware files.
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. Now double click the fixME.reg file on your Desktop and allow it to be added to the registry. Make sure you tell me if it was successful. Now run Ccleaner! Now goto this link Using MGtools and download the new version (yes there is another new version) of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one. Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) Now attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
I have carried out all the tasks as listed below although I could not locate the registry key "O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)".
In respect of the folder FMFormations It contains a .dat file which I knowingly installed at the time as it is an update for a game on the machine, now that I am on a newer version of the game this file is no longer required although I cant delete the file as my recycle bin doesnt process this file when I try dragging/dropping or even pressing delete followed by the confirmation, all it does is sit as if it is thinking about deleting although nothing moves along in the progress bar to indicate this is being carried out. The file itself is 111MB large and is found within the following folder address C:\Users\neil\Desktop\FMFormation's Database Update Please also find attached the logs as requested. Regards, Neil |
|
#13
|
||||
|
||||
|
Your logs are clean.
Quote:
Right click on the Recycle Bin icon on your Desktop and select Properties. The click the Use one setting for all drives button. Once you select this another check box option should be available. Check the box that says Do not move files to the Recycle Bin, Remove files immediately when deleted. Now go see if you can right click on the problem file and select Delete. Let me know what happens.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#14
|
|||
|
|||
|
Dear Chas,
Thank you for your help, unfortunately the file still remains despite changing the recycle bin setting. The folder still wont delete. |
|
#15
|
||||
|
||||
|
If there is anything in the folder like files and subfolders, first go to the furthest level down and delete each file and folder one at a time working your way back to the top. If that does not help, we will try more forceful methods.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Hi Chas,
I can confirm there are no further level(s) of folders. As detailed below the folder location is C:\Users\neil\Desktop\FMFormation's Database Update and the file located within this folder is people_db.dat file. I have tried cutting the file into another location but it wont budge either. |
|
#17
|
||||
|
||||
|
Do you still use the below programs?
Football Manager 2007 Football Manager 2008 Football Manager 2009 If not then uninstall them and then reboot and see it the folder can be deleted. If you still use those programs, leave the folder alone since that is what it is for. Since this is not a malware problem, I'm going to post final instructions. If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#18
|
|||
|
|||
|
Dear Chas,
I removed the older versions of the game as suggested and also all the sub directories it stored in my documents and unfortunately it still wont let me delete this FMFormations Database folder. Please see my attached screengrab for an image of the problem. |
|
#19
|
||||
|
||||
|
Quote:
|
|
#20
|
||||
|
||||
|
Whar do you mean by older versions of the game? If any version of the game is still installed the database will still be in use.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Firefox address bar/search | wmarkj | Software | 7 | 01-10-09 11:48 |
| firefox hijacked by fire search | toa monty | Malware Removal | 7 | 03-04-08 01:35 |
| Firefox cotext menu search | MKorostoff | Software | 3 | 01-27-07 06:05 |
| Firefox Search Bar hints question | shewolf | Software | 3 | 11-22-06 13:21 |
| Search Box in Firefox | womfalcs7 | Software | 1 | 07-25-05 17:34 |