searchportal.information.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by nagu, Sep 19, 2007.

  1. nagu

    nagu Private E-2

    I have been trying my best to get rid of this. I am not able to find what really the problem is. whenever i mistype in my browser, it takes me to searchportal.information.com.

    Hijackthis report looks very clean. Sophos antirootkit and blacklight gave a clean chit. AVG antispyware and spybot also gave a cleanchit. But still this problem exist. This happens only in this Laptop. i have another PC and laptop, which has no problem like this.

    Machine: Windows XP-SP2 (fully updated)
    Antivirus: Mcafee Corp Edition (Work Laptop)
    Browser: IE7 and Firefox (latest)

    Please help me in solving this problem.
    Regards,
    Nagu
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Try the below.

    Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Any change now?
     
  3. nagu

    nagu Private E-2

    chaslong, thanx for that response.
    But unfortunately there is change in the situation.:(
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you meant to say, no change? If so, continue onto the below.

    First shutdown all antivirus and other protection software and repeat my previous instructions. Also note whether you receive a success message from adding the fixME.reg patch to the registry. If you are not getting a success message, the patch is not being applied.

    If still having a problem, please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. nagu

    nagu Private E-2

    please find the attachments
    -Nagu
     

    Attached Files:

  6. nagu

    nagu Private E-2

    other files also attached
    -Nagu
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not do step 2 of the READ ME properly. You must do this now or you will not be able to find things I may ask you to delete in the below steps.


    Delete the below and also delete any other cracks or keygens you have. Also uninstall all illegal software which puts you at risk for having malware problems.
    C:\Documents and Settings\nagu\My Documents\Downloads\QuickTime Pro Keygen\QuickTime Keygen.exe
    C:\Program Files\QuickTime\QuickTime Keygen.exe

    Did you configure the below Proxy Settings yourself and are these required?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.telxsi.com:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.50.*;10.1.*;http://intranet*;http://elearning.*;<local>

    Did you or your company create the below policies?
    See the below link for what the above policy does:
    http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/93231.mspx?mfr=true

    Based on your HJT log you did not follow my instructions for the Reset of Web Settings and it you may not have applied the registry patch. Please do the following in the order written.


    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_14
    Java(TM) SE Runtime Environment 6 Update 1
    Sunbelt CounterSpy <-- since we are finished with it now.

    Then delete the below folders which may be left behind:
    C:\Documents and Settings\nagu\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    D:\Program Files\Sunbelt Software



    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

    After clicking Fix, exit HJT.
    • Now shutdown all protection software (like McAfee)
    • Repeat the steps given in message # 2 exactly as written including using Majorgeeks.com as your home page for now.
    • You must be sure to tell me if the registry patch was successfully added. That is did you get a message saying it was?
    Now attach a new HijackThis log and be sure to answer the above questions and tell me if you still have problems.
     
  8. nagu

    nagu Private E-2

    Done
    Yes
    Done

    Done
    Done
    The registry patch was succesfully executed.

    HJT is attached. There is no change in the situation as of now.
    Thanx Nagu
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below.
    • click Start
    • select Control Panel
    • in Control Panel locate Network Connections and double click it.
    • in the next window find your active Local Area Connection and right click it and select Properties
    • in the next window scroll down until you see the Internet Protocol (TCP/IP) selection and double click on it.
    • in the next window note how IP and DNS are configured (are they set to automatically?)
    • then at the bottom of this Internet Protocol Properties windows click the Advanced button
    • in the next window, click the DNS tab
    • now look to see if you have anything in the Append these DNS suffixes (in order) box. If so, what is there? Write them down exactly before continuing. Then delete anything in this box. Then click OK and OK your way back out of all of these windows/forms.
    • If you found entries in this box, did deleting them help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds