Top-Search-101

Discussion in 'Malware Help (A Specialist Will Reply)' started by tunglashr, Oct 11, 2010.

  1. tunglashr

    tunglashr Private E-2

    Before I followed the procedures in the do this first thread, a combination of detectors (StopZilla for one) told me I had the following:

    search hijacker.h
    fsa.tmp
    vundo.bib
    trojan.win32.generic (drivers\rkhit.sys)
    tr/agent.339968.0.trojan (restore\imagex.exe)

    After following your procedures I believe the rkhit.sys has been removed, but nothing else.

    Mostly what I noticed was a significant reduction in speed and an overall lag that was not present before. This is a relatively new machine with a fast processor, 4 gig ram etc. Firefox can be a memory hog, but it was off the charts. I needed to reboot all the time, typing was delayed, scrolling lagged etc.

    At first I was wearing blinders and just thought Firefox got really greedy. Then I noticed that when I clicked on certain sites, like Amazon, it would open new windows when it shouldnt. Eventually I watched and it did a sneaky redirect in there, first hitting top-search, then going to Amazon. I had always closed those windows anyway, but now I know what is up.

    I also have a text file on my desktop called debug that I cant close because it says it is open in internet explorer.

    I have tried to follow all of the directions in the do this first thread. If anything is omitted, its due to error, not me intentionally skipping anything. The only things I didnt do were for 32 bit windows, this is a 64 bit machine. Because of that, I can post all three logs here in a single post.

    Thank you for your help in advance.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Have you cleaned out your internet cache? Have you run CCleaner?

    What issues are you having still? Is Stopzilla still reporting any issues, and if so, can you attach a log from it?
     
  3. tunglashr

    tunglashr Private E-2

    I did run CCleaner and clean out my cache. I uninstalled StopZilla and the others when I started the procedure. I will reinstall it and run to see what it finds and then post the log. This should take a half hour or so.

    There is still an undeleteable text file on my desktop. My browser seems better so far, but I havent tested everything because I didnt want to cause any new problems. I will work on seeing if anything else happens, but Im just skittish about screwing things up a second before they are fixed.

    Thank you for your quick response.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is the file on your desktop ( which needs to be cleaned :) ) that you can't remove?

    Do get me the log so I can see what it is complaining about.
     
  5. tunglashr

    tunglashr Private E-2

    The file is debug.log, a text file. It is blank, but cannot be deleted.

    As for StopZilla, its still processing, but now it says I have at least 11 infections including the ones from before. Once its done I will post the log.

    Thanks
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right now your system is set to show hidden files. We will leave that until we are done.
     
  7. tunglashr

    tunglashr Private E-2

    Here is the log.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    From what I can read of this, it found and fixed some reg keys and files from a game and in your temp folder.

    Let's do an online scan with eSet:
    eSet Online Scan.
     
  9. tunglashr

    tunglashr Private E-2

    It wants me to pay to remove stuff. I do not have the full version. Are you saying the vundo.bib, search hijacker.h etc are false positives to get me to buy?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  11. tunglashr

    tunglashr Private E-2

    Confusion is a commodity in which I am a certified purveyor. I am doing the eset scan now, and so far it has found a few things. Log to follow when done.

    What I meant was, you said that it looked like StopZilla didnt do much, but I was commenting on the supposed 15 items it found. I wondered if maybe it showed me false positives to get me to buy their product.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, I don't believe it is doing that. I will wait to see the eSet log.
     
  13. tunglashr

    tunglashr Private E-2

    Here is my eset log. Let me know what you need me to do next.

    Thanks
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you just delete this entire folder:
    C:\Users\laptop2\AppData\LocalLow

    Then tell me if you are still having issues.
     
  15. tunglashr

    tunglashr Private E-2

    It will not allow me to delete it. Every time I change the folder to unset read only, it immediately changes back.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you delete the contents of the folder?
     
  17. tunglashr

    tunglashr Private E-2

    I have deleted the contents of that folder, which then allowed the folders deletion. What is my next step?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are your malware scans now coming back clean? What issues are you presently having?
     
  19. tunglashr

    tunglashr Private E-2

    The turbo-search-101 hijack is still occurring. I know I wrote the wrong thing in the title, I must have confused myself. I have my malware scan running again to see if there are more issues remaining.

    Thanks
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this what your homepage is being set to?

    Please check in msconfig under the startup programs for anything that has no name or no identifying text, then uncheck it.
     
  21. tunglashr

    tunglashr Private E-2

    It does not reset my home page. Its a lot stealthier than that. What it does is when I am on certain pages, if I click a link or sometimes even hover over a link with certain key words, it opens a new tab which goes to a relevant link via a redirect through turbo-search-101.com. So if I am in my Amazon seller account, when I click something related to Amazon it opens a new page, likely using this routing so I have clicked their affiliate link.

    When I ran StopZilla the second time it allowed me to delete the infections without registering for some reason, but I am still showing as having a trojan in my windows restore/imagex.exe file. This is in my startup in msconfig, but it does have a name and identifying text, and I believe this is a component of Windows 7 (though it could still be infected).

    Other than that, everything is cleaned out. I am going to restart and see if the hijacking continues now that StopZilla thinks its clean. Other than the listed trojan (imagex), I am clean.

    Should I do anything with imagex?

    Thanks
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will have you toggle system restore when we are certain that you are clean.
     
  23. tunglashr

    tunglashr Private E-2

    So far after restart I cannot get the turbo-search-101 behavior to recur. I believe we may be out of the woods.

    Do I have any further steps you would like me to do?

    Thanks
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  25. tunglashr

    tunglashr Private E-2

    Looks like I spoke too soon. I didnt download or install anything new, but last night around midnight turbo-search-101 again. When I ran Stopzilla again it found 3 infections, one of them being imagex.

     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have the log from running Stopzilla? I would like to see the full path to each of the files found.
     
  27. tunglashr

    tunglashr Private E-2

    Sorry for the delay. Here is the log.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  29. tunglashr

    tunglashr Private E-2

    Here is my log from Bit Defender. It looks like it agrees that imagex is infected, but I dont think it was able to fix it. I also couldnt upload an html file, so I converted it to txt. Let me know the next step.

    Thanks
     

    Attached Files:

    • log.txt
      File size:
      16.9 KB
      Views:
      2
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running the deep scan with SAS and MBAM. Attach those logs.

    Then, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds