Search here virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by ppreheim, Jul 27, 2012.

  1. ppreheim

    ppreheim Private First Class

    My young daughter downloaded a game that apparently had a ton of malware attached.

    I did the google redirect thread and then did the do me first thread. The logs will be attached. More logs on reply


    Thanks for the help as the problem still exists
     

    Attached Files:

  2. ppreheim

    ppreheim Private First Class

    Rest of the logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Are you still having issues?
     
  4. ppreheim

    ppreheim Private First Class

    Yes, I change the search tool from "search here" to google but when I open a browser it still defaults to a "search here" tool. We also have a problem when we open a new tab it defaults to a "search here" web page and we cannot seem to find a way to fix it.

    Thanks for the help!!!!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {adca5064-9e30-43fe-9856-58b07a3149fe} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
    O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll

    After clicking Fix, exit HJT.


    Now uninstall Babylon toolbar on IE

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If the above merged in to the registry, reboot your PC and see if there is any change.
     
  6. ppreheim

    ppreheim Private First Class

    Did as asked. I did recieve a success message when merging the file into the registry. Rebooted and the search problem still exists :(

    What next?

    Thanks for the help!!!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Using which browser? I'm assuming Internet Explorer.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  8. ppreheim

    ppreheim Private First Class

    Yes, I was using Internet Explorer. Ran the C:\MGtools\GetLogs.bat as administrator. Log is below.

    Thanks!!!!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we missed part of it.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. ppreheim

    ppreheim Private First Class

    I thought it was gone for a second. It was there when I opened up the browser so I went into internet options and reset the search options and the new tab options. Looked like it was gone for a bit, but then it came back.

    The fixreg was succesful.

    Log is posted below, thanks for all the hard work!!!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and save combofix.exe directly onto your Desktop but do not run it. We will run it below with specific instructions. Also make sure you follow these steps exactly ( print them if necessary ) because I'm going to have you do some steps before any browsers are open and then after your browser has been opened.

    Uninstall the below at least for now:
    DefaultTab Chrome
    DefaultTab

    Also uninstall the below outdated Sun Java versions:
    Java(TM) 6 Update 20 (64-bit)
    Java(TM) 6 Update 22

    Do not open any browsers after the reboot from ComboFix until specified below.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Again: Do not open any browsers after the reboot from ComboFix until specified below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Now rename the C:\MGlogs.zip file to C:\MGlogs1.zip

    Now open your browser, but do not make any modifications to any settings. Just open it.

    Now re-run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    When it finishes. Attach the C:\MGlogs1.zip file and the last log which will be C:\MGlogs.zip If ComboFix ran okay, the C:\combofix.txt log will automatically be added to the MGlogs.zip file.


    And now there is one more log I want to collect from OTL.


    Please download OTL by OldTimer.
     
    Last edited: Aug 1, 2012
  12. ppreheim

    ppreheim Private First Class

    I did as instructed. I did get the "illegal operation attempted on a registry key that has been marked for deletion" prompt and rebooted. All worked well after that.

    After all instructions were followed and all logs created - The "search here: window has not appeared in the browser. I clicked on the new tab button and it opened a new tab as it should. I also went into internet options and went into search options. I did not see the search here option but there was a strange one there. I did not change or delete anything. Logs are posted. Did not post combo fix log as instructed because it would be included in the mslogs.

    Thanks for all the help!!!
     

    Attached Files:

    Last edited: Aug 1, 2012
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. That looks better.



    Now shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Code:
    :OTL
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = [URL]http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157[/URL]
    CHR - homepage: [URL]http://search.conduit.com/?ctid=CT3214568&SearchSource=48[/URL]
    CHR - default_search_provider: MyStart Search ()
    CHR - default_search_provider: search_url = [URL]http://mystart.incredibar.com/mb165/?loc=IB_DS&search={searchTerms}&a=6PQBdRSEDZ&i=26[/URL]
    CHR - default_search_provider: suggest_url = 
    CHR - homepage: [URL]http://search.conduit.com/?ctid=CT3214568&SearchSource=48[/URL]
    [2012/07/26 16:00:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Winferno
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. ppreheim

    ppreheim Private First Class

    Was running the OTL and it seems to be stuck processing this command.

    [2012/07/26 16:00:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Winferno

    Dont know what to do. Afraid to reboot. Will try to leave the computer up until I hear what to do. It has been at this point for about 20 minutes.

    Thanks!!!
     
  15. ppreheim

    ppreheim Private First Class

    Computer froze so I was forced to do a hard reboot. When it rebooted I skipped the command that froze and ran the OTL with these commands

    :Commands
    [PURITY]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [REBOOT]

    Pasted in the Custom Scan/Fixes box. When that was done finished the rest of the instructions. Scans are posted below.

    Computer seems to be working fine. The strange search tool is not longer listed in internet options - change search defaults - settings. Opening a new tab works as well.

    Thanks!!!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Great! Then we only have final instructions to complete.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. ppreheim

    ppreheim Private First Class

    Did as asked..

    Thanks!!!!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds