Search Nut virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by tanusgreystar, Nov 28, 2012.

  1. tanusgreystar

    tanusgreystar Private E-2

    Hi. I've been having a lot of trouble installing Windows Home Server 2011 connect software on my laptop and I've been on the WHS forums for help, but nothing is working, and it's getting progressively worse. One thing I had overlooked is that when I try to connect by using the servername, for example http://servername/connect I get "Search Nut" search engine telling me that "servername" doesn't exist. In googling Search Nut I realized it is a virus, so WHS forum referred me here. I did all of the procedures leading up to the actual malware procedures. Everything ran, except TDSKiller, which ran, but couldn't initialize anything. Also I cannot locate my MGTools log anywhere. I looked for it on C: but there is no MGlogs.zip. Attached are the rest of my logs. Thanks!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you will need to run it again. :) Thanks.
     
  3. tanusgreystar

    tanusgreystar Private E-2

    Still no c:/MgLogs.zip.

    The individual logs are there in the MgTools folder from what i can tell.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What logs exactly? Like newfiles.txt? If so you have what I need....
     
  5. tanusgreystar

    tanusgreystar Private E-2

    Here's all the txt files in the MGTools folder. Not sure if they're all relevant. Thanks.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rescan with Hitman and have it delete Potential Unwanted Programs


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. tanusgreystar

    tanusgreystar Private E-2

    Thanks!
     

    Attached Files:

    • JRT.txt
      File size:
      6.6 KB
      Views:
      9
    • OTL.Txt
      File size:
      99.2 KB
      Views:
      6
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    @Alternate Data Stream - 1267 bytes -> C:\ProgramData\Microsoft:939NoDUQVGnsvv7J41rT1t5yd
    @Alternate Data Stream - 1168 bytes -> C:\Users\MATT_LAPTOP\AppData\Local\Temp:klaIIIVSVtZ4bmC8NWA
    @Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:5C321E34
    @Alternate Data Stream - 1046 bytes -> C:\ProgramData\Microsoft:0dGSHGeJ685UEmDOrkux6IWCh7P
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Tell me how things are running please.
     
  9. tanusgreystar

    tanusgreystar Private E-2

    I ran otl and a log was created but it didn't save to my desktop. Do I just run a scan without fixing? Also, I'm still being redirected to search nut.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. tanusgreystar

    tanusgreystar Private E-2

    Attached Files:

    • eset.txt
      File size:
      778 bytes
      Views:
      4
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Still having trouble with search nut? If so... Please download Combofix to your desktop. Please refer to these instructions prior to running. Attach log once done.
     
  13. tanusgreystar

    tanusgreystar Private E-2

    thanks
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you tell me please, are you still having trouble with searchnut??

    What's in these folders?
    • C:\ProgramData\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222}
    • C:\ProgramData\{D69A48BF-7653-4AA8-94BC-5847522A4573}
    • C:\ProgramData\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2}
     
  15. tanusgreystar

    tanusgreystar Private E-2

    When I try to connect to the server I don't get search nut anymore, but I get 404 error. So search nut seems to be gone.

    Those folders have Guitar Rig files in them. Thanks.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can post about it in software forum then if you would like. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds