I'm redirected from Google searchlist & Spybot crashing PC. Any suggestions welcome

Discussion in 'Malware Help (A Specialist Will Reply)' started by techsearch, Apr 4, 2007.

  1. techsearch

    techsearch Private E-2

    Hi
    I'm not a very technical person.
    I hope someone can help me. I have Win 2000 and MSIE 6.0.
    When I create a search list using google or yahoo and click on one of the
    results on the list I am redirected to a new search site with a popup. It's
    always a different site but with a similar look e.g. sestat.com
    I have run Ad-aware and Avaist antivirus with no result. Spybot S&D gets
    about three quarters way through and the PC crashes. I'v been using Spybot for 2 years with no problem until now.

    On advice I have run Hyjackthis and created a log but i dont know what to do next. I'v included the log file below.

    Any help or suggestions much appreciated.
    Thanks in advance
    Tech Rookie
     
    Last edited by a moderator: Apr 4, 2007
  2. techsearch

    techsearch Private E-2

    Re: I'm redirected from Google searchlist & Spybot crashing PC. Any suggestions welco

    Very Very Sorry.
    Iv just read that Hyjackthis logs mus be atached.
    will not happen again.
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Re: I'm redirected from Google searchlist & Spybot crashing PC. Any suggestions welco

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. techsearch

    techsearch Private E-2

    Still problems after Read&Run,PC shuttting down

    First off, apologies for my last thread. I pasted HJT Log in thread.
    Since then I have gone through all the steps in ‘read and run me first’

    My PC: Win 2k. MSIE 6.0. I use Avast, SpyBot S&D and Ad-aware (all up to date)
    I have had no problems for 2 years until now.

    My problems: When I create a search list using yahoo and click on one of the results on the list I am redirected to a new search site with a popup. It's
    always a different site but with a similar look e.g. sestat.com
    I have run Ad-aware and Avaist antivirus with no result. Spybot S&D gets
    about three quarters way through and the Pc shuts down.
    Also I can not start in safe mode. The PC shuts down.

    In ‘read and run me first’:
    I carried out steps 1 – 4 and downloaded and updated all the scans as instructed.

    I was unable to start in safe mode (pc shuts down) so I ran the list of scans as instructed in normal mode:
    Ccleaner: See log
    SpyBotS&D: pc shut down three quarter way through scan. No Log
    Counter Spy: Found 2 problems and Quarantined them. See Log (I think these are the source of my problems)
    OnLine Bitdefender: PC shut down during scan. Could not find log.
    Online Panda: Can not find Log
    Getrunkey: See Log
    Shownew: See Log
    Hijack This: See Log

    All the problems mentioned above are still occurring:
    Any help or advise would be much appreciated.
    Please remember I’m not very technical (it took me 2 full days to go through ‘read and run’)

    Thanks in advance
    Tech Rookie
     

    Attached Files:

  5. techsearch

    techsearch Private E-2

    Re: Still problems after Read&Run,PC shuttting down

    More Logs
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still problems after Read&Run,PC shuttting down

    Please see step 2 of the READ ME. You still have file extensions hidden. You must uncheck this!

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also uninstall Microsoft AntiSpyware which is no longer supported!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" <-- may be gone already after uninstalling
    O17 - HKLM\System\CCS\Services\Tcpip\..\{593C0DEC-C86F-4AD5-9A50-7EC393E5156A}: NameServer = 85.255.114.198,85.255.112.176
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7B055553-2156-41FF-9296-51B60502FD4A}: NameServer = 85.255.114.198 85.255.112.176
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DCDCF558-5923-44F6-9291-68E30D913D3F}: NameServer = 85.255.114.198,85.255.112.176
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.198 85.255.112.176
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.198 85.255.112.176
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.198 85.255.112.176

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  7. techsearch

    techsearch Private E-2

    Re: I'm redirected from Google searchlist & Spybot crashing PC. Any suggestions welco

    Hi
    Thanks for your response.
    I’v carried out the steps as u suggested.
    I redone step 2 of read me however everything was clicked or unclicked as suggested.
    I uninstalled all as suggested and clicked fix for the lines u suggested in HJT.
    Please find Logs as requested.

    Result:
    Im not getting redirected from google search list as before which is fantastic.
    Spybot is still crashing as before.
    thanks for all your help so far, very grateful.


    Tech Rookie.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I'm redirected from Google searchlist & Spybot crashing PC. Any suggestions welco

    Problems like this are typically not due to malware. Normally it is due to a physical problem like:
    - problem on you hard disk ( do an error check and a defrag)
    - problem in your registry ( a registry cleaner may help )
    - corruption in Spybot (uninstall, reboot <--- do not skip the reboot, reinstall )


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds