All search links redirect (google, yahoo, etc)

Discussion in 'Malware Help (A Specialist Will Reply)' started by PMB, Jan 23, 2010.

  1. PMB

    PMB Private E-2

    Google, yahoo etc. all redirect.

    I have tried to follow the directions.

    1. SAS won't run (nothing happens at all)
    2. MAM won't run (nothing happens at all; I renamed file as directed.)
    3. The combofix link doesn't work for me, so I can't download it.
    4. Rootrepeal log is attached.
    5. MG tools log is attached.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below which appears to be broken:
    Norton Security Center

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKCU\..\Run: [cls_pack.exe] C:\DOCUME~1\MiriamG\LOCALS~1\Temp\cls_pack.exe
    O4 - HKCU\..\Run: [Malware Defense] "C:\Program Files\Malware Defense\mdefense.exe" -noscan
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (file missing)
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, run SUPERAntiSpyware and Malwarebytes that you were unable to run before.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • the logs from SUPERAntiSpyware and Malwarebytes
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. PMB

    PMB Private E-2

    I have removed Windows Messenger, uninstalled Norton security center, and fixed the appropriate lines with the hijackthis! tool (except for the last, the Norton Security Center line, which was no longer there).

    Now I am up to installing Avenger.exe, but the link does not appear to be working. Is there another link to download it from, or should I just wait?

    Thank you so much for all your help so far.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It works just fine. So try again or download it using another PC.
     
  5. PMB

    PMB Private E-2

    I was finally able to access another computer to download avenger and transfer it to mine.

    Everything seemed to go as it was supposed to, except that now I can't seem to find the avenger log. It did pop up when I was done running it, but in the instructions it said it saved automatically, so I exited, and now I can't find it at the specified location, or any other location either (using a search). Trying to open it from the avenger application itself didn't work, either; it says there are no logs saved.

    The other logs are all attached; everything seems to be working okay right now. Should I run avenger again in order to get another log? Also, using SAS quarantined the objects found, but it didn't remove/delete them automatically. Is it safe for me to delete them all? Thank you so much for all your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As long as you don't unselect them and continue on, it automatically deletes them. Yes they all needed to be removed. You could rescan to see if any remain. Attach a new log. You need to do this before we can continue since we need to be sure you removed everything. Based on your logs, you did not.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\MiriamG\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new SUPERAntiSpyware log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds