Ask.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by TinkBelle, Feb 13, 2011.

  1. TinkBelle

    TinkBelle Private E-2

    How do you remove the Ask.com toolbar/search engine? I've tried everything I could think of, and this sucker just won't go away.

    1. I deleted it from add/remove in the control panel.
    2. I deleted it from 2 places in the registry.
    3. I ran gmer.

    I restart my computer and voilĂ ! It's baaaaaaack.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please run MGtools as requested in the below link and then attach the C:\MGlogs.zip file. This should give us enough info to help you.

    Using MGtools
     
  3. TinkBelle

    TinkBelle Private E-2

    Hi Chaslang,

    OK I ran MGtools and have attached MGlogs.zip

    Thank you
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Uninstall the below software:
    Java(TM) 6 Update 21
    Viewpoint Media Player <-- This is even more problematic than Ask.com


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. TinkBelle

    TinkBelle Private E-2

    Okeedoke, here they are! Thanks again. :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Do you have any remaining issues with Ask.com?
     
  7. TinkBelle

    TinkBelle Private E-2

    Yup, it's still there! :(
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where/what (exactly) are you referring to?
     
  9. TinkBelle

    TinkBelle Private E-2

    It's a toolbar/search engine. I downloaded some kind of music playing thing, frostwire.com, and it asked if I wanted their toolbar and I was clicking accept repeatedly, and didn't realize until a split-second later that I clicked accept for the toolbar but it was downloading already.

    So when I open Firefox or IE, I've got Ask.com as my default page. And it's also has a smaller search engine window in the top right corner of this page, just to the right of the majorgeeks URL. It says the word Ask in a red oblong circle, and the words Ask.com in its side window.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's is what you get when you use junk like Frostwire. I suggest that you uninstall it.

    In Firefox and IE you will have to look to see if anything for Frostwire or Ask.com appear in addons and remove them.

    Did you select and fix the below line with analyse.exe as requested and where ALL BROWSERS closed as stated when you fix it?

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
     
  11. TinkBelle

    TinkBelle Private E-2

    Slap on the wrist accepted. :-o

    I uninstalled it the very next day cause it wasn't what I was looking for anyway. But...yes I followed your suggestions and clicked "fix" after the browser was closed. Also the Viewpoint Media (I think it was called) was no longer on the list to reject, I'm figuring because it disappeared after I uninstalled it from add/remove.

    Should I check hijack this again and see if it Ask.com comes back up?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then delete the below folders from it.

    C:\Documents and Settings\Mommy\Application Data\FrostWire
    C:\Documents and Settings\Mommy\My Documents\FrostWire
    C:\Program Files\FrostWire

    I think it is still there. Shut down Avast and Outpost then close all browsers, run analyse.exe again and select the below line then click fix.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis

    After fixing, close HijackThis and do the below.

    Make sure that you have disabled/delete browser addons for Ask.com and for Frostwire if any remain.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7/8 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Now how do things look?
     
  13. TinkBelle

    TinkBelle Private E-2

    OK I did it and....it's still there. :(
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete all of my instructions and attach the new log.
     
  15. TinkBelle

    TinkBelle Private E-2

    OK here is the hijackthis log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not what I asked for or need. Attach the new MGlogs.zip file.
     
  17. TinkBelle

    TinkBelle Private E-2

    Oh, I see what happened. I read your response on my email and there's so much more. OK, I'm reading it now, there's a lot more to do.
     
  18. TinkBelle

    TinkBelle Private E-2

    "Make sure that you have disabled/delete browser addons for Ask.com and for Frostwire if any remain."

    How do I do this?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In IE, click Tools, Manage Add-ons

    Similarly in Firefox, click Tools Add-ons
     
  20. TinkBelle

    TinkBelle Private E-2

    The good news is that there are no add-ons and that IE now is done with Ask.com! Msn came up instead.

    I'm going to go through the rest of your post hopefully the Mozilla Firefox will be fixed soon. Will update you. Thank you so much.
     
  21. TinkBelle

    TinkBelle Private E-2

    I'm supposed to copy this to notepad:

    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"=-

    ...How do I get to notepad?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have never used notepad????? :)

    Here is one of many ways.

    Click Start, Run, and enter notepad into the Run box and click OK
     
  23. TinkBelle

    TinkBelle Private E-2

    OK, let's see if something happened...
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the home page setting in IE was removed and also the search scope was removed from IE. Do you still have a problem with Firefox? If so, did you check addons?
     
  25. TinkBelle

    TinkBelle Private E-2

    Yes, I still have a problem with Firefox, and I checked the add-ons. I'll check again...

    Get Add-ons, Extensions, Themes, Plug-ins...I checked all of these and there's nothing listed under them that says "Ask" or "Frostwire".
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's see if we can fix Firefox.

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    C:\Program Files\Mozilla Firefox
    C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Is the problem gone now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds