Can't get rid of Crawler search engine.

Discussion in 'Malware Help (A Specialist Will Reply)' started by usmc_wife_1345, Feb 2, 2010.

  1. usmc_wife_1345

    usmc_wife_1345 Private E-2

    It is there and not going away. It is not listed in my add on's or extensions. It is not in add/remove programs. Google is set as my default search engine and it isn't working. I've run S&D, CCleaner, AVG... Nothing is coming up. Please help! It's a big PIMA!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay So i've gotten to Step 6 on R&R me, Step #2 of the Windows XP cleaning. I can't down load Super Anti Spyware. I've never had this problem before. I keep getting this error and if I "ignore", It won't let me open it.


    I have gone through programs list already and deleted all versions of SuperAnti spy ware and tried down load from the different choices (author, major geeks etc) for the options given.
     
    Last edited by a moderator: Feb 13, 2010
  4. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Attaching logs b/c I went on to do everything else.
    Also, I ran MGTools but I can't find the log anywhere. I can't find where it was saved.

    Found it.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running an old version of MGTools, plus you did not put ComboFix directly on your desktop ( Running from: c:\documents and settings\Anna\My Documents\Downloads\ComboFix.exe ).

    Please put ComboFix on your desktop or our final instructions will not work. Let's reset your internet defaults:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me if you get a success message and if you are still having issues after a reboot.
     
  6. usmc_wife_1345

    usmc_wife_1345 Private E-2

    I guess I dont' know what to do the -- am confused. I have an icon on my desktop and just click on it. and I downloaded MGTools form one of the links you provided??

    I'll do the internet defaults now...
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing your logs show is that you have the combofix log on your desktop, not the ComboFix.exe:
    C:\Documents and Settings\Anna\Desktop\combofx log 2_11_2010.txt

    The latest version of MGTools is:
    12/28/2009 Version 2.66
    Not:
    09/10/2009 Version 2.59

    If the registry fix doesnt solve the issue, I will have you download the latest version. :)
     
  8. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I did the registry fix and I still have the stupid crawler search engine. UGH!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As TimW stated, delete the below copy of ComboFix and then download and save the current version of ComboFix.exe directly to you Desktop not to a folder or anywhere else on your Desktop. You do not have ComboFix.exe on your Desktop. You have a link to the My Documents folder on your Desktop. Then continue.

    c:\documents and settings\Anna\My Documents\Downloads\ComboFix.exe

    The copy of MGtools that you are using is more than 5 months out of date. You did not download this from our current link. It is an old file that you have had since last October as can be seen by the file date. Make sure you always download the current version as we request. Also MGtools.exe does not belong on your Desktop.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )




    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Feb 13, 2010
  10. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay in my attempt to get combofix in the correct place b/c I don't have the option of saving it to my desktop, it ran before I could do the notepad thing. I attached the log of what it gave me. I didn't want to do it since Im not sure if I still can.

    I removed MGTools (though no idea where it's supposed to go once I attempt to download it for the third time) and will run that in a sec.
     
    Last edited by a moderator: Feb 13, 2010
  11. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I couldn't edit my post to add the logs so here they are. No idea if I did it right....
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not do the first thing requested.

    You still have ComboFix here: c:\documents and settings\Anna\My Documents\Downloads\ComboFix.exe

    You MUST delete this file and then download and save combofix.exe DIRECTLY to your Desktop so that it is here: c:\documents and settings\Anna\Desktop\ComboFix.exe

    Also you saved MGtools.exe here: C:\Documents and Settings\Anna\My Documents\Downloads\MGtools(2).exe
    It belongs here: C:\MGtools.exe

    Then refollow my previous instructions again.

    What browser are you using to download files?
     
  13. usmc_wife_1345

    usmc_wife_1345 Private E-2

    As I have said I DO NOT have an option to save it anywhere but to where it is saving. There is no choice. I can not save it to my desktop. It will not let me save it to my desktop or anywhere else for that matter. I have deleted combofix about 10 times now and reinstalled it.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I asked in my last message what browser you are using to download with!!!! I assume you are using FireFox. If so, you are the one who changed it to download to the c:\documents and settings\Anna\My Documents\Downloads folder bcecause the default for FireFox is the Desktop which is a poor choice anyway. Also you should not have installed FireFox there: C:\Documents and Settings\Anna\My Documents\Installed\firefox.exe Installed programs belong in their default folders which is under C:\Program Files

    Just change the where to save downloads option back to Always ask me where to save files. You will find this under Tools, Options on the Main selection form. This way you can save files anywhere you want.

    Note: Things you download (like ComboFix, MGtools and anything else, are not your Documents or anyone else's documents. They are binary installation files and they should not be saved in a folder lableled as documents. Saving them under a Downloads folder makes sense but that should not be under My Documents. See an example of how I suggest saving downloads and saving them into organized and properly identifyable folder in message number 25 of the below thread:

    http://forums.majorgeeks.com/showthread.php?p=1256797#post1256797
     
    Last edited: Feb 14, 2010
  15. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay perhaps I am just computer illiterate. I've never changed any firefox settings and I never choose to install it to documents. I have a FF shortcut there b/c I like to be able to click it easily from the desk top. I don't get why it matters if I save things under certain folder names anyway, but whatever. Regardless, I don't know how to go about changing anything so I can't "change it back." making assumptions that I have to have not done stuff is really rude, insulting and makes me feel dumb. I didn't know making me feel like an *** was part of the help I'd receive. I'm not as computer literate as you've made me out to be. Can you please instead of saying all the things "I've done" and I should just go "undo" them, just tell me how to do it? Break it down barney style b/c apparently I need it.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but I was just stating the facts. FireFox comes with the default set to your Desktop and that is not where you are saving things. Thus you or someone else who uses the PC changed the settings. This is not an assumption. It is a fact.

    Already gave you how to change the setting to allow you to always choose where to save download in message # 14. See the middle paragraph.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds