Can't Search from Address Bar

Discussion in 'Malware Help (A Specialist Will Reply)' started by kfriedel, Feb 18, 2005.

  1. kfriedel

    kfriedel Private E-2

    For some unknown reason (more than likely an issues related to spyware) I am no longer able to search from my IE Address bar. When I try to type in a string such as Cars for Sale, I get back an "Invalid Syntax Error" and the result that is displayed in the browser bar is "http:///?%20cars%20for%20sale".

    I have run several spyware programs, and have removed all that seems to be recognized. Attached below is my HijackThis log. Can anyone help? I have done all the obvious things related to IE and the settings, but nothing has worked. I have even run the google.exe to change my default search engine, but this did not improve things.


    Edit by chaslang: Inline log attached
     
    Last edited by a moderator: Feb 19, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Where to begin, first lets start by addressing these issues with HJT. Move HJT into a secure location, for example C:\Program Files\HJT

    C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

    Next, When running HJT be sure ALL BROWSERS ARE CLOSED!
    C:\Program Files\Internet Explorer\iexplore.exe


    Please note that HJT is NOT the first step in removing these infections. Please start out by following ALL the steps in this sticky thread
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    NEVER POST A LOG INLINE! This will most likely be removed or converted into a .txt attachment.

    Please allow me a moment to analyze your log.
     
  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Go ahead and do another scan with HijackThis and Check the Boxes for the following:

    Again, make sure All Browser Windows are Closed when you Click FIX.


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://sso.uboc.com/obc/forms/login.fcc?TYPE=33554433&REALMOID=06-6eaf05e5-8076 -11d5-a9ac-00025554812f&GUID=&SMAUTHREASON=0&TARGET=$SM$https://sso.uboc.com/Che ckLogin.jsp?user_type=S (obfuscated)

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://sso.uboc.com/obc/forms/login.fcc?TYPE=33554433&REALMOID=06-6eaf05e5-8076 -11d5-a9ac-00025554812f&GUID=&SMAUTHREASON=0&TARGET=$SM$https://sso.uboc.com/Che ckLogin.jsp?user_type=S (obfuscated)

    R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)

    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)

    O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)

    O4 - HKLM\..\Run: [Spyware remover] C:\WINDOWS\Remove_spyware.exe

    O4 - HKLM\..\RunOnce: [Desktop Search Removal Tool] "C:\WINDOWS\inst\kill.exe" /VERYSILENT /NOCANCEL /NORESTART /SP-

    O4 - HKLM\..\RunOnce: [Bonus Sites Removal Tool] "C:\WINDOWS\inst\kill.exe" /VERYSILENT /NOCANCEL /NORESTART /SP-

    O4 - HKLM\..\RunOnce: [iSearch Toolbar Removal Tool] "C:\WINDOWS\inst\kill.exe" /VERYSILENT /NOCANCEL /NORESTART /SP-

    O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/..._1/axofupld.cab




    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files Enabled and navigate to and DELETE the following if they should remain:

    C:\WINDOWS\Remove_spyware.exe

    C:\WINDOWS\inst\kill.exe



    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.


    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows and Scan with HijackThis and attach that log.
    Let me know of any problems you may have encountered with the above instructions and how your computer is running now.

    Good Luck!
     
  4. kfriedel

    kfriedel Private E-2

    THANKS FOR THE HELP!!!
    I did as you suggested, and my browser seems to work fine now when I type in "key words". Instead of the Microsoft Search Engine, I am directed to Google, which is fine by me.

    I have also attached the HijackThis log as you requested.
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


    You log looks clean, are you currently experiencing any problems? If not please continue to Reset Web Settings and default all security settings.


    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    After doing the above, let me know how things are running now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds