Completed READ & RUN ME FIRST... still problem!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cool Hand Zeke, Jan 20, 2007.

  1. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    Hello. I have completed steps 1-6 on "READ & RUN ME FIRST" sticky. Then completed step 7 (Hijack This). Each step I CAREFULLY followed the precise directions, following the links and downloading/running the progams as directed. I still have this VERY ANNOYING PROBLEM...

    I have the Google Toolbar installed and have had it for a very long time without any problems. But something has happened within the last week or so. After I do a successful search from the Google Toolbar (let's say "Major Geeks"), it successfully brings up the SEARCH RESULTS PAGE. But when I click on the LINK that should go directly to the website, it brings me to an entirely unrelated site!!! What the heck! For instance, when I click on "Major Geeks," it brings me to "collegeresumes.com" or something completely unrelated. So, I click the back button on MS Internet Explorer 7 (the new one). When I click on the link for the second time, it brings me to a SECOND unrelated site. Back button. EVERY TIME I click on the link for the THIRD time, it goes to the proper website. THIRD TIMES THE CHARM. rolleyes Lately I have been simply been copying and pasting the direct URL address to the website into the address line and clicking enter. But this is quite annoying and something I really wish I wouldn't have to do.

    I have always tried to stay updated on viruses, malware, adware, etc. I know a little, but not a lot. Installed on my computer are the following programs that I run weekly: Trend Micro PC-cillin, Spy Sweeper, Ad-Aware SE Plus, Spybot Search & Destroy, and SpywareBlaster.

    Also, when I booted the computer in Normal Mode, a whole bunch of crap came up that I NEVER use. Just so you know...

    Please help. I'm not sure what to do next. Hopefully somethings jumps out at you upon looking at the attachments.

    Thank you very, very much.
    Cool Hand Zeke
     

    Attached Files:

  2. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    SAME MESSAGE ABOVE... PART TWO for the additional files that need to be attached.

    Again, thank you for your help.
     

    Attached Files:

  3. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    Thank you for the reply. The other similar threads are a help, but not really.

    With regards to the similar threads, they all have similar (but different) issues with popups and redirecting. My issue is specifically redirecting... After clicking on the link provided in the search results page, it always redirects. For instance, "Seattle Seahawks" link took me to "ebay" sports earch results and "playersarena.com."

    Also, the items the other threads were told to "fix" within HijackThis are not present in my scan results. And the items the other threads were told to add to Killbox upon startup are quite vast and different than my system.

    Please help me with more specifics. I've been trying to fix this problem for quite some time...

    Thank you very much.

    Do I need to rerun all steps 1-6 again and repost those files?
     

    Attached Files:

  4. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    Wait a minute? Maybe nobody has replied yet! Are the "similar threads" automatic at the bottom?

    Man, do I feel dumb if they are.

    Please read my original message below and my couple of replies. Thank you.
     
  5. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    Now unrelated logos in address bar...

    I'm the only person to reply to my own message! :cry

    Now I have multiple tiny little logos next to the URL address in the address line. But they are not the correct logos! Right now the "ebay" logo sits next to http://forums.majorgeeks.com/newreply.php etc. etc.

    I have a feeling that this has something to do with my problem. I've done all that I know how and will continue trying.

    I know that my problem is not as significant as others, but when you get the chance please help.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read the stciky entitled "Don't Bump as it only hurts you" ....we will be working on a fix and will get to you ...have patience.
     
  7. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    I don't think anyone ever got to this :cry ...unless the wait time is quite significant. Otherwise, I feel that I've been pretty patient. I was unaware of the "bumping" thing until Tim alerted me of that.

    I'll redo "read & run me first." But if anyone can see something from the attachments of my previous posts, I would greatly appreciate it.

    Thank you very much.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I apologize for the delay.

    Run this WareOut Removal and attach the requested log.

    * Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    * Click Next, then Install.
    * Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    * The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    * Your system may take longer than usual to load; this is normal.
    * When your system reboots, follow the prompts. Afterwards, HijackThis will launch. (If it does not launch, run it yourself). Please click Scan, and check the following items if they still exist:

    O17 - HKLM\System\CCS\Services\Tcpip\..\{C4D64479-96C7-445A-8B06-E1393E52907B}: NameServer = 85.255.116.21,85.255.112.230
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C9A43A9E-826D-4595-B4AF-2E4BC35D13ED}: NameServer = 85.255.116.21,85.255.112.230
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F32E8226-217E-4AD5-A457-0D89A2798DF7}: NameServer = 85.255.116.21,85.255.112.230
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.21 85.255.112.230
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.21 85.255.112.230

    After clicking Fix Checked, close HijackThis, and click OK to proceed.
    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  9. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    Tim, you're awesome. Thank you for your help. It looks as if you're busy on in this "Malware Removal" section! Your name is posted everywhere...

    I followed the precise directions from the "WareOut Removal" link and have attached a copy of the log.

    Also, I ran a new HijackThis log. It looks as if "WareOut" deleted ONE of the items you listed that I should delete if they still existed: O17 - HKLM\System\CCS\Services\Tcpip\..\{C4D64479-96C7-445A-8B06-E1393E52907B}: NameServer = 85.255.116.21,85.255.112.230

    So, as per your instructions I checked the remaining FOUR items and "fixed"/deleted those. Attached is the log from HijackThis PRIOR to my fixing the other four items.

    From here, I'm not sure what to do next. Do you feel that the problem may be fixed? If so, I won't hesitate to use Google search again and see if search result links take me to the proper website. Otherwise, if you feel that there is further items to be fixed, I'll wait for your orders.

    Once again, thank you. You and the rest of the gang who help us are truly great.

    Zeke
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like you fixed the O17 lines. It is possible that Spy Sweeper and or CounterSpy blocked the changes and that you needed to approve the change in them.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Mike Wawrzycki\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now shutdown Spy Sweeper and fix the below lines in HJT again (make sure all browsers are closed before fixing):

    O17 - HKLM\System\CCS\Services\Tcpip\..\{C9A43A9E-826D-4595-B4AF-2E4BC35D13ED}: NameServer = 85.255.116.21,85.255.112.230
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F32E8226-217E-4AD5-A457-0D89A2798DF7}: NameServer = 85.255.116.21,85.255.112.230
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.21 85.255.112.230
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.21 85.255.112.230

    Now reboot and attach a new HJT log.

    Try doing some surfing and let us know how things are working.
     
  11. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    :D :D :D

    Tim & chaslang -

    THANK YOU VERY MUCH. I did the final steps and am able to search with Google, and the links actually take me to the proper page!! It's great to have it working properly again.

    I've attached one final HijackThis log. The funny part is that I am still getting different tiny logos where they shouldn't be. This isn't a big deal, but for instance the Wikipedia logo ("W") is next to the current URL address: http://forums.majorgeeks.com/newreply.php?do=newreply&noquote=1&p=919196. Shouldn't this be the "sergeant with cigar" Major Geek logo?

    Thanks again for all your help.

    Zeke
     
  12. Cool Hand Zeke

    Cool Hand Zeke Private E-2

    Woops, forgot to attach the log...
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly not sure why you are having the strange icons...however:

    Fix the below lines in HJT

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seattlepi.nwsource.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    Let us know how things are now.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds