Google is screwed and it's driving me insane

Discussion in 'Malware Help (A Specialist Will Reply)' started by bek, Feb 10, 2005.

  1. bek

    bek Private E-2

    Sorry in advance for the long post, but I wanted to include as much info as possible.

    Here's the problem:
    When I go to google and search for something I get redirected to a page which looks pretty much like google, but isn't, and has a page or so of ads or 'undesirable' weblinks. Once I get to the second or third page the results seem to be normal. The address of this imitation Google is 61.131.54.618.cc

    I have had some spyware stuff on this pc before, in the last month, which a combination of ad-aware and spybot have removed.

    I have read the 'READ ME FIRST BEFORE ASKING FOR SUPPORT' thread and follwed the instructions.

    The Trend Micro and Symantec online scans were done in NORMAL mode instead of SAFE as I couldn't connect in safe mode. (I have dial-up AOL -rubbish I know) Neither found anything.

    In SAFE mode I ran: AVERT Stinger, Ad-Aware, Spybot, CWShredder, Kill2me about:Buster . They all found nothing.

    I also ran CCleaner. HSRemove said it removed 8 items, I don't know what they were.

    Rebooting in Normal mode showed that the problem was still there, so I then ran:
    a2 (a-squared) which found 1 malware: C:\WINDOWS\unstall.exe which apparently was something called Spyware.Win32.MediaMotor.a

    avast Virus Cleaner which found nothing

    and ADS-spy which found 4 ADS all are located in C:\bundle\Netscape\Win95_NT I can type the details in full if needed.

    If you need a hijackthis log file, let me know and I'll post it.

    Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. bek

    bek Private E-2

    Ok, here's the log file. I think I did everything how I was supposed to.
     

    Attached Files:

  4. PhilliePhan

    PhilliePhan Guest

    Hi Bek,

    Not too much in your HJT Log.

    Fix these lines in HJT:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\system32\DSMANA~1.DLL
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    Then, boot to Safe Mode with Viewing of Hidden Files Enabled and DELETE the following if it remains:

    C:\WINDOWS\system32\DSMANA~1.DLL

    NOW:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Reboot, attach a fresh HJT Log and tell us how things are running now. I'm sure Chas will check back when he can.

    PP :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    True PP! But this DSMANA~1.DLL is typically the problem with Google.
     
  6. bek

    bek Private E-2

    Thanks PP, you're a star! (And Chas too, obviously)
    I can happily Google again.
    Here's the HJT file anyway.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds