Help with hijacked browser, maybe search assistant

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Confused Newbie, Sep 21, 2004.

  1. Confused Newbie

    Confused Newbie Private E-2

    Hi everyone.

    This is my first post. I have had a problem with my browser being hijacked, I think by Search Assistant.

    I have 3 problems going on. First a tabbed bar appeared at the top of the browser page, which entries change from time to time, like casino, ebay, finances etc. It's search always takes me to one place:
    "Search the Web", "Your search ends here"
    http://lop.com/search/search.cgi?src=searchbar3&s="search word" quotes are mine.

    The second problem is a thick blue bar at the bottom of the browser page that pops up whether the browser is on or not. It has option buttons to click. It's not up at the moment so I can't be more descriptive.

    The third problem is that a Spybot Resident box keeps appearing saying:
    Category: Browser Page
    Change: Value Changed
    Entry: Search Assistant [sometimes it says something else]
    Old data: http://www.[jumbled letters].net/APPqIFrQzH..............
    New Data: http://www.[jumbled letters].com/APPqIFrQzH...........

    I think the letters change each time, but I haven't kept up with that.

    I followed your instructions and went through the tutorial thoroughly. I ran the programs in order. The PC-cillin virus scan picked up a trojan that I deleted. Spybot (which I am having a great deal of difficulty running because it wants to freeze on me and system restore doesn't work) fixed 5 problems and left 2: DSO exploit and Connect MFC Application. Everything else came up clear.

    The problems are still there, plus an added problem. I am getting X warning boxes popping up, saying things like:
    "Autodown.exe Unable to locate componant. The application failed to start because MSVCRT40.dll was not found. Reinstalling....."

    I had downloaded and ran HijackThis before I came to your site. I changed nothing. I have not run it since your tutorial. I decided not to follow option 1 because I am not that experienced. I humbly admit I am just a wannabe geek and I need you major geeks to help me with this problem.

    Any suggestions?

    Confused newbie
     
  2. Confused Newbie

    Confused Newbie Private E-2

    addendum to Help with hijacked browser, maybe search assistant

    Hi again,

    I want to add that when I did a security check on my system, everything turned out secure except my virus program. It said I had no virus program protecting the computer. I have just installed EZ Antivirus after my Zone Alarm expired. I wonder why it wasn't recognized.

    Confused Newbie
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Re: addendum to Help with hijacked browser, maybe search assistant

    Whew. Well, autodown does not run because you may not have the VB6 runtime files installed. You can get them in our miscellaneous section, BUT dont now because that virus will shut off your antivirus and firewall as shown in the first links list. This explains why your antivirus was not recognized :)

    http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=29927
    http://securityresponse.symantec.com/avcenter/venc/data/w32.darker.worm.html
    http://vil.nai.com/vil/content/v_100877.htm

    Stinger in safe mode should have removed it. Remove any references to it in startup and Hijack This. Same with any odd search assistant and lop files in Hijack This, many being in the 01 and 02 area.

    If still stuck, let me see you log file.
     
  4. Confused Newbie

    Confused Newbie Private E-2

    Hi Major,

    Thanks for having a look at my problem. Zone Lab said that the Win32.KillAV.B creates a winlogon.exe in Windows, which I have. I am still unsure of what to delete. I see a few other suspicious things.

    I ran Stinger in Safe Mode but didn't bring up anything.

    I have been attempting to do the Generic Solution and I am getting "confused". I think I will go ahead and send you my log. I appreciate your patience with me taking baby steps with this (I have killed computers being bold and taking steps on my own). A walk through would be appreciated.

    I could scream, but I'll take deep breathes instead.

    Thanks
    (very) confused newbie
     

    Attached Files:

  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Crap, I got all the way through this and a second logfile started, theres other crap here, if we have to do this again, please only post the log file by itself, once :) Im guessing the second was the new logfile, heres hoping as it was incomplete, if so remove these and lets see where were at.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    http://www.yyhzedqieceoktdbflil.net...eRhN46omnd0Y0P7qy4ID0l/AxRg2FJAEJWuqSvbp.html
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - (no
    file)
    O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} -
    C:\WINDOWS\questmod.dll (file missing)
    O2 - BHO: (no name) - {8CBD1B38-A6E6-D7A6-AD8C-E83BB8C1502E} -
    C:\PROGRA~1\SAFESA~1\User Chin.exe
    O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no
    file)
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser
    MOUSE\mouse32a.exe
    O4 - HKLM\..\Run: [downloaddefy] C:\PROGRA~1\64FACE~1\Debug 01 two.exe

    Not real sure on this one:
    O4 - HKLM\..\Run: [Media fast base burn] C:\Documents and Settings\All
    Users\Application Data\Help Multi Media Fast\four trust.exe

    O9 - Extra button: Yahoo! Login -
    {2499216C-4BA5-11D5-BD9C-000103C116D5} - (no file)
    O9 - Extra 'Tools' menuitem: Yahoo! Login -
    {2499216C-4BA5-11D5-BD9C-000103C116D5} - (no file)
     
  6. Confused Newbie

    Confused Newbie Private E-2

    Ooops. Sorry about that. I'm onto it now. We'll see what happens.

    confused newbie
     
  7. Confused Newbie

    Confused Newbie Private E-2

    Major Attitude,

    I have deleted the entries that you suggested. On the IE browser, the top search bar with tabs is still there. I did not see the bottom blue bar, but it comes and goes anyway, so unsure about it.

    Spybot resident popped up and it seems that SearchAssistant is still in control of the browser. Or something is. It has a new http: from before I ran the fix on HijackThis.

    I didn't say this before, because I didn't think of it, but the browser sometimes starts on Googles search page, and I have never designated it to be the homepage for this computer. When I run a search, it still goes to search the web.

    Thanks for hanging in there with me. I don't know why it ran 2 copies of the log.

    Less anxious Confused Newbie
     
  8. Confused Newbie

    Confused Newbie Private E-2

    There is something I didn't think about until now. I don't think I had the system files hidden, unchecked when I ran HijackThis. I have now unchecked the hide system files. Do you think I should run another log?

    Confused Newbie
     
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Then you lied to me on message one. I would go back and re-do the tutorial, this time not skipping anything.

    I always wonder when we get stuck at this point, and its usually because steps were skipped. If you skip steps, you may add new files, new registry entries and make the removal process much, much more difficult. This is why we have the tutorial.

    Do all the steps, come back and give me a proper logfile.
     
  10. Confused Newbie

    Confused Newbie Private E-2

    Hello Major,

    I did not lie. I am inexperienced. I went back over threads and tutorial to see if there was something I missed, and I found that. Not a lie. Just a mistake. I really do appreciate the time that you are giving me, as I cannot do this on my own.

    If I have put you out, it was unintentional. I am sending the new log. I haven't compared it to the other log yet, but will as soon as I send this.

    Confused Newbie
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why does your log still duplicate itself. You have two sets of from R0 down to O16 lines. Are you using the Save log button in HijackThis or are you using a cut & paste of some sort.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and put check marks on the following items but do not click fix until you shutdown all browsers including the one you are reading this in:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.nclbyirzwjgdhaydefkn.com/APPqIFrQZHKOe/Na4duTbAf6eRhN46omnd0Y0P7qy4IP0Rqw5SQGo5AEJWuqSvbp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll (file missing)
    O4 - HKLM\..\Run: [downloaddefy] C:\PROGRA~1\64FACE~1\Debug 01 two.exe

    Then reboot in safe mode and use Windows Explorer to delete
    C:\PROGRA~1\64FACE~1 <---- the whole directory

    Now while in safe mode run Ad-Aware SE and click Scan now and select Scan volume for ADS. The click the underlined word 'Select' and check you C: drive. Then click proceed, then click next to start the scan. Save the log and post it here as an attachment. Make sure you clean all that it finds. Then run the VX2 Cleaner pluging that should have been downloaded. Let me know if it finds anything.

    Now reboot in normal mode and post the Ad-Aware log. And let me know if there were any problems along the way.
     
  13. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Wanted to apologize to you fro everyone reading, got your email, was unaware of the situation. Lot of people cut corners, then wonder why they can not remove the problem or give up as if we could not help. So, lets carry on as Chaslang said, you have 2 sets of r0-016 lines, try and scan and then save it as a text file :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry MA. I did not see you coming back in. So I figured I would pickup where you left off. ;)
     
  15. Confused Newbie

    Confused Newbie Private E-2

    I am not sure why I get 2 readouts. I didn't realize it happened again. I just used the save log and then save the log to text. I did it the way you suggest should I try Chaslangs suggestion. Thankyou Chaslang, by the way. I will scan again and save to text, then post.

    confused Lisa newbie
     
  16. Confused Newbie

    Confused Newbie Private E-2

    I am back. I just scanned again and saved the log. I checked the log this time before I saved it to text and it was doubled up again. Could me hitting the key twice perhaps make it run twice? Oh well. Here is the log. Thanks,

    Confused Lisa Newbie :)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This log is only a single one!

    You need to run those steps I gave you below in message # 12.
     
  18. Confused Newbie

    Confused Newbie Private E-2

    Ok, I am doing that now. I am using a different computer to stay online.

    Confused Newbie
     
  19. Confused Newbie

    Confused Newbie Private E-2

    Ok, I followed the steps below, and I had to start the program 3x to get it to run. Starting IE was very sluggish, but there is no bar above and below, and so far I haven't seen a Spybot popup. The VX2 status, was system clean. The log is attached. Perhaps? Maybe there is light at the end of the tunnel?

    Cautiously happy confused newbie
     

    Attached Files:

  20. Confused Newbie

    Confused Newbie Private E-2

    Yes! It's fixed!!! Help with hijacked browser, maybe search assistant

    How do I change that frowny icon to grinning? YEAH!!
    Thank you so much.

    No more Confused newbie

    Do you take donations, or should I just buy a TShirt?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Yes! It's fixed!!! Help with hijacked browser, maybe search assistant

    You're welcome. Happy we could help.

    So I take that everything is working OK now and our work is done here.
     
  22. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Re: Yes! It's fixed!!! Help with hijacked browser, maybe search assistant

    Tell a friend, that is incredible payback for people to want to tell others about us. Come by again :)

     
  23. Confused Newbie

    Confused Newbie Private E-2

    Yes, it works!! Even IE is not sluggish anymore. Computer is fast! I will certainly pass it around. Sorry I can't change the emoticon on the thread.
    Thanks again.

    no more Confused Newbie
     
  24. BeltzeBub

    BeltzeBub Private E-2

    I just have to say this.. i have had the EXACT same problem.. up until now!
    I cant thank u guys enough.. i mean, i could never have fixed it myself.
    you guys rock! im definately gonna speak well of you, you guys get five sofas of five! keep it up! :)
     
  25. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Man that feels good after a long day :)
     
  26. onesandzeros

    onesandzeros Private E-2

    Hello,

    I am not entirely sure this is okay(using another person's thread) but I have reached a somewhat critical point. If this is not okay please let me know. I have some version of the hijack trojan. I did the "cleaning" instructions posted on the website dlsreport.com..There were a total of 3 virusus found by the freeware they recommended and I found two trojans with trojanhunter 4. Whenever I try to install hijackthis or CWShredder, the browser shutsdown before I can download it OR if I manage to copy one of the EXE(s) over to the laptop they are never visible. I have even gone so far as to try to rename the exe and then rename it again on the problem computer..no dice. I have "cleaned" the laptop and still can't get the proper software on. Any suggestions? I have tried to tackle this thing on my own for a over 24 hrs and still haven't gotten anywhere..If anyone can help me I would appreciate it.

    The laptop is NT 4.0 WORKSTATION...

    Thank you for the consideration,

    supernewbie... p.s. If anyone can point me to the directions on how to start my own thread, that would be good too, so I don't have to do this again.
     
  27. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  28. onesandzeros

    onesandzeros Private E-2

    Major Attitude,

    I may have been misleading before..allow me to clairfy. The tutorial I followed was at www.dslreports.com/faq/9721...or at least a piece of it..

    It said that I should probably use at least 3 virus scanning utils..2 of them were web based...so I didn't download any logfiles(rookie mistake). the third was a virus util called mwav. It was then that I downloaded trojan hunter4...

    Having said all of that, I tried to use your links(on the infected machine) to the adware and spybot..etc and everytime I do the browser just closes itself down. I tried downloading the files to another pc and transferring them over...no dice there either. So how do I complete your tutorial(which is much more comprehensive than the last one I found) when I am ubable to link to the page? Would it work to maybe try and burn them to CD'S and run it? Or is that endevor futile? I wrote a piece of code to get to majorgeeks.com (no big deal just 3 lines) so that I could skip the loading of the default page eqgsif.outhost.info...the page even has a link to "remove spyware"...

    If I can't link to the page what else should I try? I will try running a scan with the two utils I have on the infected machine until I hear from you...I just hope I don't have to format the drive..After this posting I will start a neew thread. Thanks for responding so quickly..you guys are a class act...

    Thanks,

    OneandZeros
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds