I can't figure this out

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jozwitch, Jul 30, 2004.

  1. jozwitch

    jozwitch Private E-2

    Hi everyone!
    Although I have been using MajorGeeks for awhile now, this is my first post. I'm really hoping someone can help me out.
    S&D keeps telling me that my search assistant is being changed to a bunch of random letters - over and over and over again. What is this? I've never seen it before and it's driving me crazy!
    I am pretty sure that the problem is spyware, but I cannot get rid of it. I have done a virus scan with AntiVir9x, spyware scan with Spybot S&D, CCleaner, and CWShredder and the problem is still there! Oh, and I'm using WindowsME.
    I ran HijackThis, so here is the attachment. I found three things that I knew were wrong and fixed them, but the problem is still there.
    TIA

    PS: I hope the attachment works!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not following the directions at this line: http://forums.majorgeeks.com/showthread.php?t=35407
    It tells you specifically, "Please close ALL running programs BEFORE you run it. This includes your web browser, email, firewall, anti-virus and programs running in your system tray (icons in the very bottom right) It cuts down on the size of your log file, making our analysis easier and more reliable. If you need help, please attach your saved logfile as a text document to a new thread. "

    You did not do any of that.

    At any rate have HijackThis fix this line after shutting down Internet Explorer:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yjvrwbbwyklytpbxs.com/bd_T6FL_a92cFTNXnLtuqtjhGTQL4HizaKq0ZLJWTLi1wtYG43O1p7gJ0rsRtfgR.php

    Let me know if this resolves you problem. If not follow the directions in the previous link and post a new smaller log.
     
  3. jozwitch

    jozwitch Private E-2

    sorry

    Oops! I thought I had closed everything, but I didn't check running programs with Ctrl+Alt+Del. I did that this time and closed everything that would close. IE refuses to go anywhere. The log is shorter now!

    Also, I have fixed that search assistant problem already:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yjvrwbbwyklytpbxs.com/bd_T6F...7gJ0rsRtfgR.php

    It just comes back as another set of letters:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.rlwcuajtuhabwhk.us/bd_T6FL_a92cFTNXnLtuqtjhGTQL4HizaKq0ZLJWTLgCYjSvEMthoLgJ0rsRtfgR.htm

    That is the problem! I need to figure out what is causing that to happen and get rid of it.
    I really appreciate any help you guys can give! Thank you!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: sorry

    If you closed down you Internet Explorer sessions (browsers) as requested. You would not see two IExplorer.exe sessions running. Shut everything down. Run your HJT scan, save your log. Now you can start everything up again and connect back to here to post a log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: sorry

    Please give about:Buster a run. Follow the directions give on the download page. Copy and paste the logs it creates back here (as an attachment).

    Questions:
    1) Do you know what this is?
    O4 - HKLM\..\Run: [Five New] C:\PROGRA~1\SHIMBLAH\deletedriveless.exe

    2) Is this your ISP?: http://www.comcast.net
    3) What is you expected Home Page?

    Also run HijackThis and select the following line but DO NOT FIX YET:
    O3 - Toolbar: (no name) - {BC19934E-31A2-D4B1-F6A1-5742CFE9475C} - (no file)

    Now shut down all Internet Explorer sessions and click Fix in HijackThis.

    Post a new HijackThis log attachment too (you can combine it with the About Buster log).
     
  6. jozwitch

    jozwitch Private E-2

    I ran the About: Buster and it didn't find anything.

    I have tried multiple methods to close Internet Explorer to no avail. The Ctrl+Alt+Del Task Manager indicates two iterations of IE running, however highlighting and clicking "End Task" does nothing, with the exception of bringing up a pop-up window saying it is "not responding." I then click on the "End task now" button. After that I check the Task Manager again, and it's like I did nothing at all. Still two IE tasks running! *sighh* So, I thought "why not delete Internet Explorer from my computer since I use a different browser anyway?" Easier said than done. IE will not allow me to delete it from my computer unless it is not in use. SEE ABOVE PROBLEM. So I thought, "Why not surf in through MS-DOS and del or deltree the Internet Explorer directory?" This actually made the processer light shine, and i could hear a whirring sound in the CPU! But Lo and behold, when I brought up another "dir/w" there was that pesky "intern~1" directory! WHY WON'T IT DIE?!
     
  7. jozwitch

    jozwitch Private E-2

    Re: sorry

    thanks!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my last message to you where I asked some questions.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you answered while I still had not sent my message.
     
  10. jozwitch

    jozwitch Private E-2

    Fixed!

    I'm not sure what did it, but the problem is now gone! :D
    In my determination to get rid of IE last night, I deleted a bunch of unused programs in an attempt to clean up the PC and free up some memory. I also attempted to delete the 'deletedriveless' file and it wouldn't go away because it was in use. It was in the recycle bin, but I couldn't delete it completely. The search assistant problem was still there, even after several restarts, so I gave up and went to bed.

    This morning I turned on the computer and got the same old message from S&D - Search assistant changed to fsdreodndklie and so on. Out of habit I emptied the recycle bin when I saw it had stuff in it - and it worked! I went into SpyBlaster and changed the pages that had been changed back to what I wanted and waited. Nothing happened. S&D did not inform me of a search assistant change! I checked to see if IE was running - and it wasn't! So I quickly stopped all programs, ran HJT, and fixed that problem:

    "Also run HijackThis and select the following line but DO NOT FIX YET:
    O3 - Toolbar: (no name) - {BC19934E-31A2-D4B1-F6A1-5742CFE9475C} - (no file)

    Now shut down all Internet Explorer sessions and click Fix in HijackThis."

    I ran a new log, which is attached, just in case.
    I also restarted the computer. Still no message from S&D! Woohoo! I think it's gone!
    Thanks for your help! I really appreciate it!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Fixed!

    Sounds good! I did not notice anything else in your log. But I only looked quickly. You have way too much stuff running that should be shut off before posting a log. You should always shut down everything that is running that you recognize so that we do not have to figure out what they are.
     
  12. IPandSoDoYou

    IPandSoDoYou Private E-2

    Free is better, but when I had this problem i would fix it and two days later have it again... my dad got McAfee virus protection, and as long as it's running i havn't had a single problem with that, once we had it installed (McAfee) I did have to run CWshredder one more time and ad-aware and spybot, but since then i have had no problems with start page hijacking or search page hijacking.

    **McAfee EATS up the RAM :( :( ( i shut it down to play high-performance games
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    McAfee and Norton (in fact most virus scanners) provide little if any protection for these items. That's because they are not considered to be a virus. Unless you meant you were using some other McAfee program that was part of their security suite. But even then you will see from reading thru threads here, they do not protect you from many of these problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds