I need help!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by nettie3, Feb 5, 2008.

  1. nettie3

    nettie3 Private E-2

    I have somehow downloaded something that whenever I do a search on google it tries to access search-daily.com website and no matter what I do I can't seem to remove it.

    Any ideas how to remove this program from my computer and anything else that was installed on my computer?

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. nettie3

    nettie3 Private E-2

    I have installed and ran all four of the files and here are the results, I'm not really sure if it has fixed everything.

    Thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you check for any of the error messages mentioned on the Using MGtools download page? Based on your logs it would appear that you had errors when running MGtools and you need to correct them and get a new log. Before trying to fix this, do the below fix anyway which may not be complete since I don't have good logs. But it should help.


    Is your copy of Spyware Doctor a paid version or free trial. If free, uninstall it now.

    The below files don't belong in this folder. If you wish to keep them, move them someplace else. I would just delete them though since you don't need them.
    C:\Program Files\ie-ads.reg
    C:\Program Files\ie-ads-uninst.reg
    C:\Program Files\ReadMe.txt
    C:\Program Files\install.bat
    C:\Program Files\LICENSE.TXT
    C:\Program Files\PleaseRead.txt
    C:\Program Files\COPYING

    Uninstall the below old versions of software:
    Java(TM) 6 Update 3
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A75CE950-AA72-4E25-9F88-A65338C883EA} - C:\WINDOWS\system32\DAVCLN.dll
    O2 - BHO: (no name) - {D0D07706-1E5D-4D91-9482-34936DF411FC} - C:\WINDOWS\system32\DAVCLN.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger. Watch for error messages when you run GetLogs.bat and see the error messages and fixes listed here: Using MGtoolsand apply the fixes and run GetLogs.bat again to get a new log after correcting the errors.

    Make sure you tell me how things are working now!
     
  5. nettie3

    nettie3 Private E-2

    Hello,

    I have done the fixes like you posted and I ran a search on google and it still isn't working...when using google search and I click on the link it tries to open up a different webpage, it takes a couple of tries before actually opening up the webpage that I searched for.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not uninstall Viewpoint Media Player as requested.

    Avenger did not run properly and the item we were trying to fix did not get fixed. Let's try another method.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {D0D07706-1E5D-4D91-9482-34936DF411FC} - C:\WINDOWS\system32\DAVCLN.dll

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    Driver::
    yxwdipqt
    lcjgqjxz
     
    File::
    C:\WINDOWS\system32\DAVCLN.dll
    C:\WINDOWS\SYSTEM32\DRIVERS\yxwdipqt.dat
    C:\Documents and Settings\Nettie\Local Settings\Temp\izuevvls.ini
    C:\Documents and Settings\Nettie\Local Settings\Temp\lcjgqjxz.dat
     
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0D07706-1E5D-4D91-9482-34936DF411FC}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Nettie\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. nettie3

    nettie3 Private E-2

    HI,

    Well I did everything like you suggested...I did get an error when I first started Combofix but then it seemed to continue on through it. I did a few searches on Google and it is going to the proper websites not defaulting to other sites which is good. Is there a way to ensure that everything is gone off my computer or is it safe to say that if I don't see anything then I'm to guess its gone.

    Thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only real honest answer to a question like this is that you would have to delete your hard disk partition, re-partition, format and reinstall. So if you want a guarantee, that is what you will need to do.

    Other than that, what we can tell you is whether your logs are clean and you can determine how you PC is behaving. If you are uncomfortable with that and require a guarantee, then you will have to be ready to do the above procedure fairly often since most people are repeat offenders when it comes to getting malware infections. Most people just remove their malware and do not go thru the pains of a reinstall.

    Your logs are clean!

    Note: You should never install software like you did with AVG Antispyware. You installed it here:

    C:\Documents and Settings\Nettie\My Documents\AVG Anti-Spyware 7.5

    Installed programs should always be installed into their default folders as recommended by the installation programs. Normal this is a folder within the C:\Program Files folder. The way you have it installed, it looks like a malware imposter.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds