Infected system with Yoog search

Discussion in 'Malware Help (A Specialist Will Reply)' started by nlinecomputers, Dec 26, 2008.

  1. nlinecomputers

    nlinecomputers Private E-2

    Hello I have a system on my bench that is infected with Yoog search that I am unable to remove.

    System had other problems and was unable to boot into windows it would hang at the welcome screen. It would boot in safe mode but I was unable to run hijackthis or install any software at all. Regedit also would not run. I pulled the hard drive and slaved it a system and scanned it with Avira Free which removed some files. For some reason it didn't log it so I can attach that.

    I have performed the procedure found here: http://forums.majorgeeks.com/showthread.php?t=139313

    I will attach the logs.

    The system now boots up and most everything appears to work correctly except that on both IE and Firefox the search engine box is hijacked to Voog Search.

    Thanks.
     

    Attached Files:

  2. nlinecomputers

    nlinecomputers Private E-2

    One more log file.
     

    Attached Files:

  3. nlinecomputers

    nlinecomputers Private E-2

    And I just had a pop up box for Contextual ads from Addsite appear so I've still got other bad things going on. I'm going to disconnect it again from the internet.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I guess you did not see the below thread?

    http://forums.majorgeeks.com/showthread.php?t=176817

    Try what I suggested in msg # 5 for you Yoog problems. It worked for that user.

    Then continue on with the below to finish fixing other issues.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now download and run the new version of MGtools.exe



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 28, 2008
  5. nlinecomputers

    nlinecomputers Private E-2

    Ok from the last time I've posted I have had some success on my own but I will do as you ask as well.

    What I've done was remove JAVA and installed the latest version. (11) I also removed flash using Adobe's flash uninstaller tool and installed the latest version of both the IE and Firefox versions. I uninstalled the adssite program in add/remove programs. I went into the registry and reomved any line that had Yoog in it. I went into about:config in firefox and reset any line with yoog to defaults. I removed Yoog as the search engine in Firefox and set google as default. In IE7 I used the reset all defaults wizard.

    This appears to have removed yoog or any other badware so I have now installed SP3.

    I will run your items but I think I'm already clean. I will post logs when finished.
     
  6. nlinecomputers

    nlinecomputers Private E-2

    Ok here are the logs.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this was also requested in step 1 of the READ & RUN ME and in my previous instructions.

    I still see Adssite Advanced Toolbar in add/remove programs and this was also requested to be uninstall in step 1 of the READ & RUN ME. ;) So based in your last logs, you still need to uninstall this.

    You also need to delete the below two files:
    c:\windows\002754_.tmp
    c:\windows\TMP0001.TMP

    After doing the above your logs will be clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  8. nlinecomputers

    nlinecomputers Private E-2

    Done.

    Thanks.

    You may lock this topic as fixed.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds