malware affecting searches

Discussion in 'Malware Help (A Specialist Will Reply)' started by ryangn, Dec 30, 2008.

  1. ryangn

    ryangn Private E-2

    Whenever a search is done I get accurate descriptions of the webpage but a link to something else. The links goto websites like beseen.com, freescan.antivirus.com, etc. I have followed the "read & run me first" with no luck. I have attached the logs. I hope I did everything correct. Thanks for your help and happy new year.
     

    Attached Files:

  2. ryangn

    ryangn Private E-2

    Here is the last log. Thank you again!!!!
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to Major Geeks, ryangn

    Please be patient while I review your logs.

    Thanks,
    dr.m
     
  4. ryangn

    ryangn Private E-2

    Thank you
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ryangn

    Are you meaning that a web search gives accurate results/returns... but clicking on any of links you get re-directed to something else? Does this happen with all browsers? Does it happen in Safe Mode?

    You used outdated versions of both MGTools and SUPERAntiSpyware. UN-install SAS, delete the MGTools.zip and the MGTools folder.

    *Use this link Windows XP Cleaning Procedure to download the updated versions.
    *Run CCleaner
    *Install and immediately update the definitions for SAS

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the updated SAS.

    Attach new MGlogs.zip & SAS Scan log to your next reply, answer my questions...AND describe how your pc is working now.

    Thanks!
    dr.m
     
  6. ryangn

    ryangn Private E-2

    Below is a copy of the first two results of a google search for Target(the store). It shows the correct heading and description but the web address is not what it should be and if I click on the link it sends me to beseen.com or monstermarketplace.com or etc. I could not connect to the internet in safe mode and internet explorer is the only browser I have installed and use. I did everythink else you asked and attached those logs. Other than the search problem my computer seems to be running just fine. I appreciate your continued help.


    Welcome to TargetExpect More, Pay Less at Target.com, the official Target online retail site. Shop the latest in Women, Men, Baby, Kids, Home, Bed+Bath, Furniture, Sports, ...
    Show stock quote for TGT
    www.beseen.com - 157k - Cached - Similar pages


    Target : Store Locator : Store LocatorEnter your city and state or ZIP Code to find a Target store. Only search for stores with: ... Sign up to receive special offers and promotions from Target. ...
    www.monstermarketplace.com - 155k - Cached - Similar pages
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ryangn

    Please download and try Mozilla Firefox 3 3.0.5 just to see if you have the same problems.

    * Did you have any browser add-on with IE Explorer 6? How are you connected to the internet --- dialup/Cable/DSL? Are you using a router between your cable or DLS modem?

    Also - give me this info... right click on the "Welcome to Target link" and select Properties. What does it say for "Address"? Do the same for the "Target: Store Locator" link.

    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix, exit HJT.

    Step 2:
    Run Ccleaner

    Step 3:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip

    Make sure that you answer my questions, tell me if you had any problems running this procedure and give a description of how things are working now!

    Thanks!
    dr.m
     
  8. ryangn

    ryangn Private E-2

    I downloaded and installed firefox. I still have the same problems with web searches with firefox.

    There is a list of add-ons listed under Tools>Manage add-ons... (adobe pdf reader link helper, diagnose connection problems..., java(tm) plug-in 2 ssv helper, java(tm) plug-in ssv helper, jqsiestartdetectorimpl class, shockwave flash object, spybot - search & destroy configuration, spybot-sd ie protection, windows messenger) and thats all I know about add-ons?

    I am connected via cable(comcast) with a router between the cable modem. This is the only computer currently plugged into the router.

    The addresses I get when I right click on the links are:
    "Welcome to Target link"
    http://209.85.171.199/url?
    q=http://www.beeseen.com/

    "Target: store locator link"
    http://209.85.171.199/url?
    q=http://www.monstermarketplace.com/

    I followed the next three steps and attached the new logs. The computer still seems to be working just fine. Just the web searches seem to be affected. I hope I got everything for you.
     

    Attached Files:

  9. ryangn

    ryangn Private E-2

    AVG found a trojan today.

    Trojan horse Rootkit-Agent.Cl
    C:\WINDOWS\System32\wdmaud.sys

    My web searches are now showing correctly and the computer seems to be working just fine. I will await further instructions before I do anything else though.
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ryangn

    Do this: Temporarily bypass your router and connect your pc directly to the cable mode. * Power cycle your cable modem and re-boot the pc after making the connection change. Let me know if this makes any difference.

    Thanks!
     
  11. ryangn

    ryangn Private E-2

    I don't know if u seen my post about AVG finding and fixing a trojan

    Trojan horse Rootkit-Agent.Cl
    C:\WINDOWS\System32\wdmaud.sys

    Everything is working great since then and the web searches are fixed. Do u still want me to remove the router?
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *Glad to hear the good news. A search of your logs show that wdmaud.sys has been removed. Since you're no longer having problems, it is time to do our final steps:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds