random search engines connect to internet

Discussion in 'Malware Help (A Specialist Will Reply)' started by jager, Jan 16, 2005.

  1. jager

    jager Private E-2

    When my computer is just sitting with nothing going on, the internet explorer will automatically connect to random search engines like lycos, yahoo, gigablast, hotbot, etc. what can i do to fix this annoying problem?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. jager

    jager Private E-2

    still having trouble, sorry, i tried all that stuff and it still screws up
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please finish following my directions!
     
  5. jager

    jager Private E-2

    someone please please analyze

    My computer automatically connects to the internet via my cable modem and internet explorer will pull up random search engines like yahoo, lycos, gigablast, hotbot, etc. I tried all the spyware searches in the READ ME links along with HSRemove and all the others. I believe it was HSRemove that found 8 items and it says that it deletes them, but when i repeat the search they appear again. Please help me so i dont have to reload windows. I attached my hijackthis report
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: someone please please analyze

    This is a good way to get delayed in getting help! You should have posted in your original thread. Not a new one! I'm moving you back there now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: someone please please analyze

    Please do not run HSremove anymore. You don't need it. I don't think you ever did. It is only for HSA hijacks.

    Please click Start, Run and enter msconfig and click OK! Then check the Normal Startup option. Then reboot and post a new HJT log. Right now you are blocking things from loading and I want to see what they are.

    Note: the below does not appear to be valid. What version of Ad-Aware SE do you have? And is it the free version or did you buy it?


    O21 - SSODL: Ad-Aware SE Personal - {8AC8465D-1AF3-1746-3018-F56F987A88F4} - C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Aware.dll
     
  8. jager

    jager Private E-2

    this is the free version of ad-aware SE, i downloaded it from lavasoft. here is the second hjt log
     

    Attached Files:

  9. jager

    jager Private E-2

    ad-aware personal 1.05
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O21 - SSODL: Ad-Aware SE Personal - {8AC8465D-1AF3-1746-3018-F56F987A88F4} - C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Aware.dll

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:

    C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Aware.dll

    This is more than likely the below full path name (but you will have to check):
    C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.dll

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. jager

    jager Private E-2

    I did like you said to run hjt with no browsers open and i fixed the two you said to, and as soon as i finished and exited hjt, the internet explorer connected to wisenut.com or something like that. Weird huh? then i booted to safe mode and i couldnt find windows explorer so i went into c drive and then into lavasoft and deleted the ad-aware.dll file there. here is my hjt log now
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you could not find Windows Explorer how did you delet the file? That's what you used.
    There are many ways to bring it up.
    - MyComputer
    - click Start, Explore
    - run it from Accessories.....etc

    The file is gone and so is the entry in HJT. How are you problems?
     
  13. jager

    jager Private E-2

    i will have to sit and wait without being connected to the internet to see if it automatically connects to some stupid random search engine, i will be back to let you know. By the way, what did i fix or delete with hjt
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You delete a DLL that has absolutely nothing to do with Ad-Aware from Lavasoft and looks to me like it is related to malware and popups according to what I found.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds