Redirecting Yahoo Searches

Discussion in 'Malware Help (A Specialist Will Reply)' started by XKazeCloudX, Feb 19, 2006.

  1. XKazeCloudX

    XKazeCloudX Private First Class

    Hey, I have completed all the following steps with going to safe mode and running all the virus scanners. It came up with no virus at all, and ad-aware just deleted some cookies like always. When I click on links in searches on yahoo it goes to some other website mostly junk not related to porn, and will work every few times I click on it. My computer seems fine but I just hate having the feeling of something in it. I have included my logs...I am not a super good computer guy so I might have missed something...Please tell me what to do.
     

    Attached Files:

  2. XKazeCloudX

    XKazeCloudX Private First Class

    Help Please T_T
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    You need to follow ALL the steps in the READ & RUN ME. You have not done them please run them all and attach ALL requested logs.


    Part of your problem is a WareOut infection. After you complete ALL steps in the READ ME, we will be able to help you remove this.

    Is your version of CounterSpy a paid version?
     
    Last edited: Feb 19, 2006
  4. XKazeCloudX

    XKazeCloudX Private First Class

    Sir i would gladly try to do that for you. But not all the scans work...and also it takes EXTRODINARILY long for it to finish..the one you requested...i have no idea why...and im pretty sure i dont have the paid version to anything hahaha well...i will try and do ita again..
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does take along time to run! But the purpose is to remove all malware from your PC and to help prevent (as much as possible) future malware problems. It is a require procedure so that we can help you fix your problems.

    You should not use illegal software. It is of no use to you in the long run since you cannot get updates. If CounterSpy is not capable of fixing problems (i.e. it is the free trial version), you should uninstall it because it will not help you.
     
  6. XKazeCloudX

    XKazeCloudX Private First Class

    on the panda scan it keeps saying

    Not allowing the application's ActiveX control to be downloaded.

    Problems with the Internet connection.

    The error could be due to a download error or an installation error due to lack of hard disk space, privileges etc.,...

    and i dont know why..but heres the other scan log
     

    Attached Files:

  7. XKazeCloudX

    XKazeCloudX Private First Class

    it doesnt ask me to accept direct X download either
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you install HijackThis properly yet per the directions in step 7 of the READ & RUN ME? If not, please do so before continuing.

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://a.tribalfusion.com/p.media/VSNTJFJUIMYQRMXPSLGMKDQSTJKPPHLFCJSKMHEHGDYOTFMOOREQTKGRJOOEGQILMJMOKHCTHOOS/369876/pop.html
    O1 - Hosts: localhost 127.0.0.1
    O4 - HKLM\..\Run: [jbzqw.exe] C:\WINDOWS\system32\jbzqw.exe
    O4 - HKLM\..\Run: [dmonz.exe] C:\WINDOWS\system32\dmonz.exe
    O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3F627916-857B-4517-BF83-A16DDB9342D1}: NameServer = 85.255.116.103,85.255.112.185
    O17 - HKLM\System\CCS\Services\Tcpip\..\{88CB990C-9DD4-48ED-A5FF-C89D66D31DD3}: NameServer = 85.255.116.103,85.255.112.185
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B1C8BE85-A6F6-4350-84A0-093946090A77}: NameServer = 85.255.116.103,85.255.112.185
    O17 - HKLM\System\CS1\Services\Tcpip\..\{3F627916-857B-4517-BF83-A16DDB9342D1}: NameServer = 85.255.116.103,85.255.112.185
    O17 - HKLM\System\CS2\Services\Tcpip\..\{3F627916-857B-4517-BF83-A16DDB9342D1}: NameServer = 85.255.116.103,85.255.112.185


    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\WINDOWS\system32\jbzqw.exe
    C:\WINDOWS\system32\dmonz.exe
    C:\Program Files\UnSpyPC <--- delete the whole folder if found

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds