Search Engine Hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by sevans10598, Feb 4, 2009.

  1. sevans10598

    sevans10598 Private E-2

    Hi,
    Whenever I use a search engine, the first page comes up filled with suggestions that seem relevant by their headlines, but as soon as you look at the actual URLs/addresses, you see that they are the always same 8-10 bogus sites (such as ampkeywords.com, toseeka.com, etc). Doesn't matter what search terms and doesn't matter what search engine.

    Another issue (I don't know if it's related) is that part of my Mcafee Virus Scan keeps getting automatically turned off.

    I have run SpybotSD, Super Antispyware and Spyware Blaster, but none of these solved the problems. I also ran through the maintenance you suggested to do prior to getting into malware removal, including removing unnecessary programs and running SmartDefrag, CCleaner & Comodo Reg Cleaner. This all helped speed up the computer, for sure, but the basic problems still remain. One more thing: I wasn't sure what to do about updating Java. I looked in the control panel as suggested, but I didn't see a single thing that looked even remotely like the samples you gave (and I was able to identify everything there anyway). Should I go ahead and install the updated Java anyway?

    Any suggestions? Thanks in advance!!
     
    Last edited: Feb 4, 2009
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gifWelcome! to MajorGeeks.com!http://www.majorgeeks.com/images/grenade.gif

    Please follow the instructions in the READ & RUN ME FIRST link given further down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in Safe Mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is advised that after completing the READ & RUN ME you also read this sticky:
    4. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. sevans10598

    sevans10598 Private E-2

    Hello,
    I followed all the steps in your malware guide and my search engine problem is resolved! I'm 90% sure the hijacking of mcafee is fixed too. Thank you so much!

    I've attached the MGTOols and SuperAntiSpyware logs. Next two logs coming in next post.

    This is an amazing site. I will definitely use it again and I will tell friends about it. Thanks again.
     

    Attached Files:

  4. sevans10598

    sevans10598 Private E-2

    I've attached the Malwarebytes log, but i'm having a little trouble figuring out how to get to the Combofix one. Could you tell me what to do, or is there a sticky or post I could look at for advice? Thanks again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ComboFix log is right where the instructions say it will be. C:\combofix.txt
    All you need to enter into the Manage Attachments box is c:\combofix.txt and then click Upload.

    Also run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    I also suggest that you do the below to get a log from the current version of MGtools which could be helpful.

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the new C:\MGlogs.zip file:
     
  6. sevans10598

    sevans10598 Private E-2

    Here's the combofix file. Sorry I took so long (thought we were done). Thanks agin or your help and let me know if you need anything else.
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please attach the new log from MGTools.exe.
     
  8. sevans10598

    sevans10598 Private E-2

    Here's the new MGtools log.
    There's another issue w/my computer. I'm not sure if it's related. Over the past 1.5 weeks or so, getting on line and using links has gotten slower and slower. I have cable internet w/ wireless and it's taking a couple of minutes to hook up (used to take a few seconds). Sometimes freezes entirely and then takes forever to close out w/task manager. Sometimes does go faster if i close out w/task manager then and then start over. Is this issue appropriate for this thread, or should i start a new thread?
    Thanks.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds