Search engine problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by dundee, Nov 14, 2005.

  1. dundee

    dundee Private E-2

    Whenever I click on a search result in Google I end up with advertisements, other search pages, etc. MS Antispyware detected trojan.downloader and PWS-Pinch Password stealer, which it removed before they regenerated the next time I ran the antispyware. I've also used CCleaner and Ad-Aware SE, which come up clean, as have various virus scans. The inability to use Google continues, though.

    Any help would be much appreciated. I have attached the HJT log.

    Thanks in advance.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix the following:
    Boot to Safe Mode.

    Using the Search function in the Start Menu serach for dmcak.* DELETE every occurance.

    Reboot to Normal Mode and post a fresh HijackThis log.
     
  3. dundee

    dundee Private E-2

    Thanks for the reply.

    The IP address does not belong to my ISP and I fixed it.

    I ran the HJT scan, but no result turned up for
    O4 - HKLM\..\Run: [dmcak.exe] C:\WINDOWS\System32\dmcak.exe

    Searching in safe mode for dmcak.* did not throw up any results either.

    I have attached the latest HJT log. However, I noticed that this time around there is

    O4 - HKLM\..\Run: [dmwif.exe] C:\WINDOWS\System32\dmwif.exe

    Should I do the same for this? Thanks
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  5. dundee

    dundee Private E-2

    Thanks, Shadow. Attached is the ewido log.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    That found and removed some more of the Trojan.

    Run CCleaner before doing the below.

    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  7. dundee

    dundee Private E-2

    I downloaded and ran WinPFind. After a couple of minutes, it showed the message 'Invalid data type for system'...and seemed to stop the check after that (i let it run on for quite a while). I've attached the scan results as far as it progressed...hope it helps. Thanks,
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Open Windows Explorer, navigate C:\WINDOWS\SYSTEM32 to and delete this file SetupCarnival.exe.

    Post a Fresh HijackThis log.
     
  9. dundee

    dundee Private E-2

    Thanks, Shadow. I have removed the file. Here is the latest HJT log.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log is clean. How is your system running?
     
  11. dundee

    dundee Private E-2

    Its working great! No more redirections to other search pages, pop-ups...nothing. Thank you so much for helping me fix this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds