Search Engine results only list links to spyware/adware

Discussion in 'Malware Help (A Specialist Will Reply)' started by everpeak, Dec 27, 2008.

  1. everpeak

    everpeak Private E-2

    I just completed the Windows XP cleaning procedure (as much as I could; my system crashed when I ran SuperAntiSpyware and Malwarebytes Anti-Malware), and I'm still getting crazy results when I use any search engine. This only started over the past 2 days. I also am have trouble clicking on links (i click, but nothing happens). I tried to post the logs from the programs I just ran, but the attachment button doesn't allow me to click. Please help...:(
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please begin by clicking Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices
    • Scroll down to Non-plug and Play Drivers and click the plus icon to open those drivers.
    • Then search forTDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    • Also if TDSSserv.sys is found and you disable it, then reboot.
    • After reboot continue on with other cleaning instructions you may have been having problems running.
    Now try running the scans. If necessary, do them in safe mode.
     
  3. everpeak

    everpeak Private E-2

    Hi, TimW,
    Thank you for getting back to me.

    Unfortunately, when I tried to locate TDSSserv.sys under the Non-Plug and Play Drivers list, it wasn't there. Is there anything else I can try?

    Thanks in advance...

    everpeak
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now see if you can use the manage attachment button. We need to see what ever logs you can supply. If you still can not attach the logs, you can copy and paste them into your next few replies and I will attach them. :(
     
  5. everpeak

    everpeak Private E-2

    After running the ATF cleaner, I was able to attach 2 logs! I think I'm missing a 3rd log, but I'm not sure where it is on my computer.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    everpeak

    To get the Malwarebytes' Anti-Malware log:
    • Open the program
    • Click on the Logs tab
    • Single-click the most recent log and click Open
    • Copy & Paste that log into a new notepad.txt and Save that to your desktop as mbam-log-<insert date recreated here>

    The MGlogs.zip is normally saved to C:\MGlogs.zip

    Please attach these two logs in your next reply to this thread.

    Thanks!
    dr.m
     
  7. everpeak

    everpeak Private E-2

    I hope these are the correct logs!
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  9. everpeak

    everpeak Private E-2

    I hope this time I did it right!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You attached the instructions for SAS not the actual log. Plus the MGTools that you are using are way out of date --> where did you get it??

    Please go to the READ & RUN ME FIRST. Malware Removal Guide and ( after removing MGTools and the related folders) download and run the latest version.

    Make sure you are also using the latest versions of SAS and MBAM and that they are updated.
     
  11. everpeak

    everpeak Private E-2

    I believe I downloaded the MGTools the last time I had a problem (I think it was summer 08). When I go to delete the MGTools folders, a message pops up, telling me that deleting the files will affect the running of some programs. Do I just ignore this?
     
  12. everpeak

    everpeak Private E-2

    Sorry for all of my neediness...
    I've been trying to follow everything precisely as written, but when I went to type in msconfig, I received a message that "windows cannot find 'msconfig.'" Could this be something affecting my pc?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    You should have msconfig back.
     
  14. everpeak

    everpeak Private E-2

    I downloaded everything again and followed the READ AND RUN ME FIRST MALWARE GUIDE.

    My computer crashed while running SuperAntiSpyWare (as per the guide, I ran it a 2nd time, but it crashed again), and no log seems to have been created.

    I ran SpyBot, and it didn't find anything. The logs for MalwareBytes AntiMalware, Combofix, and MGtools are attached.

    Unfortunately, I'm still unable to use Google and other search engines properly(the only one that seems to work okay is AOL). Every time I put something in for a google, yahoo, or msn search, the descriptions that come up seem real enough (like a wikipedia entry) but the links under the descriptions are for things like: security-antivirus.com, freescan.antivirus.com, ave99.com, couponmountain.com, monstermarketplace.com, hotjobs.com, etc!
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ah....sneaky little devil.

    Use windows explorer to find and delete:
    c:\windows\system32\0E58Feq8.exe


    N
    ow tell me why the only other admin user is disabled:
    Code:
    Users on this computer:
    Is Admin? | Username
    ------------------
       Yes    | Administrator
              | Guest (Disabled)
              | HelpAssistant (Disabled)
       Yes    | Ms. Hsu (Disabled)
    
    Did you try running the scans on this accout?

    Do you have the same problem if you run in safe mode with networking?
     
  16. everpeak

    everpeak Private E-2

    I just deleted "c:\windows\system32\0E58Feq8.exe"

    As for the other admin account, I believe that was set up a few years ago, but then I tried to delete the account. When I try to see if it's still an option (looking under user accounts and then also when logging off and clicking on "switch user"), it's nowhere to be found---so...I wasn't able to run the cleaner programs on that account.

    I haven't tried running the computer on safe mode. I'm not sure I know how to do that without having had a blue screen of death, first.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Starting your computer in Safe mode

    Then you need to create a new account and not be using the Aministrator account for your normal computer usage.

    Tell me what happens if you attempt to start in safe mode.
     
  18. everpeak

    everpeak Private E-2

    If I'm not using the administrator account for normal usage, what happens to all of my documents currently on that account?
     
  19. everpeak

    everpeak Private E-2

    I'm running in safe mode, and created a new account. I'm using that account right now. The problem with the search engines still exists, though. At this point, should I run all of the programs that I did with my admin acccount?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browser are you using...and does it happen with a different browser?

    We will work on transferring your docs and files to the new account later.
     
  21. everpeak

    everpeak Private E-2

    I'm using IE7, and yes, it does the same thing with Firefox (pity!).
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot back into normal mode and lets try this:

    This procedure explains how to get to the BitDefender Online Scan sites and how to setup and perform an online scan. It also explains how to obtain a log so you can attach it to a message. You must use Internet Explorer to run this scan and make sure your Sun Java version it current. Get Sun Java here: Sun Java Runtime EnvironmentBefore installing the current version, you should uninstall all previous versions first!!!!

    ****NOTE**** DO NOT INSTALL Bitdefender's Antivirus program. Make sure you follow the directions below and run the ONLINE SCANNER only.


    To start the online scan go here: Bitdefender

    • Agree to the license and then select Scan.
      • DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.

    • Once Bitdefender completes the scan:
      • Click-on the Detected Problems tab. Then select Click here to export the scan report
      • When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt)
      • And then in the File name box enter bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html. If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us.

    • Post the bdscan.txt file as an ATTACHMENT. See: HOW TO: Attach Items To Your Post
    • If you run BitDefender Online scan and have previously run PandaActive scan, the below false detection may be seen in BitDefender:

      C:\WINDOWS\system32\ActiveScan\pskahk.dll
      Infected with: Generic.Malware.SIMDWYNVdprn.D9407F4E
     
  23. everpeak

    everpeak Private E-2

    Happy New Year!

    I'm afraid I don't have good news.

    I started Bitdefender just before going to sleep last night and awoke to a computer that was completely shut down. Unsure of what to next, I tried to run Bitdefender again. After about 2 hours, it gave me a BSOD.

    The confusing part is that while Bitdefender was running, it said that no problems were found. When I tried to run SuperAntiSpyware earlier, it said it detected 64 infections (due to adware, I believe)---however, I'm never able to find out what these exact problems are, b/c SAS also made my computer crash. Is this b/c they're looking for different things?

    Is there anything else I should be trying?

    Ugh! :confused
     
  24. everpeak

    everpeak Private E-2

    My computer crashed a couple more times today, but now the search engines aren't giving me links to anti-virus programs or coupon mountain!

    So, I guess my question now is what other measures should I put into place to make sure that all of the crashes my computer experienced haven't ruined my hard drive?

    Also, how do I transfer all of my documents from the admin account to the new user account I created yesterday?

    Thanks!
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Crashing will not physically harm your hard drive. You will need to tell me exactly what the BSOD referenced.

    Are you still having problems? Have you rebooted and gotten another BSOD?
     
  26. everpeak

    everpeak Private E-2

    I can't exactly remember what the BSOD referenced. It seemed, however, that my computer crashed every time I tried to run a scan (Symantec, SpyBot, BitDefender)---even though I'd previously been able to run these without problems.

    I'm not sure if I should have done this, but I was feeling really nervous about breaking my computer. So, I did a system restore to bring my computer back to a point before I started having problems. I hope that's okay...(the search engines are working properly!).
     
  27. everpeak

    everpeak Private E-2

    Okay, another BSOD...I was trying to run AVG, and it went for a good 2 hours before the crash (I think I'll stop with the scanning until I hear from you again!).

    This time, I wrote down what the BSOD said:

    "Driver_Irql_not_less_or_equal"
    "STOP 0X000000D1 (0X00000010, 0X0000002, 0X0000000, 0XF83360E4)"

    Also:
    "iastor.sys_Address F83360E4 base at 8327000, Datestamp 41c367a8"

    Any idea what this all means? :(
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me if this helps.
     
  29. everpeak

    everpeak Private E-2

    I tried to follow the directions in the link, but couldn't find everything that was referred to. Could this be b/c I don't have a Dell computer (mine's a Fujitsu tablet pc)?
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The item refers to an intel storage matrix.....can you do a system restore again to before this happened...then check your device manager for any X's, ! or ? marks.

    You may need to post in the software section as this is not malware.
     
  31. everpeak

    everpeak Private E-2

    I did another system restore to a date in Nov 08.
    I checked the device manager, and the only thing with a big red X was the "1394 Net Adapter." When I clicked on it, the message I got was "device is disabled (code 22)". Should I enable it?

    If you have any other thoughts, please let me know. I'll also post my problem in the software forum.

    Thanks for all of your patience!
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No..that is a firewire connection. Please do me a favor and since you have restored, download the tools from the Read and Run First and let me see those logs:
    SAS
    MBAM
    MGTools.exe --> MGLogs.zip
     
  33. everpeak

    everpeak Private E-2

    Do you mean the logs from the last time I followed the 'read and run me first' directions?
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The tools have been updated...so you will need to download them again from the Read and Run First.......I just want to make sure that your restore point is clean.
     
  35. everpeak

    everpeak Private E-2

    I just want to make sure I'm following all of your directions properly. This may be a stupid question, but just to clarify:

    You'd like me to follow the instructions from Read and Run First, and run all the scans again on the computer (after downloading the most updated versions)? And then send you the logs?
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes as there is a possibility that your restore points are infected. And yes download SAS, MBAM and MGTools.exe from the current Read and RUn First instructions as MGTools and SAS are both new versions since we started.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds