Search Engines getting hijacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by zelmo, Nov 16, 2005.

  1. zelmo

    zelmo Private E-2

    Hello and thanks for looking at this problem. Recently, a relative helped me get rid of Vundo/Win Fixer, using Hijackthis and Vundo Fix. It appears to have been part of a bundle, however, because its removal has not stopped IE from getting hijacked when I attempt to search on Google, or any other search engine. I get taken to "Morwill Search". Strange. Whatever it is, it has not infected Firefox as of yet(unlike Vundo/WinFixer). I am stumped.

    Here are my computers vital stats:
    Toshiba Satellite Laptop
    Windows XP/HE - Service Pack 2
    Pentiun 4- 3.06GHZ
    448 MB of RAM
    McAffe Antivrus always on


    I went to MG forums to search for similar issues. I have read the "Stickies" and done the following(with no fix yet, unfortunately):

    1.Downloaded:
    Ad Aware SE
    CCleaner
    CWshredder
    The Cleaner
    Windows Antivirus
    Spybot
    About Buster
    Spyware Blaster
    Stinger

    2.Disabled System Restore

    3. In Safe Mode - ran all the above programs, one at a time

    Result: This "Sticky" recommendation helped to clean LOTS of crap off of my computer unbelievable, actually), but found no Trojans or Viruses. Tricky sucker, whatever it is.

    So what should I try next?

    I have attached a log file of Hijackthis.
     

    Attached Files:

  2. zelmo

    zelmo Private E-2

    I've also run Kill2Me. Not infected with that.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're log still shows signs of the Vundo infection and also some other issues. We also need to get HijackThis installed and run properly. I will include steps for this below.

    Let's begin by running the steps in this link: Running Spy Sweeper..

    Make sure you attach the log from SpySweeper.


    Now make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a new log:

    Downloading, Installing, and Running HijackThis
     
  4. zelmo

    zelmo Private E-2

    I am at work right now and do not have access to my computer but I will follow your instructions and email you back with the log info.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It will take awhile for the Spy Sweeper scan to run. When finished make sure you attach its log and then also get HJT installed properly and attach a new log from it too.
     
  6. zelmo

    zelmo Private E-2

    Very impressive. Spy sweeper identified 3 items, as seen in the attached log. The problem seems to be gone. Thank you.
    I closed MSConfig and moved Hijack This from a temporary folder to a new one "HJT". New log is attached. Hope I did it right this time. Is there any need for additional fixes?
     

    Attached Files:

  7. zelmo

    zelmo Private E-2

    OOPS! Sorry, wrong HJT log attached. Here is the correct one, done this morning.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: Bho Class - {B69CA4E7-3E34-4837-89FC-7AB494253868} - C:\WINDOWS\system32\epfsjeqe.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O20 - Winlogon Notify: sstqr - C:\WINDOWS\system32\sstqr.dll (file missing)

    After clicking Fix, exit HJT.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Is there a reason you still have Symantec Security Center running when you have McAfee already running? I'm questioning the below service:
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    It would also be a good idea to consider purchasing and keeping SpySweeper and uninstalling MS Antispyware. Running both is pretty resource intensive. If you do not want to buy SpySweeper, uninstall it and keep MS Antispyware.
     
  9. zelmo

    zelmo Private E-2

    Thanks for keeping up to date with me. I followed your instructions and removed those six items and Symantec as well. I already paid for McAfee. Might as well use it. Not sure it's very effective, though. Also uninstalled MS Anti Spyware.
    Everything seems to be okay. I've attached the latest HJT log.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to purchase SpySweeper inorder to be able to keep it upto date and to have full functionality. What you downloaded is a 14 day trial.

    You did not get rid of the Symantec Service. The below line is still there. You cannot just fix services with HJT. Either the programs uninstall procedure must be used or other methods.

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    If there is no uninstall in Add/Remove programs, follow the below steps.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to SymWMI Service (or if not found look for SymWSC) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SymWMI Service

    If that does not work try entering the short name: SymWSC

    Now exit HJT and then reboot. After reboot check to see if the O23 line is gone.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds