Search Engines Hijacked - Media players infected too?

Discussion in 'Malware Help (A Specialist Will Reply)' started by h2ogeek, Jun 9, 2009.

  1. h2ogeek

    h2ogeek Private E-2

    After reviewing common symptoms that I am experiencing, I think I have a malware issue. The problem began about a month ago when I noticed my search engines were being hijacked. I would get results from, for example, Google but when I clicked on a link, it would redirect me to an unrelated page.

    Initially, I thought it had been due to my antivirus software license lapsing. I tried to update it, but it would not allow me to (NOD32 Antivirus). I then uninstalled it and bought and downloaded McAfee. McAfee will not install either.

    I will admit, I had been downloading movies on Bit Torrent prior to the problem occurring. I was priming for a lot of traveling and wanted something to watch on the planes. I was new to it and would not doubt that I got this problem from there.

    More recently (yesterday), I plugged my Sansa E260 MP3 player in to sync with Rhapsody. Rhapsody did not recognize the player at all. The player screen indicated something to effect of "There is not enough space. Please free up 6MB before continuing". When I disconnected the player, all of my music was wiped clear. There are no files left on the Sansa.

    Earlier today, I tried running a system restore back to when I knew the problem did not exist. This did not help.

    I have performed all requested steps in the READ & RUN ME FIRST thread (although some were not possible)

    During the add/remove programs step, I did not find any programs on your list, but I did remove a couple of programs that I did not feel I needed (Adabas, DNA, xVID).

    System has been configured for normal startup.

    CCleaner installed and ran with no problems.

    I ran into some issues on step 3 (running Win XP SP3 by the way).
    I could download all programs except for Malwarebytes Anti Malware. Their page (malwarebytes.org) does not seem to be working with either FireFox or Explorer.

    I tried installing SuperAntispyware as requested, but I get an error message: "SuperAnitspyware has encountered a problem and needs to close. We are sorry for the inconveinence". It give me the typical windows "send error report, don't send" options.

    I did try to rename the executable SAS.exe as requested. Same error.

    Since I could not get SuperAntispyware to run or Malwarebytes AntiMalware to download, I was hesitant to continue with the combofix or MGTools (although they are downloaded and ready to go). I did not know if they needed to be run in order as in the instructions.

    Any advice on the next steps would be greatly appreciated.

    Thanks,
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need to see some logs.....otherwise we can't help. So do try to get combo to run and at least get us the MGLogs.zip.
     
  3. h2ogeek

    h2ogeek Private E-2

    Thanks for the reply.

    I just did a windows wipe and reload. Some of it was still there, but could be removed by autoeater.

    All is good now.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds