Search Here issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by wastedwords, Jan 6, 2013.

  1. wastedwords

    wastedwords Private E-2

    My wife managed to download this search here virus/malware/rootkit, whatever it is. It has placed an extra tab in Firefox and is trying to hijack her home page in Internet Explorer, I believe. Since she has an intranet page for work as the home page it can't change it, so it creates an object error that can't be bypassed. IE is completely unusable. I have run thru the read me first scanners. I am posting 5 of the attachments here. I sincerely appreciate any help offered here as she is desperate to be able to work tomorrow. TIA.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Susan Robison\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
    • O23 - Service: DefaultTabUpdate - Unknown owner - C:\Users\Susan Robison\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe

    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Susan Robison\AppData\Roaming\DefaultTab
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CD97D978-2B5D-4F76-BBD8-682A3C37173C}]]]
    
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.




    Run this and attach the results.

    Using ESET's Online Scanner


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. wastedwords

    wastedwords Private E-2

    Kestrel-- Thanks for responding.
    I have run all the scanners you asked for and attached the log files.
    I was unable to turn off the anti-virus as this is her company computer and they have denied me access there. Hope that since the scanners ran, this will not make them invalid.

    IE still hangs with the object error and two instances of IE Explorer in the task manager. Ending the process there continues to be the only way to exit IE.

    Extra tab still exists in Firefox.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall this if you see it ---> DefaultTab

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    SRV - (24x7HelpSvc) -- C:\Program Files (x86)\24x7Help\App24x7Svc.exe (PCRx.com, LLC)
    IE - HKCU\..\SearchScopes\{CD97D978-2B5D-4F76-BBD8-682A3C37173C}: "URL" = http://www.mysearchresults.com/search?&c=4203&t=11&q={searchTerms}
    FF - prefs.js..extensions.enabledAddons: addon@defaulttab.com:1.4.3
    O4 - HKLM..\Run: [24x7HELP] C:\Program Files (x86)\24x7Help\App24x7Help.exe (PCRx.com, LLC)
    [2009/01/02 14:50:06 | 001,511,424 | ---- | C] () -- C:\Program Files (x86)\CFPSH.exe
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    • Now rerun OTL again, just a scan and attach log.
    • Did you run the ESET scanner I asked you to run?
    • How are things running now?
     
  5. wastedwords

    wastedwords Private E-2

    Found DefaultTab, went to uninstall, said it already was, so deleted from program list .

    no change is the issue
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox (Except we will use Revo Uninstaller) and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    • Any better for Firefox?
    • What issues remain?
     
  7. wastedwords

    wastedwords Private E-2

    I'll try it when I get back,
    but I haven't been able to get IE to work.
    Object error, etc. I have to close it with the task manager.
    So not sure I will be able to get thru this.

    Firefox has the search here tab, but I can still use it.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just do the firefox uninstall and reinstall when you get back and let me know how it behaves then. I may or may not be able to help with Internet Explorer. I may refer you on to the software forum for that.
     
  9. wastedwords

    wastedwords Private E-2

    Did the firefox uninstall/reinstall. The two folders you asked me to remove were gone, must have been taken out by the uninstaller. Firefox is all good now. No longer has the extra tab.

    Internet Explorer continues to lock up with an Message from webpa...
    [object Error] The task manager shows two instances of IE Explorer and both must be ended to close the browser. Nothing has changed with that damn browser, (which BTW I would never use, but that's what they use to log into her intranet)

    I believe that the "search here" hijack is trying to take over the home page, but it is locked and won't let it, hence the object error.

    Thanks for all the help so far. Now if it was possible to uninstall IE, maybe...
     
  10. wastedwords

    wastedwords Private E-2

    I have moved the IE problem to the software forum. Thanks Kestrel
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds