Search Here Tab & Other Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by RE2LeonS, Nov 24, 2012.

  1. RE2LeonS

    RE2LeonS Private First Class

    Once again my brilliant family managed to plague the family computer with yet another virus. My one brother thinks he can get free games all the time while my mother thinks all these 'deals' she clicks and downloads are legitmate. I don't bother with the family computer since I have my own but they've all been on my case to fix it. I warned them if they ruin this computer one more time, I'm (and you kind people) done fixing it. I wonder if there's a way I can place Parental Controls on all their accounts so they need a password in order to download things?

    Anyway, getting to the point. There was a nasty virus on here that wouldn't go away after running Microsoft's Security program. It was stuck in the BIOS I believe, or that's what people have said when I did some research on it. I've done the "offline" scan with it, but it kept coming back. There is also this annoying "Search Here" tab which I then found out was another virus that wouldn't show up on scans or a threat in any of my scanners.

    I previously did a scan of all the programs in the "READ FIRST" thread on November 18th, but I wanted to provide newer logs first. Well that was my stupid mistake because once I deleted those logs and did a CCleaner run, it removed those logs. So now when I do new logs, some of the programs say the computer is fine. I'm sorry if this hinders you guys, it was a dumb blond moment on my end. I'll attach all the logs that I was given, but the logs that are missing are from the programs that didn't give me one because the computer was 'clean'. Thank you in advance, and if there is a way I can lock my intelligent family out from downloading things please let me know. This routine is getting old and I hate coming back and bothering you guys with it.

    Thank you again.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove potentially unwanted programs and malware remnants. Then rescan and attach the new log.
     
  3. RE2LeonS

    RE2LeonS Private First Class

    I ran it twice, and there are entries that won't delete
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below softwares:

    • PriceGong 2.6.7
    • Viewpoint Media Player



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2abe6413-81a3-46f1-8a79-22cea9517499&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2abe6413-81a3-46f1-8a79-22cea9517499&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2abe6413-81a3-46f1-8a79-22cea9517499&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2abe6413-81a3-46f1-8a79-22cea9517499&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
    • R3 - URLSearchHook: (no name) - {cdf97ee2-ded0-4369-835e-99dd08225fa5} - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.6.7\PriceGongIE.dll
    • O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - (no file)
    • O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
    • O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
    • O2 - BHO: HelloWorldBHO - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
    • O2 - BHO: (no name) - {CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
    • O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
    • O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
    • O3 - Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - (no file)
    • O23 - Service: WajamUpdater - Wajam - C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
    After clicking Fix exit HJT.



    Delete this folder if it shows:

    C:\ProgramData\Browser Manager


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Re run Hitman again and attach log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. RE2LeonS

    RE2LeonS Private First Class

    I threw a HijackThis log in there just in case.

    Thank you!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget that.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. RE2LeonS

    RE2LeonS Private First Class

    Whoops sorry, when I ran it and opened up my browser again it keeps asking me to choose a serch provider and it won't let me add a new one but only select that "search here" thing. I just closed it out and didn't say yes to it
     

    Attached Files:

    • JRT.txt
      File size:
      61.3 KB
      Views:
      5
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And the log from OTL??? :)
     
  9. RE2LeonS

    RE2LeonS Private First Class

    Oh holy crap on a stick! I'm so sorry, it's just been one of those weeks...or months...
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    IE - HKLM\..\SearchScopes\{A18DC704-6BAD-4A58-8E45-842A87CB5324}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
    IE - HKCU\..\SearchScopes\{0EFE26E5-9F27-4482-9F82-3AC966698C6D}: "URL" = http://www.mysearchresults.com/search?&c=2633&t=03&q={searchTerms}
    [2012/07/19 15:03:38 | 000,002,519 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C53FE659-316A-4F56-A194-A5BE491BE866} - No CLSID value found.
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    Explain how things are running. :)
     
  11. RE2LeonS

    RE2LeonS Private First Class

    Everything seems to be running better, that 'Search Here' thing is finally gone and I was successful in being able to download updates finally! Thank you so much, you guys/gals are some guardian angels when it comes to the actions of the people who have no clue what their doing online; my family!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad everything is okay again. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds