search hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by otisb, Apr 23, 2008.

  1. otisb

    otisb Private E-2

    has anyone run across the 'domainparkltd' search hijack? Hits IE and FF. HJT, Spybot, and AdAware all miss it.

    Any help greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. otisb

    otisb Private E-2

    SUPERAntiSpyware
    Spybot – Search & Destroy
    Malwarebytes Anti-Malware.
    none of these made any deletions.

    ComboFix. quarantined a catchme.log

    MGtools crashed on ProcessDll.exe failed to initialize properly.

    ???

    thanx
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the logs!




    Uninstall NetMeter 1.1.3 After uninstalling this some items below may not be found. Just ignore and continue.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. otisb

    otisb Private E-2

    all the fixes ran fine. but No Fix. that #$%^&* domainparkltd still grabs any misspelled search.

    Bollocks!!!!

    The Netmeter wasn't the problem. I loaded it from my jump drive. version that is on at least a dozen PCs.

    i really appreciate your help; but this is a real stumper, eh!

    Is it possible that ISP shoves this at me? TimeWarnerCable.

    Can I block the offending IPs in IE and FF?

    thanx

    I did a tracert to the bums, and the first step was a 10. private addy; but mine is a 192. series. Is this relevant?
     

    Attached Files:

    Last edited: Apr 26, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a recommended utility. See the below:
    http://www.castlecops.com/s2440-NetMeter.html
    http://www.bleepingcomputer.com/startups/NetMeter.exe-3644.html
    http://www.tasklist.org/task_NetMeter_exe_2221.html
    http://www.2-spyware.com/file-netmeter-exe.html


    Yes it could be that your ISP is mapping unknown searches there. You may want to check with them. You could also try flushing your DNS cache.

    Do you have your DNS settings configured to "Obtain DNS automatically" ?
     
  7. otisb

    otisb Private E-2

    I sure appreciate your time on this.

    I may stand corrected; but netMeter never cause dme probs on other sets.

    ISP disavows any knowledge.

    DNS is on Auto.

    is the 10. private IP in the tracert significant? since my actual is 192.....

    Also, I got in to my Router and turned ON the firewall. It was not done on Install. An SMC. and I changed the PW.

    this is making me nuts!

    good nite.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is probably part of your ISPs equipment, like a cable or DSL modem. The 192 addresses are on your side of the network only.

    Do you have any other PCs? If so, do they have the same issues?

    Try the below browser.

    Opera

    Do you see the same problem using Opera?


    Go to Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Do you still have the same results with all browsers?
     
  9. otisb

    otisb Private E-2

    Still no joy. I guess reformat!!

    But you guys are the bomb for all the help.

    thanx
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try Opera?

    Did you flush the DNS cache?

    You could try the below.

    Download Registry Search (see the link titled RegSearch Download Link)

    * Extract the files from Regsearch.zip into a folder.
    * Doubleclick regsearch.exe to start the program.
    * Enter domainparkltd in the top area of the form and then click "OK".
    * Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.
     
  11. otisb

    otisb Private E-2

    still no joy.

    DNS cache flushed. Brian flushed....
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Third time I'll ask this! Did you try Opera?

    If yes and it did not work, try the Software or Hardware Forum or format as you suggested if tired or trying. Your problems appear to be hardware or driver related.
     
  13. otisb

    otisb Private E-2

    may try Opera tomorrow. Wanted to exhaust all other options before risking hosing that up!

    cheers
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Good luck.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds