Search hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by Beagle99, Aug 14, 2010.

  1. Beagle99

    Beagle99 Private E-2

    Hi,

    On 8-11-2010 when I tried to click on links from any search engine search result, it was redirected to another page, also it took about 55 to 65 seconds for the new web page to appear, the normal time on my network is 2 to 3 seconds. I have followed all the instructions in the Sticky READ & RUN ME FIRST. At the completion of all those processes my browser is no longer being redirected but the time for a web page to appear is still in the 60 second range. I have 2 other computers on the network that are not affected. I am afraid that the virus is still on my computer. Do you have any suggestions? I have attached all of the log files from the scans from SUPERAnti Spyware, Malwarebytes Anti-Malware, combofix.exe, RootRepeal and MGtools. I will attach the remaining fills in another post.

    I’m running XP Media Center Version 2002 Service Pack 3, all drives on the network are NTSF, there are 3 computers on the network plus a networked hard drive. This is the only computer I’m having a problem with.

    Thanks
     

    Attached Files:

  2. Beagle99

    Beagle99 Private E-2

    Here are some more log files.
     

    Attached Files:

  3. Beagle99

    Beagle99 Private E-2

    The remaining log files.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please just attach the entire C:\MGLogs.zip and also attach the log from running ComboFix.
     
  5. Beagle99

    Beagle99 Private E-2

    Thanks for the quick response. Is this what you need?
     

    Attached Files:

  6. Beagle99

    Beagle99 Private E-2

    The search hijack just returned.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are many forms of DNS poisoning that can occur. One that has been occurring more and more in recent months is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    After doing the above, see if you still have redirect issues.
     
  8. Beagle99

    Beagle99 Private E-2

    I had already done that and it had the same problem, I just did it again and no change. I've even connected the computer that I'm having a problem with directly to the modem and no change. Two of the three computers on my network have no problems, just one.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I also asked for the log from running ComboFix.
     
  10. Beagle99

    Beagle99 Private E-2

    Hi,

    There is a Combofix log in the zip file that I attached, is that not the one you wanted? I do not have any others.
     
  11. Beagle99

    Beagle99 Private E-2

    I just ran Combofix again. Here are the logs.
     

    Attached Files:

  12. Beagle99

    Beagle99 Private E-2

    As an option to cleaning the computer I'm considering formating the hard drive and reinstalling everything. I would like some advice before I do that. What is the risk that the virus is in the contacts folder of Outlook, in the data files or photos? The problem is that these files have been been backed up since the computer was infected and I do not know if it is safe to try to use them.

    Thanks
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I seriously doubt they are in your backed up files. You said you got redirected again after your last post with the new MGLog.zip. We may need a new one. What I would prefer you to do at this point is to uninstall IE as well as FireFox. Then run CCleaner and then re-install both.

    For Firefox:
    So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:

    C:\Documents and Settings\Diane\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?
     
  14. Beagle99

    Beagle99 Private E-2

    Thanks, I'll try this now.
     
  15. Beagle99

    Beagle99 Private E-2

    Everything is working normally. The only thing that I noticed was in C:\program Files\Internet Explorer is still there, I removed all of the files in that folder then emptied the recycle bin, several of the files refused to be deleted and kept coming back from the Recycle Bin to the Internet Explorer file. I don't know if this is normal or not. I attached that folder if you want to look at it.

    On another note thanks so much for the time you have devoted to solving my problem. From looking through the Major Geeks website there appears to be a tremendous demand for help. How do you keep from becoming burned out?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know that things are working now. ;)

    Burn out? Daily!! LOL.....but too many people are depending on us for assistance that we try to have a real life and still manage to find a little time to devote to the site.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the saying, "Shooting oneself in the foot" mean anything to you? ;) This is a required folder for Windows. You just deleted your Internet Explorer browser which means you will not be able to properly access Microsoft's websites to get various downloads and updates for Windows and other Microsoft programs. And in addition, many other software tools and websites require IE.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds