searchcore.net virus/malware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by starrekin61, Apr 3, 2012.

  1. starrekin61

    starrekin61 Private E-2

    Hello. I have run all the appropriate scans and followed all the directions in the "read this first" section. I have attached the log reports and an HiJack This log as well.
    The scans found and repaired the MY Web Search malware and removed that, but not the searchcore.net malware.

    The system is Windows 7, it is 64 bit.

    As of now, no anti-virus is installed.

    Any help you can give me, is much appreciated.

    I first used the RKill program which I downloaded from Malware Bytes, while in Safe Mode with Networking to remove it, but it didn't find it either.

    I also have a laptop with the Babylon Search malware - IE browser Hijacker that I am also fixing and will post the scans for that one shortly.

    Thank you for all your help, as this one is persistent!:cry
     

    Attached Files:

    • log.zip
      File size:
      306.2 KB
      Views:
      2
    • logs.txt
      File size:
      27.4 KB
      Views:
      2
  2. thisisu

    thisisu Malware Consultant

    Hello starrekin61,

    Your ComboFix log is incomplete, please retry attaching c:\ComboFix.txt

    __

    http://img825.imageshack.us/img825/2648/hjt.gif Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    1. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchcore.net/437
    2. O2 - BHO: (no name) - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~2\SITERA~1\SiteRank.dll
    3. O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (file missing)
    4. O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll (file missing)
    5. O2 - BHO: Updater For Simppull Toolbar - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - (no file)
    6. O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - (no file)
    7. O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll (file missing)
    8. O4 - HKLM\..\Run: [SiteRanker] "C:\Program Files (x86)\SiteRanker\SiteRankTray.exe"
    9. O4 - HKLM\..\Run: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.9\facemoodssrv.exe" /md I
    10. O4 - HKLM\..\Run: [BabylonToolbar] "C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarsrv.exe" /md I
    11. O4 - HKLM\..\Run: [Babylon Client] C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe -AutoStart
    12. O4 - HKCU\..\Run: [RebateInformer] C:\PROGRA~2\REBATE~1\REBATE~1.EXE /STARTUP
    13. O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~2\MYWEBS~1\bar\2.bin\F3SCRCTR.DLL,LES
    14. O4 - HKCU\..\Run: [Jenkat Arcade] C:\Users\Anna Boyden\AppData\Roaming\Jenkat\Jenkat Games Arcade\notifyapp.exe
    15. O4 - HKCU\..\Run: [CSmileys] "C:\PROGRA~2\Crawler\Smileys\CSmileysIM.exe"
    16. O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4


    __

    Delete these folders:
    • C:\Program Files (x86)\facemoods.com
    • C:\Program Files (x86)\BabylonToolbar

    __

    Let me know what problems remain after you have completed the above tasks.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds