Searchmiracle

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shef, Oct 13, 2004.

  1. shef

    shef Private E-2

    Please help. Something calles Searchmiracle has invaded my computer. It
    has added a toolbar called ELITE TOOLBER to my toobars
    list, it has added links to my favorites list, is
    causing many annoying pop up ads, is denying access to
    one of the sites on my favorites list (it takes me to
    a searchmiracle site). I am also experiencing
    problems with my windows xp operations (I don't know
    if this is related). I have run many scans including
    many of the ones that you suggest but cannot get rid
    of this thing. I see some SEARCHMIRCLE items in my
    HJT log but haven't removed any of them on the advise
    of this site. Below is my hjt log.
    Suggestions?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start here:

    Please follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You other thread with the HJT log has been delete. Please do not make duplicate threads. And do not post HijackThis logs unless we ask for them.

    Read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  4. shef

    shef Private E-2

    sorry about the duplicate. I have solved some of my problems by finding and deleting a trogan named Startpage 12G. which was located in C:\WINDOWS\SYSTEM32\WINYRS32.EXE. Having deleted this file i am no longer gettng all the pop up ads, i was able to get rid of the ELITE TOOLBAR in my toolbars list and Windows seems to be operating better. However, I am still being denied access to one of the web sites in my favorites (it no longer takes me to searchmiracle.com though), and when i run my spyware detection program it continually finds a "possible browser hijacker....Internet Explorer Search Page...located in http:\Searchmiracle.com. even though i delete this it comes back in the next scan. Another spyware called Brilliant Digital...located in HKEY_local_Machine\Software\Altnet keeps comming backalso. I have run the your suggested programs with the exception of spybot and registry mechanic which require purchase of their products (something I'd rather not do unless absolutly necessary). I continue to see references to Searchmiracle and Elite Toolbar in my HJT log. Any suggestions? Thanks
     
  5. Kodo

    Kodo SNATCHSQUATCH

    spybot is free and does not require a purchase. Please download it and run the scan as suggested.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As Kodo said, SpyBot is free. You need to follow ALL the steps of the READ ME FIRST thread and in the order indicated. We did not even mention running Registry Mechanic. Please complete the tutorial as indicated and then tell us where everything stands and we will continue as necessary to resolve your problem.
     
  7. shef

    shef Private E-2

    ok, ran all the steps in "read me first" with the exception on Trend Micro which wouldn't let me download in the safe mode. Only problems remaining are: 1. the one website on my favorites is not available (note that that it did work for a short time after i deleted that winyrs.32.exe file and that i can access the site if i use my other ip-AOL-, hmmmm?, #2 i still have that Brilliant Digital spyware, #3 i still see some reference to SEARCHMIRACLE in my hjt log and don't know if i should worry about it,#4 windows is still acting up...sometimes won't access programs from the shortcuts or the file....don't know if this is a related problem
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The tutorial specificall tells you if you have a problem running the online scans in safe mode to run them in normal boot mode then return to safe mode for the other steps. Were you using Internet Explorer to do the online scans or a different browser?

    Post you HJT log as an attachment. Make sure you have follow the directions of the HJT tutorial and have version 1.98.2.
     
  9. shef

    shef Private E-2

    Yes I was using Internet Explorer for my online scans. HJT log attached.
    Thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try running them in normal boot mode?

    You must save the HJT log as a .txt file rather than a .log file so that you can upload it here. Your log is not attached most likely due to that problem. The tutorial indicates that you must save it this way.
     
  11. shef

    shef Private E-2

    Sorry, here is the log i hope.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I'm analyzing your log please do the following. We are going to need it.

    Download ProcessExplorer from:
    for WinNT/2K/XP - http://www.sysinternals.com/files/procexpnt.zip
    Unzip it and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
     
  14. shef

    shef Private E-2

    yes it is
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Make sure you have download and extracted ProcessExplorer per my previous message before continuing. We must use it to identify the correct file below. (Note: A similar function is available within HijackThis under Config, Misc Tools, Open Process Manager).

    Please bring up ProcessExplorer (or use HJT) and right click on them (one at a time) and select Kill process tree (or Kill process in HJT). MAKE SURE YOU SELECT THE ONE THAT MATCHES THE PATH GIVEN. explorer.exe is valid from c:\windows but not from C:\WINDOWS\system32
    C:\WINDOWS\system32\explorer.exe
    C:\WINDOWS\autoupdt.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [explorer] C:\WINDOWS\System32\explorer.exe
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v6.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\explorer.exe
    C:\WINDOWS\autoupdt.exe

    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  16. shef

    shef Private E-2

    ok, now what
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What?
     
  18. shef

    shef Private E-2

    posted "now what" thread just prior to post #15. Followed your instructions but am unable to locate C:\Windows\system32\explorer.exe. I find the entire system 32 folder (it's over 1gb) What should i do?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you enable viewing of hidden files? Check that it is still enabled.

    How did you look for the file? The enable of viewing of hidden files is for Windows Explorer not for Windows search function. Search requires advance options to be configured to find hidden & system files.

    Did you get ProcessExplorer, unzip, and configure as requested? Do you see C:\Windows\system32\explorer.exe running in ProcessExplorer?
     
  20. shef

    shef Private E-2

    hidden files is activated, looked for file using windows explorer and also used the Start>search function from the desktop. I do see Explorer Exe runnning from the C:\Windows\system32\explorer.exe path in the Process Explorer. (note: yesterday I had used HJT to kill that process
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But yesterday you said you cannot find C:\Windows\system32\explorer.exe. If it is running, it must be there. And it needs to be deleted. Normally you cannot delete a file if the process is running. So the process must be terminated first. But before retrying what I gave you yesterday again, please navigate to c:\windows\system32 and see if the explorer.exe file is actually there. If so, right click on it and get Properties info. Look for the Version tab and click it. The work you way thru the Item name s and see who this belongs too. Chances are you may not even see a version tab. That would be an indication that this is not a valid explorer.exe. Look at c:\windows\explorer.exe and you will see what a valid one should look like.

    To use search you must set other options:

    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter explorer.exe
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.
     
  22. shef

    shef Private E-2

    checked system32...don't see exe. used search method....i see an explorer.exe.ooo in a $ntservice pack uninstall file, and 2 in c:\windows\prefetch. no single explorer exe.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you look while ProcessExplorer was displaying c:\windows\system32\explorer.exe ?

    Please do the following, reboot your PC and immediately (before running anything else) get another HijackThis log and post it here. Immediately after that get another ProcessExplorer log and post it too.
     
  24. shef

    shef Private E-2

    ok, here is the data
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Both ProcessExplorer an HijackThis show the bad explorer.exe file:

    ProcessExplorer has:
    EXPLORER.EXE 1612 C:\WINDOWS\system32\explorer.exe
    HijackThis had:
    C:\WINDOWS\system32\explorer.exe

    Thus the C:\WINDOWS\system32\explorer.exe must exist and you need to find it and delete it.
    When you have it listed like this in both ProcessExplorer and HijackThis, run Windows Explorer (by clicking Start, Explore) and navigate to c:\windows\system32 and look for the explorer.exe file. You must make sure you have viewing of hidden files enabled first. Then once located. You must kill the process using ProcessExplorer and then delete the file using Windows Explorer.
     
  26. shef

    shef Private E-2

    chaslang I'm telling ya i have searched hi and low and cannot locate this file.
    I have hidden files enabled (i see the lightened files) and have used the search mode, i have also navigated to system 32, opened it and don't find explorer exe.

    I have also asked the wife to look ( she's more knowledgeable about computers) and she can't find it
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shef,

    This is really strange. The process did show in you last HJT log and ProcessExplorer. However it no longer shows a line in HJT where it is loading. (In message #15 we delete that line in HJT).

    Please download and install Advance Process Manipulation from:
    http://www.diamondcs.com.au/index.php?page=apm

    Then run it. Look in the process list. If things are still the same, you should see two explorer.exe processes running. One from c:\windows\explorer.exe and one from c:\windows\system32\explorer.exe. When located here is what I want you to do for each of them and give me the information found:

    Right click on the process and select 'Get Command line' tell me what it says in the popup window for both processes. All I need is the info after the "Commandline:" text
     
  28. shef

    shef Private E-2

    text was as follows:
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\explorer.exe-r
     
  29. shef

    shef Private E-2

    Hold on chazlang, just found the exe file. There were two items that were still checked under the file viewing options.......(hide extensions for known file types & hide protected operating system files).... after unchecking these i know see the explorer exe under system 32
    Sorry!!!!!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. But please be sure to follow directions properly from now on. That was one of the things that should have been done during the READ ME FIRST. Now you see why I kept insisting that it had to be there.

    Did you get the file deleted and did you fix the line in HijackThis?
     
  31. shef

    shef Private E-2

    i had fixed the file a while ago with HJT. Now, just to make sure i'm doing the right thing.....i kill the process...EXPLORER.EXE in path c:\windows\system32\explorer.exe in process explorer then delete explorer.exe in windows system32 via windows explorer?
     
  32. shef

    shef Private E-2

    i know you know what your doing but is it safe to delete this file?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know you fixed it before but it does not hurt to check to make sure it did not come back.

    Yes, kill the c:\windows\system32\explorer.exe process and then delete that file. It is safe to delete this file. It does not belong here. The file the Windows uses for its shell is c:\windows\explorer.exe. If you have a problem deleting this file after killing the process, repeat the steps after booting in safe mode.

    Anytime you are not sure about deleting a file you can always take the approach of renaming it to something that cannot execute. So you could rename the c:\windows\system32\explorer.exe file to something like c:\windows\system32\explorer.badexe (do not use c:\windows\system32\explorer.bad.exe that could still execute). Then after a few days your comfort level should increase to the point where you are sure you do not need the file and then you can delete it.
     
  34. shef

    shef Private E-2

    ok, changed the explorer name. windows seems to be working ok, still cannot access one of my sites on my favorites list but the hell with it....i can get to it using aol for some reason

    couple of other things....i keep getting this item when i run spybot....DOS Exploit. I keep fixing it but its back the next day. What is it and should i worry about it?

    also i am trying to remove norton antivirus and am unable to. i get error message 1606-could not access network location-%userprofile%\recent\. And then i get a message stating Fatal error during installation. any ideas?

    Thanks
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds