Something Changing Address Bar Seach to Yahoo! in Firefox

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sevenismagic, Jan 17, 2012.

  1. sevenismagic

    sevenismagic Private First Class

    A program began changing the default search engine for Firefox to Yahoo! instead of my preferred, Google.

    I completed all steps in the malware readme run me first sticky, and they are attached.

    It did fix the problem of changing the search bar default every time I restart Firefox, but it continues to change the address bar search function to Yahoo!

    I entered "about:config" in Firefox and changed all search defaults back to Google, but something is still changing it back each time I restart the browser.

    Thank you, Geeks!~!!
    7
     
  2. sevenismagic

    sevenismagic Private First Class

    Woops.

    Here are the files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did it to youself when you downloaded and installed YouTube Downloader Toolbar v4.9

    Uninstall it and see if it goes away.
     
  4. sevenismagic

    sevenismagic Private First Class

    I uninstalled the toolbar. Still Yahoo! changing. I'm going to uninstall and re-install Firefox now.

    Ok. Now the URL bar doesn't search anymore. I can deal with it, but it would be nice to fix it.
     
    Last edited: Jan 18, 2012
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's use ComboFix to cleanup a few things
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. sevenismagic

    sevenismagic Private First Class

    EDIT Forgot to restart. Was going to panic.
     
    Last edited: Jan 19, 2012
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still waiting for the logs. ;) And also for a response to how things are working.
     
  8. sevenismagic

    sevenismagic Private First Class

    FF won't open. I attached the ComboFix log, MGtools log...I just ran MGtools now. There's a FireFox crash report too.

    Uninstalling and re-installing FireFox doesn't work.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably not a malware problem. But try the below.
    • Uninstall Firefox but DO NOT reinstall it yet. Wait until I tell you to do so. ( It may be necessary to remove Thunderbird too since it use overlapping folders. In fact, it would be best if you did this since the below fix may break it anyway. And if you want to fix this crashing of Firefox, all of Mozilla likely needs to be removed. Use IE in the meantime.
    • Run the below fix.
    First you must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    You other alternative to disabling Teatimer is to uninstall Spybot.

    The below are still installed based on your logs. Uninstall them now:
    • YouTube Downloader 3.4
    • YouTube Downloader Toolbar v4.9
    Now download The Avenger by Swandog46, and save it to your Desktop.
    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. sevenismagic

    sevenismagic Private First Class

    Firefox would not uninstall this time...or at least it is still in the programs list. Spybot would not uninstall either. I did disable TeaTimer. Spybot gave an error upon trying to uninstall, but Firefox just did nothing.

    Should I continue even though Firefox still shows?

    FOP - I uninstalled a bunch of other things including the YouTube Downloader and Toolbar.
     
    Last edited: Jan 26, 2012
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No.

    Try uninstalling all of those in sage mode. If that does not work, see if you can uninstall with the below:

    Revo Uninstaller
     
  12. sevenismagic

    sevenismagic Private First Class

    OK.

    I uninstalled Firefox & Spybot successfully with Revo.

    I ran Avenger, but it gave me no log. I looked in C: and did a search. I will attach the MGTools log. Hopefully that might say what happened with Avenger...?

    Thank you!
    7
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Try again. It did not run properly at all. Try right clicking it and select Run As Administrator.

    Only attach a new MGlogs.zip if Avenger runs properly ( which means it reboots your PC after running the fix and it creates a log )..
     
  14. sevenismagic

    sevenismagic Private First Class

    No good. I see a flash of a cmd prompt window upon restart...then nothing.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's try using ComboFix.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. sevenismagic

    sevenismagic Private First Class

    ComboFix ran.
    MGTools too.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. sevenismagic

    sevenismagic Private First Class

    Things are working nicely now. I still have not re-installed FireFox though. I'm sure I'm just as fast...if not faster than I was when I unboxed the machine. :major

    Here are CF & MG logs.

    Thanks, Chaslang!!!!!!!!!

    7
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Now that we have remove the infected files, the hidden drivers for them showed up and we need to run another fix to remove them.



    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds