TheSearchMall-How do I remove it??

Discussion in 'Malware Help (A Specialist Will Reply)' started by HHdHeel, Jan 24, 2005.

  1. HHdHeel

    HHdHeel Private E-2

    I know you all have helped others with TheSearchMall hijacker so hope you can help me. Background: I have just run AdAware SE with VX2 Plug-in, Spybot S&D with DSO Exploit Fix, SpyBlaster (after infected), and HSRemove (after infected). No help. I have always run Spybot S&D and AdAware SE weekly, and have McAfee VirusScan running with automatic updates, and ZoneAlarm Pro firewall. I just ran HiJackThis today (in safe mode...is this OK?) and following is the log. Hopefully you can review it and tell me what I need to remove, and anything else I should do to clean up my computer. I am not knowledgeable enough to touch my registry or any other of the operating Windows files/systems without help. Thanks!

    Logfile of HijackThis v1.99.0
    Scan saved at 11:35:07 AM, on 1/24/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Unrequested inline log deleted.
     
    Last edited by a moderator: Jan 24, 2005
  2. jarcher

    jarcher I can't handle a title

    have you already gone through this sticky if not please do so. . .
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal:
    if you have double check everything and make sure you did do everything
    and all software is up to date

    if proven unsucessful run through this before attaching a log
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting:
    *Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis! Please do this!!!*

    you also need to make sure you close all running apps and close all windows(including this one) before running a HJT scan( all information is in the above links)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also in addition to what jarcher has given you:

    uninstall WeatherBug from Add/Remove programs in Control Panel

    And next time do not post HJT logs inline. They must be added as an attachment and should only be posted upon request.

    Also as jarcher noted, the below should not be running when using HJT.
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
     
  4. HHdHeel

    HHdHeel Private E-2

    Thanks chaslang.
    My first time on this site and was trying to give as much info in one post as I thought someone needed to help me. Will learn the rules. Thanks for the tips in running HJT, too.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem! My comments were meant to be educational!

    So now I hope you are working thru the steps of the READ ME that jarcher gave you!
     
  6. HHdHeel

    HHdHeel Private E-2

    Yes, have finally been able to work through all the steps in READ ME FIRST from jarcher, and have uninstalled WeatherBug. Here are steps and results from Read Me instruction:

    1) Disabled Sys Restore
    2) Skipped 2....no about:blank or home search hijack;
    3) done.
    4) Downloaded 10 tool software tools. Don't need about:Buster or HSRemove

    Scanning:
    1:b) In Safe Mode w/... ran on-line scans at Trend Micro, Symantec, and McAfee AVERT -- NO INFECTED FILES.
    2: Cleaned hard drive w/ CCleaner, cleaned out temp files.
    3: Ran Ad-Aware SE w/VX2 Cleaner and Spybot w/DSO Exploit + immunized -- NO SPYWARE FOUND. (I run both regularly and had just cleaned out some Spyware couple of days ago - no new ones)
    4: Ran CWSchreader (&FIX) and Kill2me. Nothing unusual.

    BOOTED TO NORMAL MODE:
    I downloaded and ran Hijack This and have a log saved if you wish to see it.

    ( I followed the instructions in the READ ME FIRST article in detail and found nothing that was infected. My computer is much cleaner I'm sure because I cleaned many fragments of old uninstalled programs, etc. I have always kept my temp files and cookies cleaned out but these softwares were more thorough.)

    Are there any other steps or programs to run now or what is your next suggestion? I see that there are 'thesearchmall' references all through the Hijack This log and probably much more that shouldn't be there that I can't recognize.

    I still need your help, please!! My IE is still being hijacked while I surf.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  8. HHdHeel

    HHdHeel Private E-2

    I used HiJackThis v 1.99 & ran a scan in normal boot, all applications and browser closed. Started the program from it's own folder in Program Files.

    Prior to this I ran all suggested steps outlined in READ ME FIRST...and results are explained in my previouis post.

    Attached is the log file from today's HJT scan as requested. Looking forward to your analysis of the scan and cleaning out the bad guys.
    Thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://thesearchmall.com/index.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://thesearchmall.com/index.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://thesearchmall.com/index.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://thesearchmall.com/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://thesearchmall.com/index.php
    R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    O2 - BHO: ohb - {0AEE4D0C-4B38-4196-AE32-70ACE5656647} - C:\WINDOWS\system32\winsrm32.dll
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O3 - Toolbar: TheSearchMall.com Bar - {4B8F38C7-62FC-4762-B9A0-27E63F768167} - C:\WINDOWS\system32\winsrm32.dll
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???\WkDetect.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {11111111-1111-1111-1111-111111111237} - http://69.50.170.125/1/deaGB176.exe
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb028.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\winsrm32.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. HHdHeel

    HHdHeel Private E-2

    Success!
    I finally got back home and tested my computer thoroughly for the hijacker after following your instructions. No sign of it any more. Your systematic procedure worked great. Thanks for all the help
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome, but you really should post the follow up HJT log request so we can be sure we got rid of everything.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds