windowsisearch

Discussion in 'Malware Help (A Specialist Will Reply)' started by jonathanmoss, Sep 29, 2008.

  1. jonathanmoss

    jonathanmoss Private E-2

    Hello,

    I have recently contracted what i assume to be some sort of melaware. It erased my search engine add-ons and whenever i type in a search quarry it takes me to www[dot]windowsisearch[dot]com. i have run the latest updates of melawarebytes, ad-aware and spybot and have indeed removed some stuff, but the problem persists. i have run hijack this, but i couldn't spot any reference to windowsisearch. I have seen sevral posting regarding windowsisearch lately and all mentioned spotting a windowsisearch mention in their hijack this log. any suggestions would be appriciated.

    Jonathan
     
    Last edited by a moderator: Sep 29, 2008
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Major Geeks!

    As malwre can hide in the most unexpected places, hijackthis may not locate it or its name has changed to something else that one of our malware experts may notice, so the below guide and logs may help.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:


    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. jonathanmoss

    jonathanmoss Private E-2

    Thanks. I am working on it and will get back to you as soon as i've completed all the procedures you listed
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just attach the requested logs whenever you finish.
     
  5. jonathanmoss

    jonathanmoss Private E-2

    Thank you. i will get on it tommorow. it's been a bit of a crazy week.
     
  6. jonathanmoss

    jonathanmoss Private E-2

    Hi,
    I attached the MGTools log beneath. I could not attach the SAS log or the Malwarebytes log, so i'm cutting and pasting them below. I apologize for this. I did not run combo fix. although SAS and malwarebytes seemed to have removed some infections. I still have the initial problem which is my firefox search bar has lost all of its search engines and whatever search term i put in, it takes me to winsisearch.com.
    Thanks for your help.

    Edit by bjgarrick: Inline logs attached!
     

    Attached Files:

    Last edited by a moderator: Oct 16, 2008
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why not? What problems did you have?

    You did not update MBAM and SAS to the current definitions. Please do so now and run new scans and then attach the new logs.

    Why not? You need to run this and attach the log and then you will have to re-run MGtools since it needs to be run after ComboFix has been run.
     
  8. jonathanmoss

    jonathanmoss Private E-2

    I am using the most current versions of all programs. I couldn't attach the logs because i couldn't find where they were being saved. They were definitely saved somewhere but i couldn't find it, so i simply cut and paste them. Is that a problem?
    As far as combo fix, i had some problems with mcafee recognizing it as an unwanted program and i read quite a few posts in which it was recommended not to use combofix anymore.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Having the current version of the program does not mean you have the current definitions/detections which is what I asked you to update to. You still need to do this.

    Yes. We do not want inline logs as explained in the READ & RUN ME. The instructions explain how to find the logs but here is where they would normally be saved on your PC:

    C:\Documents and Settings\Ruthie & Jonathan \Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs

    C:\Documents and Settings\Ruthie & Jonathan \Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

    These logs normally would show in MGlogs.zip but they do not. The problem could be due to the choice of user account names you chose. You have USERNAME=Ruthie & Jonathan Using user account names like this will cause many miscellaneous problems ( including problems for MGtools) as the & is a special character. You really should change your user account name and each user should also have their own user account.

    ComboFix is a valid program used in hundreds of forums thousands of time per day. You need to shut down McAfee as requested in the instructions and run the scan and then attach the log.
     
    Last edited: Oct 5, 2008
  10. jonathanmoss

    jonathanmoss Private E-2

    will do.
    thanks
     
  11. jonathanmoss

    jonathanmoss Private E-2

    o.k.

    I think i've done all that is required. I downloaded the latest versions of all the programs and updated their definitions. The three logs are attached. I appreciate your time and advice.
     

    Attached Files:

  12. jonathanmoss

    jonathanmoss Private E-2

    oops. I forgot to attach the combofix log. Here it is.
     

    Attached Files:

    • log.txt
      File size:
      11.2 KB
      Views:
      1
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install the below on Sep 30th?
    Code:
    "C:\Program Files\"
    1-CLIC~1      Sep 30 2008              "1-Click Answers"
    ANSWERS.COM   Sep 30 2008              "Answers.com"
    
    Try uninstalling them and see if it cure your problems. I'm not sure it will solve this problem but Answers.com is questionable software. You may have a new form of infection that is starting to crop up that shows no signs in any scanners yet. It may be infecting a particular registry key but we have no info on what. What we have seen is that other user accounts are usually fine or using a browser like Opera rather than IE or FireFox seems to work okay.


    Also uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 5

    There is no real malware in your logs.
     
    Last edited: Oct 12, 2008
  14. jonathanmoss

    jonathanmoss Private E-2

    I did install the Answers program (a great program by the way). I've been using it for a long time (although i reinstalled in recently). I don't think it is the problem.
    Strange no.
    The only evidence i still have of all this thing is that when i all the search engines have disapeared from my search bar, and whenever i enter some search word it takes me to: Windowsisearch.com.
    As long as that is the only thing it's not such a big deal. i just hope there is not something i'm missing here.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try a few more things. Make sure you shutdown all protection software before doing the below.



    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode


    Copy the bold text below to notepad. Save it as fixIE.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot your PC. After reboot is there any change?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds