www.search-more.com hijack and popup problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hewwingman, Mar 29, 2005.

  1. Hewwingman

    Hewwingman Private E-2

    Could use a hand with this one...
    My browser has been hijacked to www.search-more.com, and I am being bothered by popups..no joy with adaware, spybot, AVG. Easyclean and ccleaner haven't helped either. I followed the advice on removal of spy and malware..but I just can't track this sucker down to kill it. Can anyone help me?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot tell from your message if you have run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal


    If you have then continue with below. If not run all steps in the above sticky first.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Hewwingman

    Hewwingman Private E-2

    Hi there, thanks for replying..
    Okay, I have completed all of the steps in the sticky thread, and have two items of spyware left onboard, it seems, detected by Microsoft Antispyware, which I ran as an afterthought. I let it treat them, but they reappeared after rebooting, I couldn't save it's diagnostic, so I copied it verbatim. This is what it said:

    Transponder.ABetterInternet.ceres
    C:\WINDOWS\ceres.dll

    iSearch.DesktopSearch(Spyware)
    C:\WINDOWS\system32\drivers\delprot.sys
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\security security
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Enum 0 Root\LEGACY_DELPROT\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Enum Count 1
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Enum NextInstance 1
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot Type 1
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot Start 1
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot Error Control 1
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot Imagepath\SystemRoot\System32\drivers\delprot.sys
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot DisplayName delprot

    Any ideas would be appreciated...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Please complete the second part of my previous message.

    Did you run MS Antispyware after booting in safe mode?
     
  5. Hewwingman

    Hewwingman Private E-2

    here it is, as requested. No, I didn't run the microsoft antispyware in safe mode, it was pretty much an afterthought. I'll give that a shot this evening, just in case it solves the problem
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\m?hta.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: (no name) - {54BDB60A-5C9F-2268-946A-5FA7104EC690} - (no file)
    O2 - BHO: (no name) - {A3230239-E6AC-9C01-A928-BEC9D7C76F95} - C:\WINDOWS\System32\dqokdy.dll
    O2 - BHO: (no name) - {d36ac614-f331-f31a-53ed-fdd682644311} - C:\WINDOWS\System32\tfclick.dll
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/07acd98fda86392f7802/netzip/RdxIE601.cab
    O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://207.234.185.217/ABoxInst.exe
    O16 - DPF: {00000000-0000-0000-0000-000020040000} - http://207.234.185.217/ABoxInst_int4.exe
    O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/gbn298.exe
    O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/gbn298.exe
    O21 - SSODL: Secuirity Systems - {B73F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\wsaln.dll
    O21 - SSODL: tfclick.dll - {d36ac614-f331-f31a-53ed-fdd682644311} - C:\WINDOWS\System32\tfclick.dll

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\dqokdy.dll
    C:\WINDOWS\System32\tfclick.dll
    C:\WINDOWS\System32\wsaln.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. Hewwingman

    Hewwingman Private E-2

    Okay, I ran through the steps as you put them to me, here is the log of HJT.. The one thing that didn't go quite as planned is that one of the dll's that you told me to remove wasn't there.. : C:\WINDOWS\System32\dqokdy.dll wasn't in that location.. I found and removed the other two though, as well as all the other steps.
    IE seems to be running much faster though, which seems promising..
     

    Attached Files:

  8. Hewwingman

    Hewwingman Private E-2

    A quick addition for you... I ran microsoft antispyware again, and it picked up the ceres spyware, and the isearch desktopsearch again. I ran the cleanup on it, and then rebooted in safe mode.. That time, the ceres had gone, but the isearch was still there, so I ran the cleanup in safe mode, then rebooted normally, and ran the check again, and it looks as though they have both gone... fingers crossed, but I think we may have solved it! :D If it pops up again, I will repost to let you know. Do you think it might be safe enough for me to reactivate system restore yet?
    Yours gratefully..
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try having HJT fix this line:

    O2 - BHO: (no name) - {d36ac614-f331-f31a-53ed-fdd682644311} - (no file)

    If it comes back, don't worry about it. We seem to see many of these removable BHO entries lately. But the file is gone so there should be not problems.

    After that yes you can enable system restore. Also make sure you complete all the steps in the below thread that have not yet been completed:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds