Yes, I am still having problems with YOOG Search (Malware)

Discussion in 'Malware Help (A Specialist Will Reply)' started by geekfollower_83, Jan 3, 2009.

  1. geekfollower_83

    geekfollower_83 Private E-2

    Hello All,

    Happy new year 2009 !

    Well, I recently noticed a YOOG Search being active instead of Google search engine in Mozilla(the extreme right default search bar)..I changed it to google, but it never is changed, it sets back to YOOG Search :-(

    I landed on thread, Malware Removal Guide and I hope I did as was said in the guide.. Everything went fine and please find attached with Logs.

    Sad to say, but even after running all the suggested softwares, YOOG Search still sits in the same place, What type of Malware ,even MBAM couldnt remove ?

    Any help is highly appreciated.

    Thanks with Regard,
    Abhi
     

    Attached Files:

  2. geekfollower_83

    geekfollower_83 Private E-2

    and the last log file
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks

    Please be patient while I look over your logs and prepare a fix for you.

    Thanks!
    dr.m
     
  4. geekfollower_83

    geekfollower_83 Private E-2

    Hi Dr. M,

    Thanks, I will be waiting your Solution.

    Regrds,
    Geekfollower
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, geekfollower 83

    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Do you know what the below file is?
    C:\BOXSTER.BIN

    Step 1:
    How To - Remove Yoog Search
    • Re-boot your pc into Safe Mode
      Starting your computer in Safe mode
    • Navigate to - C:\Documents and Settings\Useraccount(where Useraccount is your user name)\Application Data\Mozilla\Firefox\Profiles\( your profile name.)xypw77w4.default\searchplugins
    • Delete Yoog
    • Run CCleaner
    • Re-boot into Normal Startup Mode

    Step 2:
    Download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 3:
    Run Ccleaner

    Step 4:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).
    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\avenger.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    Thanks!
    dr.m
     
  6. geekfollower_83

    geekfollower_83 Private E-2

    Hi, dr.moriarty,

    Thanks for excellent step by step procedure.

    I am not sure, but i suspect,it came from the FolderBox1.20 software
    or bxNewFolder software.

    Yoog Search, does not appear any more in searchbar :)

    All of the procedure ran exactly as you described it in your reply.

    Could you please tell me a most probable reason , how did it come so that i can avoid it in future ? What else did it affect on my computer ?

    For the moment, yoog is no more and computer works fine..will update if anything comes up.

    Could you please advise a Free Firewall which doesnt conflict with

    1)Avast free home edition ,
    2)Spybot
    3)Super Antispyware
    4)Malware bytes, Antimalware

    Thanks for your reply and solution

    Regards,
    geekfollower






     
  7. geekfollower_83

    geekfollower_83 Private E-2

    Whoops !! I forgot the logs in my previous reply..here they are

    Geekfollower
     

    Attached Files:

  8. geekfollower_83

    geekfollower_83 Private E-2

    Hi again,

    The yoog search toolbar appears in Internet explorer..how do i remove this ?
    kindly guide ..I noticed it just now..

    Thanks
    geekfollower
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :major

    geekfollower_83

    That's something that we have seeing this lately.

    Please run the IE7 part this Yoog Removal and then report back on any problems you had following these instructions and also tell me how things are working now.

    I should finish reviewing your logs and posting to them later today, and also answering your questions.

    dr.m
     
    Last edited by a moderator: Jan 13, 2009
  10. geekfollower_83

    geekfollower_83 Private E-2

    Hi dr. majority,

    Thanks again for the updated link. I again followed it to make sure, yoog is being completed removed off.
    The first reply was a better though which actually worked for me , Avenger :)

    Well, I navigated to Keyword.URL in mozilla and reset it, although there was
    Yoog appearing but i never saw a yoog in my search engine bar ..donno why

    Re IE ,

    I openend up Internet explorer, clicked on search engine drop down--> Change Search Defaults and simply removed Yoog and it worked..
    I restarted, I dont see any more Yoog appearing on my Internet Explorer

    Following your steps, I couldnt find globaladsolution and globaladsolution browser enhancer , so didnt think much about it

    Could it be the case that its Hidden somewhere?

    Could you please reply with regards to my precious post ?

    Thanks

    Cheers,
    geekfollower
     
  11. geekfollower_83

    geekfollower_83 Private E-2

    Hi dr.m,

    was awaiting your reply.. pls revert , thanks

    Cheers,
    geekfollower
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, geekfollower

    We'll leave C:\BOXSTER.BIN.

    * Navigate to and delete this file - C:\WINDOWS\qfe109.tmp

    Now run CCleaner
    .

    Important observation:
    ------------------------------------------------------------------
    If you are not having any other malware problems, it is time to do our final steps:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds