Search engine is hijacked?
#1
Posted 19 June 2011 - 02:32 PM
So far today it has taken me to travel web sites, something classed My Local Hero (local yellow page looking thing)
I don't know how to get rid of it.
Can anyone point me in the right direction? I read some other posts but they all seem very specific so I wanted to start from scratch. I am a little new to this - so I apologize ahead of time if I have questions.
Thanks for your help.
Colleen
#2
Posted 19 June 2011 - 08:54 PM
Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds file to run the tool.
- When done, DDS will open two (2) logs:
- DDS.txt
- Attach.txt
- Save both reports to your desktop. Post them back to your topic.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#3
Posted 20 June 2011 - 03:36 AM
"A problem has been detected and windows has been shut down to prevent damage to your computer [RQL_NOT_LESS_OR_EQUAL]"
There were more lines but there was also a technical code:
STOP: 0x0000000A (0x00461000, 0x0000001C, 0x00000000, 0x0806163CF)
I had disabled my "noscript" as mentioned but am not sure if maybe there is something else I need to disable.
Do you know if the blue screen is a result of something interfering with the DDS or if there is something really wrong? My husband thinks I might be safer letting a computer tech do this instead of doing this myself...should I be afraid?
Thanks
Colleen
#4
Posted 20 June 2011 - 05:55 AM
Are you able to use system in safe mode? If yes, please try to run DDS there.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#5
Posted 20 June 2011 - 07:01 PM
Please let me know if you need me to do something else to it in order for you to be able to use it.
Thanks for your help.
colleen
Attached Files
#6
Posted 20 June 2011 - 07:09 PM
Logs posted like expected
Next AVG has to be uninstalled so that it won't interfere with cleaning process. That can be done with Appremover. AVG can be reinstalled after we've finished the case (I'll let you know when).
When done, please visit this webpage for download links, and instructions for running ComboFix tool:
http://www.bleepingc...to-use-combofix
Please ensure you read this guide carefully first.
Please continue as follows:
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
Remember to re-enable them afterwards.
- Click Yes to allow ComboFix to continue scanning for malware.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New dds log.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#7
Posted 20 June 2011 - 07:16 PM
Thank you.
Colleen
#8
Posted 20 June 2011 - 07:18 PM
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#9
Posted 21 June 2011 - 04:34 AM
#10
Posted 21 June 2011 - 05:49 AM
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#11
Posted 25 June 2011 - 03:19 AM
If you need something else, let me know.
(there is another file called combofix quarantined files)
In the meantime - should ALL my blockers/firewalls be down?
Colleen
Attached Files
#12
Posted 25 June 2011 - 12:02 PM
Open notepad and copy/paste the text in the quotebox below into it:
DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:6092
uInternet Settings,ProxyOverride = <local>;*.local
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - No FileSave this as
CFScript
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
Uninstall old Adobe Reader versions and get the latest one (Adobe Reader 10.1) here or get Foxit Reader here. Make sure you don't (unless you want to) install toolbar if choose Foxit Reader! You may also check free readers introduced here.
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...
Updating Java:
- Download the latest version of Java Runtime Environment (JRE) 6 Update 26.
- Click the
Download
button to the right. - Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.
- The page will refresh.
- Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
- Close any programs you may have running - especially your web browser.
- Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
- Check any item with Java Runtime Environment (JRE or J2SE) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove each Java versions.
- Reboot your computer once all Java components are removed.
- Then from your desktop double-click on jre-6u26-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.
* Go here to run an online scanner from ESET.
- Note: You will need to use Internet explorer for this scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the activex control to install
- Click Start
- Make sure that the option Remove found threats is UNchecked.
- Click Scan
- Wait for the scan to finish.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#13
Posted 25 June 2011 - 01:47 PM
If you need me to go back and do that over again with the updated version, let me know.
Off to do the other items on your list - and will post the next dds when that has been completed.
Colleen
Attached Files
#14
Posted 25 June 2011 - 03:41 PM
Here is the other log in the meantime. The combofix is in the above post.
Sorry...
Attached Files
#15
Posted 25 June 2011 - 05:43 PM
Did ESET window have any details about found items visible?
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#16
Posted 25 June 2011 - 08:35 PM
Do you want me to rerun and write them down if I can't find a way to generate a log?
Colleen
#17
Posted 25 June 2011 - 09:31 PM
Please see if C:\Program Files\EsetOnlineScanner\log.txt file exists. If not then run the scanner again.
EDIT: Check also c:\program files\ESET contents for log file.
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#18
Posted 25 June 2011 - 09:56 PM
Thanks
Colleen
Attached Files
#19
Posted 26 June 2011 - 09:37 AM
Delete these files:
C:\Documents and Settings\Joe\My Documents\My Music\Incomplete\Preview-T-3209657-loving pi.mp3
C:\Documents and Settings\Joe\My Documents\My Music\Incomplete\Preview-T-4224012-loving pi HIT TOP50.mp3
C:\Documents and Settings\Joe\My Documents\My Music\LIMEWIRE downloads\loving pi.mp3
How's the system running now?
ASAP & UNITE member since 2006
I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.
Provided removal instructions are meant to be used in the correspondent user's case only.
Please use "Reply to this topic" -button while replying.
#20
Posted 26 June 2011 - 12:43 PM
I added them to the recycle bin and emptied it.
Thank you again for all your help...will await you next instructions.
Thanks!
Colleen
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users


This topic is locked









