Solved Firefox Search Results redirection

Status
Not open for further replies.
checkup

Results of screen317's Security Check version 0.99.7
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java(TM) 6 Update 24
Out of date Java installed!
Adobe Flash Player 10.2.152.32
Adobe Reader 9.4.3
Out of date Adobe Reader installed!
Mozilla Firefox (x86 en-US..) Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
Microsoft Security Client Antimalware MsMpEng.exe
``````````End of Log````````````
 
Update Adobe Reader

You can download it from https://www.techspot.com/downloads/2083-adobe-reader-dc.html
After installing the latest Adobe Reader, uninstall all previous versions.
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or other garbage.
 
ESET results

C:\Documents and Settings\OWNER\My Documents\Downloads\media.player.codec.pack.v3.9.5.setup.exe Win32/Adware.Toolbar.Dealio application
C:\Documents and Settings\OWNER\My Documents\Downloads\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application
C:\Documents and Settings\OWNER\My Documents\Downloads\MsgPlusLive-484.exe a variant of Win32/MessengerPlus application
C:\Documents and Settings\OWNER\My Documents\Downloads\VideoConverter_Setup.exe a variant of Win32/SweetIM.A application
C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\e8oafg9s.default\extensions\{6f6ff0e4-8823-4bc8-b08c-3beea33f0e83}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Documents and Settings\OWNER\Application Data\Mozilla\Firefox\Profiles\8p3jaudc.default\extensions\{6f6ff0e4-8823-4bc8-b08c-3beea33f0e83}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
 
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\OWNER\My Documents\Downloads\media.player.codec.pack.v3.9.5.setup.exe 
    C:\Documents and Settings\OWNER\My Documents\Downloads\MsgPlusLive-483.exe 
    C:\Documents and Settings\OWNER\My Documents\Downloads\MsgPlusLive-484.exe 
    C:\Documents and Settings\OWNER\My Documents\Downloads\VideoConverter_Setup.exe
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

=====================================================================

Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. Run defrag at your convenience.

11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

12. Please, let me know, how your computer is doing.
 
All processes killed
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Documents and Settings\OWNER\My Documents\Downloads\media.player.codec.pack.v3.9.5.setup.exe moved successfully.
C:\Documents and Settings\OWNER\My Documents\Downloads\MsgPlusLive-483.exe moved successfully.
C:\Documents and Settings\OWNER\My Documents\Downloads\MsgPlusLive-484.exe moved successfully.
C:\Documents and Settings\OWNER\My Documents\Downloads\VideoConverter_Setup.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 3598 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: OWNER
->Temp folder emptied: 12429537 bytes
->Temporary Internet Files folder emptied: 47529 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 34711180 bytes
->Flash cache emptied: 996 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2993 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 45.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: OWNER
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 03272011_221716

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
 
something called
justched.exe
keeps popping up saying that its stopped wo rking and if id like to send an error report or something like that
it showed up too when i ran OTL
 
um secunia did its scanning thing and it gave me 7 insecure and 2 end of life programs and 95 patched ones
the end of life ones are
adobe AIR 1x
adobe shockwave player 10x
 
well thanks man really appreciate the help. if i gotta go right now
but if i hook up my ipod or a flash drive is there a possibility of reinfection
 
Yes.

Install this first....

Download, and run Flash Disinfector, and save it to your desktop (Windows Vista and Windows 7 users, scroll down)

*Please disable any AV / ScriptBlockers as they might detect Flash Disinfector to be malicious and block it. Hence, the failure in executing. You can enable them back after the cleaning process*

  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
  • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.

Windows Vista and Windows 7 users
Flash Disinfector is not compatible with the above Windows version.
Please, use Panda USB Vaccine

Now, you're safe to plug in anything and scan the device with your AV program.

Good luck!
 
CPU usage Spike

ive noticed on the task manager on thep erformeance and CPU usage section the percentage has been a lot higher than i usually see it becasuse wheni cleared my recent history it spiked to 100percent and when this thread was loading it was in the upper 90s
 
You install said program on your computer and it's good for any external device, you connect to the computer.
 
how do i check to see if the computer didnt get the virus or whatever the issue was when i plugged inthe ipod and flash drive
 
Open Windows Explorer.
Right click on a letter corresponding to a given device and you should see an option to scan it with MSE.
 
Status
Not open for further replies.
Back