also @ TechSpot: Weekend Open Forum: Google Chrome OS and the future of cloud computing
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Search engine results redirecting

Closed Thread
Page 1 of 2 1 2
Bookmark Thread Tools
  #1  
Old 10-26-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
Search engine results redirecting

hi,
all my browsers are running very slowly and all search engine results keep being redirected to often unrelated pages. from reading other posts here, i assumed there is some sort of virus on my machine, so i tried a few free antivirus scans but with no real results.
i would be very grateful if someone could tell me how i could rectify this problem?
cheers, r
  #2  
Old 10-26-2008
almcneil's Avatar
TechSpot Maniac
 
Location: Ottawa, CANADA
Member since: Jun 2007, 1,499 posts
Sound like a type of spyware falled "web browser hijacking".

Go to http://www.download.com and download/install/run the following 3 antispyware utilities:
  • AVG 8.0
  • Ad-Aware 2008
  • Spybot Search & Destroy

Repost with results.

Best,
-- Andy
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 10-26-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
cheers, ive run AVG 8.0 and Ad-Aware 2008, but spybot wouldnt install, so the problem is still here.any other ideas?
thanks again
  #4  
Old 10-27-2008
almcneil's Avatar
TechSpot Maniac
 
Location: Ottawa, CANADA
Member since: Jun 2007, 1,499 posts
Rats!!

Rats!! Of the 3 anti-spyware utilities I recommended, it's Spybot that is the best at removing hijackers. Try restarting in Safe Mode and see if Spybot will install there. If you can't, you're in a pickle.

Repost if you can't install Spybot in Safe Mode.

Best,
-- Andy
  #5  
Old 10-27-2008
Wendig0's Avatar
TechSpot Member
 
Location: Legian Beach
Member since: Oct 2008, 201 posts
System specs
While I am not the best at reading them, a lot of users here are very adept at reviewing "HijackThis" logs. Download HijackThis, run it, and post the results.

Though it may not be the most advanced remedy for this particular problem, I have had the same problem you describe in the past, and a system restore to a date before the problems began cured it while most malware/spyware removal tools could not. It might work for you as well, but I still recommend creating a HijackThis report first.
  #6  
Old 10-27-2008
BillAllen55's Avatar
TechSpot Member
 
Location: Central Oregon - Gods Country
Member since: May 2008, 221 posts
System specs
Please during your cleaning process review the excellent 8-step process from Tech-spot found here:
http://www.techspot.com/vb/topic58138.html
  #7  
Old 10-27-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
i tried to install spybot in safe mode but it still wouldnt work
  #8  
Old 10-27-2008
almcneil's Avatar
TechSpot Maniac
 
Location: Ottawa, CANADA
Member since: Jun 2007, 1,499 posts
Quote:
Originally Posted by ruari View Post
i tried to install spybot in safe mode but it still wouldnt work
Then proceed to HijackThis and post your logs.

Best,
-- Andy
  #9  
Old 10-27-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
ive however installed HJT so hopefully this will help...

the HJT log is as follows (i dont know if this helps) :
[COLOR="Red"]moderator edit: log removed. logs should be posted as attachments, not copied pasted.[/COLOR]

Last edited by momok; 10-29-2008 at 01:29 PM.. Reason: dont triple post!
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 10-27-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,885 posts
Quote:
ive however installed HJT so hopefully this will help...
We offer malware cleaning with instructions for disabling Real Time protection, updating Java if needed, running the malware programs and attaching the logs. You were given the URL by a member as:
http://www.techspot.com/vb/topic58138.html


The HijackThis program is run AFTER the other cleaning programs, not before. We then check the logs for additional removals.

Please read this: How to post your Hijackthis log-file as an ATTACHMENT
http://www.techspot.com/vb/topic19133.html

Additionally, a server with IP 85.255.112.113 is shown. This is in the Ripe Network. I cannot connect to their database at this time, but will try to ID the Netname later.

Edit: I was finally able to access the Ripe database: IP 85.255.116.214 is assigned as follows:
netname: UkrTeleGroup
descr: UkrTeleGroup Ltd.
Country Code UA>> Ukraine

IS this oYour ISP?

Last edited by Bobbye; 10-27-2008 at 10:36 PM.. Reason: Edit to add IP info.
  #11  
Old 10-28-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
attached are the requested logs:

cheers

p.s. im dont know about the ISP
Attached Files
File Type: txt mbam-log-2008-10-28 (21-59-16).txt (2.8 KB, 2 views)
File Type: log hijackthis.log (7.2 KB, 4 views)
File Type: log SUPERAntiSpyware Scan Log - 10-28-2008 - 12-26-21.log (1.9 KB, 2 views)

Last edited by momok; 10-29-2008 at 01:30 PM.. Reason: dont double post. use the EDIT button.
  #12  
Old 10-29-2008
BillAllen55's Avatar
TechSpot Member
 
Location: Central Oregon - Gods Country
Member since: May 2008, 221 posts
System specs
Follow this suggestion first:

Quote:
Originally Posted by BillAllen55 View Post
Please during your cleaning process review the excellent 8-step process from Tech-spot found here:
http://www.techspot.com/vb/topic58138.html
Once this has been accomplished it would then be helpful to the experts (myself NOT included) to then insert a copy of your hijackthis! log.
  #13  
Old 10-30-2008
momok's Avatar
TS Special Forces
 
Location: Singapore
Member since: Mar 2007, 2,269 posts
Please boot into safe mode.

Next, go to Start > run and type services.msc

Search for "Windows Tribute Service" and set the start up type to 'disabled' (right click properties).

Then run HijackThis and fix the following entries:
Quote:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [5FF.tmp] C:\Windows\temp\5FF.tmp
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C4052AC-4CD9-4E36-BF27-7602D2E57245}: NameServer = 85.255.112.113;85.255.112.73
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A2832AB-274F-425F-9C58-ABFFE9B13C80}: NameServer = 85.255.112.113;85.255.112.73
O17 - HKLM\System\CS1\Services\Tcpip\..\{2C4052AC-4CD9-4E36-BF27-7602D2E57245}: NameServer = 85.255.112.113;85.255.112.73
O17 - HKLM\System\CS2\Services\Tcpip\..\{2C4052AC-4CD9-4E36-BF27-7602D2E57245}: NameServer = 85.255.112.113;85.255.112.73
O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdtde.exe
Search for C:\Windows\system32\kdtde.exe and delete it.

Reboot into normal mode, then scan and save a fresh HijackThis log. Post it here in your next reply.
  #14  
Old 10-30-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,885 posts
Quote:
i tried to install spybot in safe mode but it still wouldnt work
I'm going to let momok continue with these logs. But I want to point something out. There is an AV program and 2 spyware/adware programs being recommended by one member, in place of the cleaning programs that are recommended by TechSpot. Those 3 programs DO NOT do they type of cleaning we usually need here for heavy malware infections. They are programs that should be can on a system on a regular basis, but NOT used for the cleaning.

Additionally, AVG has been beset by problems since v8 came out. It is NOT the recommended first choice for an AV program. Even AdAware has evolved to a less than satisfactory program over the years. I use or have used all three of these programs on 2 systems over a number of years.
  #15  
Old 10-30-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
ok cheers, will do it now

here is the requested new HJT log:

the attachment wouldn't show up so here it is:

[COLOR="Red"]moderator edit: log removed. logs should be posted as attachments, not copied pasted.[/COLOR]
[COLOR="DimGray"](2nd Notice)[/COLOR]
Attached Files
File Type: txt ruari-HJT-Log.txt (7.1 KB, 1 views)

Last edited by kimsland; 10-30-2008 at 07:48 PM.. Reason: Removed pasted log. Attached log. Posts merged
  #16  
Old 10-30-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,885 posts
Gosh it's tough to go through a log when it's pasted in! What happened that it wouldn't attach?

Anyway, hopefully momok can take you through this one:
Quote:
O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdetx.exe
Locate the following Files/Folders and delete them if they exist (if no location given, just do a search for them):
C:\Windows\system32\kdetx.exe
As you can see, it's still on the log. I see some have run ComboFix and still had it, then required script on Notepad and a regedit to get rid of it!

I'd have Hijackthis remove these though:
Quote:
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [5FF.tmp] C:\Windows\temp\5FF.tmp
O13 - Gopher Prefix:
Quote:
IF this is a special entry of yours, leave it:
O8 - Extra context menu item: E&xportálás a Microsoft Excel programba - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
And once more:
Quote:
Can you verify the IP here. As mentioned previously it belongs to:
Additionally, a server with IP 85.255.112.113 is shown. This is in the Ripe Network.
IP 85.255.116.214 is assigned as follows:
netname: UkrTeleGroup
descr: UkrTeleGroup Ltd.
Country Code UA>> Ukraine
IF the is your ISP or you company network, leave it alone. Can you identify it?
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C4052AC-4CD9-4E36-BF27-7602D2E57245}: NameServer = 85.255.112.113;85.255.112.73
  #17  
Old 10-30-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
im not sure, i just kept attaching it, and it kept saying it was already attached, but i couldnt see it!
im not sure how to find what my IP is?
cheers
  #18  
Old 10-31-2008
momok's Avatar
TS Special Forces
 
Location: Singapore
Member since: Mar 2007, 2,269 posts
Hi, I believe that is your old log as it states 27-10-2008.
Please run a new scan and save that log. Attach it here in your next reply. If you really can't then copy and paste. We'll (one of us mods) will help you attach it after that.
  #19  
Old 10-31-2008
Newcomer, in training
 
Member since: Oct 2008, 9 posts
it worked this time
Attached Files
File Type: log hijackthis.log (7.1 KB, 2 views)
  #20  
Old 11-03-2008
momok's Avatar
TS Special Forces
 
Location: Singapore
Member since: Mar 2007, 2,269 posts
You should fix these:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

I dont see other bad items. How's your system running now?
Closed Thread
Page 1 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
What's your favorite search engine? The Meeting Spot - Chat & Socialize 21 04-24-2007 02:59 AM
internet search returns search engines not results Virus & Malware removal 4 10-02-2006 07:47 PM
Search engine trouble! Software & Utilities in General 3 12-18-2004 06:36 AM
Business search engine News and Links from Around the Web 1 09-21-2003 02:44 PM
The Vivisimo search engine Windows OS 2 12-22-2002 03:37 AM


All times are GMT -4. The time now is 09:10 PM.