Avast is not picking up on a virus or Trojan on my computer, when I use any type of search engine their results pop up ok… but then when I click on ANY of the results on their search list the page is redirected to eBay or another search engine etc…sometimes just oddball pages. Anyone heard of this and is their a fix???
Disable System Restore on Windows ME or Windows XP. System Restore cannot be disabled on Windows 9x and it’s not available in Windows 2k. After boot you can enable System Restore again after step 3).
Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot. Other option is scanning in SafeMode (repeatedly press F8 while booting).
It will be good if you download, install, update and run AVG Antispyware. Some users recommend SUPERantispyware, Spyware Terminator and/or a-squared (take care about false positives).
If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
Also, if you still detecting strange behaviors or you want to be sure you’re clean, maybe making a HijackThis log to post here and, specially, scan and submit to on-line analysis the RunScanner log would help to identify the problem and the solution.
After you’re clean, use the immunization of SpywareBlaster or, which is better, the Windows Advanced Care features of spyware/adware cleaning and removal.
Finally, when you’re clean, check for insecure applications with Secunia Software Inspector to update insecure applications and avoid reinfection.
Sounds more like browser hijack or possibly a HOSTS file redirect and not a virus or trojan.
Try the anti-spyware tools Tech mentions and check the C:\Windows\HOSTS file using notepad or other text editor, there may be entries for the search engine domains.
If that doesn’t resolve it HiJackThis in Tech’s step 6.
Hello again… Still having same problems, so here is my HijackThis log:
Thanks for looking.
-Don
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:21:03 AM, on 7/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal
Other than the O17 entries I don’t see anything obvious and this usually is associated with your ISP (85.255.112.167 and 85.255.113.106 = inhoster.com), is that associated with your ISP ?
Its actually the IPs in the lines rather the the CLSIDs.
I would have a look at the FixWareOut log and, assuming there are positive detections and fixes made, then fix all the 017’s in HJT and get a fresh HJT log.
I wish you’ve posted this before… I have just a nightmare trying to clean infections like this one in a computer of a friend of mine. Living and learning: O17 entries and Wareout infection.
Not all 017’s are bad - check the IPs for 85.255… (its an indication, not a guarantee, of infection).
FixWareOut will show detections in the log if any are found and ComboFix is also effective against this now. After fixing the lines in HJT you need a fresh log to see if any 04 lines have unusual entries because there is a version that will try to rename itself on reboot and re-establish the infection. Some are rooted, too.
BTW, this is not the initial indication I saw but a probable confirmation: The IPs are in the Ukraine while dleske’s profile shows he is in Washington state.
Below is the Log File from using the fixware program. I hope it helps.
…do I need to fix the 017’s and get a fresh HJT Log? If so please instruct. SO FAR the fix seems to have worked I think…, since I have done a search and it no longer “re-directes” me to a bogus page.
Do I need to delete the fixware program or any of the other reg/fix programs, once used?
Your assistance is invaluable, let me know if there is any way I can show my appreciation ok.
Thanks,
-Don
####################################################################
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“MSMSGS”=“"C:\Program Files\Messenger\msmsgs.exe" /background”
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe”
…
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
Did you run the fix like it should, just like it is explained with pictures there on the bleeping.computer page? Just run it - load the findings, then push the fix button and then reboot… Did you read all the instructions?
You can show your appreciation to come and visit this site and maybe later help others, we’re all volunteers here, some with somewhat more experience then others, but we stand on each other’s shoulders, and that is making us TALL.
1 & 2. it looks like it confirms the O17 entries were suspect and should be fixed, though the fixwareout tool would appear to have changed the values in the registry, running HJT again should confirm this.
All of those helping you on this are avast users (just like you) volunteering their time to help other avast users.