View Single Post
Old 06-29-2009, 06:00 PM   #5 (permalink)
mas_pogi
Analyst, Security Team
 
mas_pogi's Avatar
 
Join Date: Apr 2008
Location: Tokyo, JP
Posts: 1,476
OS: Vista, Linux Mint


Re: Search Redirects

hi.

Quote:
Originally Posted by chckmgnte View Post
Hi Mark, thanks for the reply!
I've heard Eset Nod32 is pretty good and doesn't slow a system down (for gaming) which is key for me. Any recommendations for once we clear this up?
Yeah. ESET is good but we usually recommend Avira here because its free and lightweight. I'll let you install Avira. Though you can change it to ESET later on.

continue..

------------------------------------------------------------------------

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

----------------------------------------------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. You can find instructions HERE.

3. Open notepad and copy/paste the text in the quotebox below into it:

Quote:
http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/390018-search-redirects.html#post2214016

COLLECT::
c:\windows\system32\UACcajrusuqmyaedba.dll
c:\windows\system32\drivers\UACexwbapqjewqvrnd.sys
c:\windows\system32\UACyirlcwwspiltbtj.dll

DOMAINS::
Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
If you do not get a message box, please do the following:

There should be a file named [4]-Submit_date@time.zip with today's date, located here:

C:\QooBox\Quarantine\[4]-Submit_date@time.zip

Using the 'Browse' button, please submit it to this site ==> http://www.bleepingcomputer.com/subm....php?channel=4

Please let me know if you successfully submitted the file. Thanks.
------------------------------------------------------------------------

These indicate some settings have been changed

These are "Change the way Security Center Alerts Me" in Control Panel > Security Center.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

This means they are turned off. If that's your choice, that's fine, otherwise tick the boxes to turn the notifications back on.

-------------------------------------------------------------------------

Please uninstall the following. Using windows ADD/REMOVE program at the control panel.

Outdated java runtimes: (Older versions have vulnerabilities that malicious sites can use to exploit and infect your system)

J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 7
J2SE Runtime Environment 5.0 Update 9
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1


Your Java is out of date.

Java(TM) 6 Update 13 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now. An update should begin; follow the prompts.

--------------------------------------------------------------------------

Install this FREE AntiVirus program, update it, and run a full system scan.

Avira AntiVir Personal

When the scan is complete, click on the Report button. A log file will open. Save it to your desktop as Avira.txt. Please attach it in your next reply.

Do not install more than one antivirus program because they will conflict with each other. It is imperative that you update your antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch new malware that may have come out.
-------------------------------------------------------------------------
How's you computer now?




In your reply, please post

C:\combofix.txt
Avira result result <--attached
Answer to my questions


Mark
__________________
To accomplish great things, we must not only act, but also dream; not only plan, but also believe.
If I have been helping you and do not reply within 24 hours, please send me a message.
I'm a member of U.N.I.T.E and A.S.A.P
mas_pogi is online now