View Single Post
Old 07-03-2009, 08:06 AM   #7 (permalink)
ndmmxiaomayi
Analyst, Security Team
 
ndmmxiaomayi's Avatar
 
Join Date: Jun 2006
Posts: 714
OS: immune system, circulatory system, central nervous system, muscular system, skeletal system, digesti


Re: Need help with virus redirecting google

Hi highergroove,

Everything looks much better now. There isn't much lurking now, but you have some programs installed which has questionable practices.

Please uninstall these programs:

Dealio Toolbar v4.0
Search Settings 1.2.1


After uninstalling these programs, please disable Spybot Teatimer temporarily.
  1. Right click the Spybot Icon in the system tray near the clock (looks like a blue/white calendar with a padlock symbol).
  2. Click once on Resident Protection, then right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  3. Go to Start > All Programs > Spybot - Search & Destroy > Spybot Search & Destroy.
  4. Click on Mode > Advanced Mode. When it prompts you, click Yes.
  5. On the left hand side, click on Tools.
  6. Check (tick) this box if it is not yet ticked: Resident.
  7. You will notice that Resident is now added under Tools. Click on Resident.
  8. Uncheck (untick) this box: Resident "TeaTimer" (Protection of over-all system settings) active.
  9. Exit Spybot Search & Destroy.
  10. Restart your computer for the changes to take effect.

Next, please open Notepad and copy and paste the following in the Code box into Notepad:

Code:
Folder::
c:\documents and settings\Owner\Application Data\Dealio
c:\documents and settings\Owner\Application Data\Search Settings
c:\program files\Search Settings
c:\program files\Dealio Toolbar

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SearchSettings"=-

DeQuarantine::
C:\Qoobox\Quarantine\D\Desktop.ini.vir
Click on File > Save As....

In the File Name field, copy and paste in CFScript.txt. Do not change the file name.

Click Save.

Referring to the picture below, drag CFScript into Combofix.



Combofix will start running. When done, a log will be produced. Please post this log in your next reply.

Do not mouse click on Combofix while it is running. That may cause it to stall.
__________________




Done your best? Really?
ndmmxiaomayi is offline