how to fix google redirects to mywebsearch

May 31, 2009 at 14:04:13
Specs: Windows XP

#1
May 31, 2009 at 14:08:25
 Also, when trying to click on a hiperlink it redirects me to http://homesearchtulsa.com/

#2
May 31, 2009 at 14:11:36
 Hi,Can you please post your AVZ log:Note: Run AVZ in windows normal mode. If avz.exe doesn't start, then try to rename the file avz.exe to something else and try to run it again.Make sure your web browser is open in background before making the log.1) To create the logfile, download AVZ by clicking HERE. Please save this file to your desktop or "My Documents" folder.2) Next, unpack the file to a new folder using the Compressed (zipped) folders wizard built into Windows XP/Vista, or a zip utility of your choice.3) Once you have unpacked the contents of the zip archive, please launch the file AVZ.exe by double clicking on it or right clicking and selecting Open.Note: If you are running Windows vista launch AVZ.exe by right clicking and selecting Run as Administrator.You should now see the main window of the AVZ utility. Please navigate to File->Custom Scripts. Copy the script below by using the keyboard shortcut CTRL+C or the corresponding option via right click.begin ExecuteStdScr(3); RebootWindows(true); end. Paste the script into the execution window by using CTRL+V keyboard shortcut, or the "paste" option via the right click menu. Click on Run to run the script, the PC will reboot. After the reboot the LOG subfolder is created in the folder with AVZ, with a file called virusinfo_syscure.zip inside. Upload that file to rapidshare.com and paste the link here.Image Tutorial-------------------------------------------------

#3
June 1, 2009 at 21:51:45

#4
June 1, 2009 at 22:12:08
 Follow these Steps in order numbered. Don't proceed to next step unless you have sucessfully completed previous step:1) Run this script in AVZ like before, your computer will reboot:begin SetAVZGuardStatus(True); SearchRootkit(true, true); DelBHO('{39fc2065-c9c7-49cd-8942-44cc2dedc844}'); DelBHO('{2267F93C-600C-420E-A229-3317AADD3951}'); QuarantineFile('C:\WINDOWS\system32\sysloc\sysloc.dll',''); QuarantineFile('C:\WINDOWS\ieocx.dll',''); QuarantineFile('C:\windows\ld08.exe',''); QuarantineFile('C:\Documents and Settings\Mary\Start Menu\Programs\Startup\ChkDisk.dll',''); QuarantineFile('C:\DOCUME~1\NETWOR~1\protect.dll',''); QuarantineFile('C:\WINDOWS\SYSTEM32\DRIVERS\ONSIO.SYS',''); QuarantineFile('C:\WINDOWS\system32\DRIVERS\akpcsc.sys',''); QuarantineFile('C:\WINDOWS\system32\autochk.dll',''); DeleteFile('C:\WINDOWS\system32\autochk.dll'); DeleteFile('C:\DOCUME~1\NETWOR~1\protect.dll'); DeleteFile('C:\Documents and Settings\Mary\Start Menu\Programs\Startup\ChkDisk.dll'); DeleteFile('C:\windows\ld08.exe'); DeleteFile('C:\WINDOWS\ieocx.dll'); DeleteFile('C:\WINDOWS\system32\sysloc\sysloc.dll'); BC_ImportAll; ExecuteSysClean; BC_Activate; RebootWindows(true); end. 2) After Reboot. Attach a Combofix log, please review and follow these instructions carefully.Download it here -> http://download.bleepingcomputer.co...Before Saving it to Desktop, please rename it to something like 123.exe to stop malware from disabling it.Now, please make sure no other programs are running, close all other windows and pause Antivirus/Sypware programs (http://www.bleepingcomputer.com/forums/topic114351.html Programs to disable) until after the scanning and removal process has taken place.Please double click on the file you downloaded. Follow the onscreen prompts to start the scan. Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please upload that file to rapidshare.com and paste the link here.-------------------------------------------------

#5
June 2, 2009 at 18:31:20

#6
June 2, 2009 at 18:53:55
 Follow these Steps in order numbered. Don't proceed to next step unless you have sucessfully completed previous step:1) Run this script in AVZ like before, your computer will reboot:begin SetAVZGuardStatus(True); SearchRootkit(true, true); QuarantineFile('c:\windows\sonce122714.dat',''); QuarantineFile('c:\windows\sonce122713.dat',''); QuarantineFile('c:\documents and settings\Mary\Application Data\asd.bat',''); QuarantineFile('c:\documents and settings\Mary\Application Data\svchost32.exe',''); DeleteFile('c:\documents and settings\Mary\Application Data\svchost32.exe'); DeleteFile('c:\documents and settings\Mary\Application Data\asd.bat'); DeleteFile('c:\windows\sonce122713.dat'); DeleteFile('c:\windows\sonce122714.dat'); BC_ImportAll; ExecuteSysClean; BC_Activate; RebootWindows(true); end. 2) After Reboot. Run this script in AVZ:begin CreateQurantineArchive('c:\quarantine.zip'); end. 3) A file called quarantine.zip should be created in C:\. Then please zip up C:\qoobox\quarantine and upload both it and C:\quarantine.zip to a filehost such as http://rapidshare.com/ Then, Private Message me the Download link to the uploaded file. 4) Lastly, uninstall Combofix by: pause Antivirus/Sypware programs (http://www.bleepingcomputer.com/forums/topic114351.html Programs to disable) > Start > run > type combofix /u > ok. Or Start > run > type 123 /u > ok.-------------------------------------------------

#7
June 2, 2009 at 20:28:19
 Hi,I finished unistalling combofix. I sent you two messages with quarantine zips. I enabled back antivirus and firewall. Please let me know what is the next step, and recommendations to avoid this happening again. Thanks a lot for all your support and your easy to follow instructions.

#8
June 2, 2009 at 20:35:43
 You send me the same file twice still need c:\quarantine.zip you send me the combofix files. Please send other one.-------------------------------------------------

#9
June 2, 2009 at 21:22:56

#10
June 3, 2009 at 20:08:37

#11
June 3, 2009 at 20:10:28
 Superantispyware log:http://rapidshare.com/files/2405800...MD5: FFA5CFCAF0A55EFC1DA254CD4F73ED52

#12
June 3, 2009 at 20:11:08
 Malware log:http://rapidshare.com/files/2405802...MD5: 19E66B48C422D867A4DDF97066FA0BD2

#13
June 3, 2009 at 20:18:40
 Fix what all three detected. Your malware free. Is your orignal problem fixed any more malware related problems? Follow these next for Housecleaning:- J K -------------------------------------------------

