[Self Resolved] seekservice... but must be something more

[Self Resolved] seekservice... but must be something more
« on: November 02, 2009, 05:46:02 PM »
Hey all, I hope you can help me.

I have reviewed many different fixes on the "seekservice" malware.  Like they all suggest, I found the add-on in firefox and uninstalled it.  I then found the folder in my program files and uninstalled it.  After performing these actions, I opened Firefox and I was successful at getting to the google.com homepage.  I then rebooted my computer and found that although my web browsers were not redirecting me to seekservice.net, they were still not working.

I then downloaded Malwarebytes and manually updated it.  I ran a scan and found one infected file:

Malwarebytes' Anti-Malware 1.41
Database version: 3030
Windows 5.1.2600 Service Pack 3

11/3/2009 9:16:46 AM
mbam-log-2009-11-03 (09-16-46).txt

Scan type: Quick Scan
Objects scanned: 139231
Time elapsed: 23 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Temp\CD16E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

I again rebooted my system, but nothing was fixed.  Which brings me to this forum.  My HiJackThis log is posted below.  I hope you can help.

« Last Edit: November 17, 2009, 01:57:29 AM by Maurice Naggar »


Re: seekservice... but must be something more
« Reply #1 on: November 15, 2009, 10:03:31 AM »
Hello and welcome to SpywareHammer.

Let me know if you have resolved your issues or if the same issues are still present.

Start with the following:
Step 1
Set Windows to show all files and all folders.
On your Desktop, double click My Computer, from the menu options, select tools, then  Folder Options, and then select VIEW Tab and look at all of settings listed.

"CHECK" (turn on) Display the contents of system folders.

Under column, Hidden files and folders----choose ( *select* ) Show hidden files and folders.
Next, un-check Hide extensions for known file types.
Next un-check Hide protected operating system files.

Step 2
Take out the trash (temporary files & temporary internet files)
Please download ATF Cleaner by Atribune, saving it to your desktop. It is used to cleanout temporary files & temp areas used by internet browsers.
Start ATF-Cleaner.exe to run the program.

Under Main choose: Select All

Click the Empty Selected button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser, do this also:
Click Opera at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.
 ATF-Cleaner should be run per the above in every user-login account {User Profile}

Step 3
1. Go >> Here << and download ERUNT
(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
2. Install ERUNT by following the prompts
(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
3. Start ERUNT
(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
4. Choose a location for the backup
(the default location is C:\WINDOWS\ERDNT which is acceptable).
5. Make sure that at least the first two check boxes are ticked
6. Press OK
7. Press YES to create the folder.

Step 4
Download Security Check by screen317 and save it to your Desktop: here or here

  • Run Security Check
  • Follow the onscreen instructions inside of the command window.
  • A Notepad document should open automatically called checkup.txt; close Notepad.  We will need this log, too, so remember where you've saved it!
If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.

Step 5
Download Random's System Information Tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open.

Please post the contents of both log.txt (<<will be maximized)
and info.txt (<<will be minimized)
and Checkup.txt
~Maurice Naggar
MS-MVP (October 2002 - September 2010)


Re: [Self Resolved] seekservice... but must be something more
« Reply #2 on: November 17, 2009, 01:58:50 AM »
User advises problems have been resolved.
I'm closing this topic & moving to archive.
~Maurice Naggar
MS-MVP (October 2002 - September 2010)