Any browsers search results get redirected......

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dicostanzot, Jun 23, 2011.

  1. dicostanzot

    dicostanzot Private E-2

    I have been through some of the existing steps of available threads and still continue to get the issue where any search results get hijacked and redirected. Additionally svchost.exe is consuming alot of cpu and memory, that may be another issue. though. I have submitted my logs.

    thanks so much for someone's help!:cry
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not submit the logs we request. You still need to attach these:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip

    I also want you to run this:
    TDSSkiller - How to run
     
  3. dicostanzot

    dicostanzot Private E-2

    Hi Tim,

    yes the logs are all in that zip file.

    Tom
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It did not include the C:\MGLogs.zip. Please attach that.
     
  5. dicostanzot

    dicostanzot Private E-2

    I just tried running that, it opens the cmd window as stated runs fine for a few minutes and windows boots, no zipped logs are in the directory. I tried it again, same results.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Got a C:\MGlogs.zip now?
     
  7. dicostanzot

    dicostanzot Private E-2

    Hello, I finally had a chance to do that. No errors that I could see. It seemed to run ok I uploaded screen shots for you to see.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you need to attach the C:\MGlogs.zip file that was created.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also need to attach the TDSSKiller log that Tim requested you obtain in message # 2.
     
  10. dicostanzot

    dicostanzot Private E-2

    I am not getting any logs created, I made sure no files were hidden, the only items that got created last night when I ran everything I attached.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Lane\Local Settings\Application Data\1061297859
    C:\Documents and Settings\Lane\Local Settings\Application Data\3046731244
    C:\Documents and Settings\Lane\Local Settings\Application Data\ueu4ue45lg20w7c4ddf
    C:\Documents and Settings\All Users\Application Data\1061297859
    C:\Documents and Settings\All Users\Application Data\3046731244
    C:\Documents and Settings\All Users\Application Data\ueu4ue45lg20w7c4ddf
    C:\Documents and Settings\Lane\Templates\1061297859
    C:\Documents and Settings\Lane\Templates\3046731244
    C:\Documents and Settings\Lane\Templates\ueu4ue45lg20w7c4ddf
    
    Folder::
    C:\Documents and Settings\All Users\Application Data\Avg7
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you are. You are not looking in the right place. They are not in the MGtools folder. As stated in the instructions and in messages here in this thread, the file is C:\MGlogs.zip. It is not C:\MGtools\MGlogs.zip which is where you seem to be looking


    Also you still did not attach the requested log from TDSSKiller.
     
  13. dicostanzot

    dicostanzot Private E-2

    chaslang you were right :-o, my mistake. I have attached both logs
     
  14. dicostanzot

    dicostanzot Private E-2

    looks like after running the combo.fix again, and the TDDSKiller the issue is gone! can you still look at the logs?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds