Followed all the steps-still need help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lcmabe, Feb 22, 2009.

  1. lcmabe

    lcmabe Private E-2

    I have followed all the steps in the "Read & Run Me First". I am still having trouble with being redirected when attempted to go to Windows Update and still can't update some of my spyware programs without manually downloading the updates.

    This all started several months ago with Vundo I think. Every time I clicked on a link it was redirected. My Symantec anti-virus found it, but I've not been able to get to Windows Update ever since.

    I don't have any idea what other information you need, but I am on a wireless home network and the other computer is having the same problem.

    Here are the first 3 logs:
     

    Attached Files:

  2. lcmabe

    lcmabe Private E-2

    Here are the other logs.

    Thanks
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs other than what the scans removed. Are you having redirects in all browsers? Have you removed any toolbars and add-ons? Please do this:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  4. lcmabe

    lcmabe Private E-2

    I did the ATF thing and closed all browsers then reopened. Still getting redirects; in IE7 I put in a password for content adviser (for no rating) 3 times then hit cancel when the address showed "http://burnteam.net/?qq=windows%20update". I don't think Window's Update will work in Firefox anyway, right? If I try it, I get what look like fake Google pages to me. I can't update spyware, like Ad-Aware, Windows Defender and all of the scans I ran in "Read & Run Me First". I had to manually download all of the updates. The error usually says something about not finding the server, or check my internet connection.

    I am also getting alot of pop-ups, but don't know if that is related. I read somewhere about the router getting infected. Since both of the computers on my wireless home network have the problem, is it possible that's what is wrong? My son just reinstalled Windows XP on his computer and it is still doing it. Any ideas how to find out or fix it?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

    * Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    * Then search for TDSSserv.sys
    * Let me know if you find this or not.
    * If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    * Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.

    Then open your router and check for any DNS changes.
     
  6. lcmabe

    lcmabe Private E-2

    Did not find it.

    Don't know what I am looking for when it comes to the DNS settings, or really how to check what DNS address it is using. We have it set to "Obtain DNS Server address automatically".
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is a button on the back of your router ( or underneath ) to reset to factory settings. Do that.

    Do you have the pop up blocker activated in IE7.....does this happen with FireFox? And yes there is a FF add on for IE so you can use it for updates.

    There is also an anti-phishing setting in IE7...is that turned on?
     
  8. lcmabe

    lcmabe Private E-2

    I reset the router then immediately tried in both IE & FF. Still no luck on Windows Update. Also tried to update MBAM and SAS, but that didn't work either.

    Pop-Up blocker & Anti-Phishing are both on in IE. I use FF as my default browser and the pop-ups I am getting now are blank windows that say FF has prevented this page from automatically redirecting to another page.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK....now connect directly to your modem....bypassing your router. Does it still happen?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If not, then I want you to plug in any thumb drives ( J drive? ) and do a system search for all "autoruns.inf" and delete them.

    Then
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Re-run combofix and attach the new log.
     
  11. lcmabe

    lcmabe Private E-2

    MBAM updated & got to Windows Update site when connected directly to modem. Deleted 9 autorun.infs and got the message about adding info to registry.

    Here's new combo fix log:
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I apologize for missing it in the beginning....brain on vacation but left the body behind..:(

    This travels thru usb devices so I want you to check each computer on your network, even if they have not had a thumb drive inserted. Run Combo on each and attach each log letting me know which is which.

    I also want you to look for this file on that thumb:
    j:\resycled\boot.com --> if you find it, delete it. :)
     
  13. lcmabe

    lcmabe Private E-2

    OK--son said j is a 'virtual drive', whatever that is. Neither one of use uses a thumb drive, but I noticed combofix deleted a file by that name off his m drive.

    Anyway, here are the logs:
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...that looks good. Are you having any other issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  15. lcmabe

    lcmabe Private E-2

    The redirect issues come back when I connect through the router, so obviously that is where my biggest problem is...Can you tell me how to clean it or do I need to get a new one?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is a switch on the router that will reset it to factory settings....you need to hold that down for about 20 sec. to do that. You also need to check all computers for the TDSSservice before doing this. See post #5
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds