Google redirecting links and pop ups - please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rajah1rogers, Jan 31, 2010.

  1. rajah1rogers

    rajah1rogers Private E-2

    Hi,

    Have have followed all the steps on the readme and am still having problems with my laptop.

    A few weeks ago Google started redirecting search results to various sites. I was also getting windows error messages - which seem to have stopped now - and pop ups opening randomly every now and then.

    I'm still getting the pop ups and google redirects.

    Have attached all the logs asked for except root repeal - I couldn't get this to run and have tried several times, following the instructions on here.

    Any help with this would be greatly appreciated. It's driving me mad.

    Thanks a lot,

    James
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's first do this:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. rajah1rogers

    rajah1rogers Private E-2

    Here are the two logs.

    At the moment, and I don't want to curse it, google seems to have stopped redirecting!

    I will keep you posted and let you know if I get any more pop ups/redirects.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to clean out these folders:
    C:\Windows\temp\
    C:\Users\James\AppData\Local\temp\

    Run CCLeaner and then run ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program. Then go to each folder and make sure nothing is remaining other than items with today's date.

    We can clean up one other item:

    copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now tell me what issues you have. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. rajah1rogers

    rajah1rogers Private E-2

    Thanks a lot for your continued help!

    Ran the two clean ups and successfully added the file to the registry. However, in local/temp a file called FXSAPIDebugLogFile.txt is still running and I can't delete it. It's dated 23/1. There's an item with today's date in windows/temp so assume this is ok.

    Random pop ups, windows error messages and google redirects all seem to have stopped though. Do I need to do anything else before completing the final steps?

    Thanks again,

    James
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    FXSAPIDebugLogFile.txt logs errors that occur during use of"Windows-Fax and -Scan" It seems to be on Vista machines. You should post about that in software if you think it is a problem.

    Otherwise, you can just finish with my last instructions if you haven't already. :)
     
  7. rajah1rogers

    rajah1rogers Private E-2

    The google redirects have all cleared up but now I'm suffering from Blue Screen errors. These appear to be random - I've received all kinds (Bad Pool Caller, Memory Management, IRQL not equal etc.) and seem to pop up at strange times. For example, I'm working in Windows now but it sometimes crashes unpredictably and refuses to load back up.

    Could this be anything to do with a virus/malware?

    Thanks,

    James
     
  8. rajah1rogers

    rajah1rogers Private E-2

    Not sure if this will help:

    I went back through the ATF cleaner stage and then checked the files you recommended. These files are still running in AppData and I can't remove them as they're running in another programme. They are:

    etilqs_YxnReE3lVhoxgPiWh15x
    etilqs_vwH0YTYfp2bZMm3bqr9d
    etilqs_ueed6QfWgqXMjlCamZee
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need not worry about those files. But the rest of your issues sound like either a hardware or software concern. I suggest again that you post in the software forum, after defragging your hard drive and running chkdsk on the drive. You could have a heat problem or a software conflict.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds