google redirection removals

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DKSuddeth, Aug 14, 2011.

  1. DKSuddeth

    DKSuddeth Private E-2

    i've tried the removal tools several times as well as malware bytes and combofix. attached are some of the logs. thank you for looking.
     

    Attached Files:

  2. DKSuddeth

    DKSuddeth Private E-2

    44 views and no replies......did I not do something right?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like to see ALL of the logs, which would include logs from running C:\MGTools.exe ---> C:\MGlogs.zip
    The only thing you have done wrong is to not be patient. The 44 views were probably from people who have no authority to post here. Also I would like to point out to you that we are volunteers. You shouldn't just breeze in, demand an instant reply and start complaining. :) Takes time to analyse the logs too. PLUS we all have real lives and have jobs and families. You have been a member here a long time so should know this. Attach the log I requested, plus another (see below) and I will review your logs as soon as possible. Thanks

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
    Last edited: Aug 15, 2011
  4. DKSuddeth

    DKSuddeth Private E-2

    Kestrel, thank you for replying and you have my sincere apologies for my impatience. I've been a long time member and have become accustomed to seeing you and others promptly replying. I promise to be more patient in the future. attached is the mglogs you requested and thank you very much for looking.
     

    Attached Files:

  5. DKSuddeth

    DKSuddeth Private E-2

    forgot to attach the mbr logs. it shows up in the initial post now.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh, yes, I missed that.

    However, you ran an outdated copy of MGTools. :( So have to start over with that step.

    Download a fresh copy of MGTools.exe to the root folder of your boot drive (C:\)

    Run the new C:\MGTools.exe and attach the new C:\Mglogs.zip.
     
  7. DKSuddeth

    DKSuddeth Private E-2

    updated and new log attached. thanks again.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What are you currently using for antivirus?? I see remnants of Mcafee which we will take care of with Combofix.

    C:\Documents and Settings\Administrator\My Documents\utilities\ComboFix.exe <--- You need to move this directly onto your desktop, please.


    Uninstall the following softwares:

    • Java(TM) 6 Update 26
    • Java(TM) 6 Update 7
    • Java(TM) SE Runtime Environment 6
    • Viewpoint Media Player

    Please go to virustotal and upload the following files for analysis, and let me know the results.
    • C:\WINDOWS\system32\drivers\18267728.sys
    • C:\WINDOWS\system32\pingy.dll

    Could you please get these: 18267728.sys, pingy.dll into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip

    If this method happens to fail then please try and zip them up and attach them for me?



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    SafeBoot
    SbAlg
    SbFsLock
    RsvLock
    
    File::
    C:\WINDOWS\system32\drivers\SafeBoot.sys
    C:\WINDOWS\system32\drivers\SbAlg.sys
    C:\WINDOWS\system32\drivers\SbFsLock.sys
    C:\WINDOWS\system32\drivers\rsvlock.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. DKSuddeth

    DKSuddeth Private E-2

    18267728.sys was analyzed by virustotal, but pingy.dll is read only and unable to access.
    I have zipped them together as you asked. pingy.dll looks like my issue.

    attached are the zip file and analyze results for 18267728.sys

    I'll run combofix and then post those results in a later post.
     

    Attached Files:

  10. DKSuddeth

    DKSuddeth Private E-2

    was afraid of this. after running combofix the laptop will not boot up. it seems caught in a cycle of rebooting. i can get to the advanced options menu, but selecting start windows normally, safe mode, vga mode, or boot logging only continues the cycle. If I try 'last known good configuration' I get the message that windows could not start because system32/drivers/sbalg.sys is corrupt.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seeking advice. Hang in there.
     
  12. DKSuddeth

    DKSuddeth Private E-2

    will do
     
  13. DKSuddeth

    DKSuddeth Private E-2

    just an FYI, i've been trying to use the recovery console thinking I could just delete the sbalg.sys file. access denied to the program files directory
     
  14. DKSuddeth

    DKSuddeth Private E-2

    attached is my BSOD if interested.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.


    Boot from your Windows CD
    Select the first R prompt, to log into the recovery console
    Press 1 then Enter
    Then type: chkdsk C: /f then press enter


    Did that help? Can you now boot into windows?
     
  16. DKSuddeth

    DKSuddeth Private E-2

    chkdsk /f is not a valid parameter. all it gave me was /p and /r

    I ran /r, no mention of any errors or recovered sectors/data.

    tried rebooting with no success.

    unless you have other ideas, I guess i'll just have to reinstall windows.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Replied to your PM. We are still discussing this in the background. There are certain things I am not sure about, so I am getting everything absolutely right before responding to you regarding this.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have your XP CD, you can first try doing a repair install. Let Kes know how that goes.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OP reports that they followed TimW's advice and that everything is running as it should be. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds