Google redirects, fake antivirus, etc

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by amberjn, Jun 10, 2010.

  1. amberjn

    amberjn Private E-2

    Hello, I'm working through an apparent slough of bugs in my parents computer.

    They are running Windows XP, SP3. They've been having Google redirect issues for a few weeks and CPU usage in the upper 90%'s.

    In the process of (and after running all these scans) fake antivirus software has popped up making the system unusable, offering that rundll32.exe and logonui.exe are disabled.

    I am working in Safe mode right now, and have since removed AVG Free to replace it with Microsoft Security Essentials. I have also reset the wireless router in case it has been infected.

    Any help would be greatly appreciated.

    Thanks,

    Amber
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the log from running MGTools --> C:\MGlogs.zip.
     
  3. amberjn

    amberjn Private E-2

    Oops. I forgot that one. MGTools log attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still being redirected?

    Please use windows explorer to find and delete:
    c:\documents and settings\Owner\Local Settings\Application Data\mrynbnl
    c:\documents and settings\Owner\Local Settings\Application Data\riwerdumw
    c:\documents and settings\Owner\Local Settings\Application Data\maurhefvp
     
  5. amberjn

    amberjn Private E-2

    No redirects in safe mode. I'm going to reboot in Normal mode.
     
  6. amberjn

    amberjn Private E-2

    The Google redirects seem to have stopped. Upon booting, iexplorer.exe was running with a window open. Windows explorer was not running. I hopped into taskmanager and stopped a rundll32.exe process which seemed to free up the system a bit, then use Run to start explorer.exe.

    No fake antivirus warnings have popped up yet. I'll try another reboot to see if the same startup issues happen.
     
  7. amberjn

    amberjn Private E-2

    Google redirects have stopped (folders requested to be deleted have been deleted). Windows started normally. Internet Explorer is not finding any pages, but Mozilla Firefox is running normally.

    Shall I wait to install Microsoft Security Essentials until iexplorer.exe issue is resolved?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you get to any web sites using IE? There is no reason to not change AV programs at this time. You may need to post in the software forum for your IE issues. Have you tried uninstalling it and reinstalling?
     
  9. amberjn

    amberjn Private E-2

    iexplorer lists that it "cannot display the webpage" for all pages (including google, working fine on FF).

    I haven't tried to uninstall/reinstall iexplorer.exe, since I've never done that outside an OS restore or reinstall.

    I'll hop over to software for the problem if I can't get it going.

    Thanks so much for your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try to reset your IE settings:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  11. amberjn

    amberjn Private E-2

    Registry merge was successful. No change in IE thus far.

    Windows Live Mail is also failing to sync with MSN.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just noticed you have a proxy setting:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:1397

    See these instructions:
    Change Proxy Settings.
     
  13. amberjn

    amberjn Private E-2

    Ha! I feel silly. I didn't even think to check that. It's up and running now. Thanks again.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  15. amberjn

    amberjn Private E-2

    All steps done. I installed Comodo's firewall. My parents will just have to learn to deal with firewall popups. It's better than having your system fall apart every few months from malware! :-D
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Indeed!! But I wish you luck in teaching the folks!! :-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds