google unrelated sites

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by scraggs, Nov 27, 2010.

  1. scraggs

    scraggs Private E-2

    Hi everyone,
    I have been having a problem for the past couple of weeks where google has been mis directing me to unrelated sites.
    The only out of these sites is to shut down browser and restart browsing.
    Pushing the back numerous times does nothing!
    I hope someone out there can help me.
    Many thanks in advance,
    scraggs
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

  3. scraggs

    scraggs Private E-2

    Many thanks for your help.
    There was a lot of rubbish on my computer!
    It was really running slow and doing odd things.
    It now seems to be a little better.
    Maybe I should do a complete restart ie. a full format!
    Cheers,
    Scraggs:wave
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also attach the SUPERantispyware log, and also run Malware Bytes as you missed this step.

    Are your search results still being redirected? If so run this, attach the log, and let me know how things are running now. Then I will see what malware remains if any and post a fix.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  5. scraggs

    scraggs Private E-2

    Hi there,
    Malaware bytes wouldn't run.
    the following message came up.
    missing file MSVBVM60.dll
    Sorry about not sending the other log file.
    I will attach it now.
    Cheers,
    scraggs:
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please refer to this link.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}]
    
    :files
    C:\Documents and Settings\John Gartland\Application Data\FunWebProducts
    C:\Documents and Settings\John Gartland\Application Data\ParetoLogic
    C:\Documents and Settings\John Gartland\Application Data\PriceGong
    C:\Documents and Settings\All Users\Application Data\ParetoLogic
    C:\Documents and Settings\All Users\Application Data\STOPzilla!
    C:\Documents and Settings\John Gartland\My Documents\ParetoLogic PC Health Advisor.exe
    C:\Documents and Settings\John Gartland\My Documents\STOPzilla_Setup.exe
    C:\WINDOWS\system32\drivers\kgpcpy.cfg
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Run Combofix as per the instructions in the Read and Run me First Procedures.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Is this STILL happening or not? You must let me know.
     
  7. scraggs

    scraggs Private E-2

    Thank you for all your help.
    I still have a problem re unrelated sites. Not as bad as before, but still occasionally. Enough to cause problems as I have to shut down the browser to get out of the unrelated site.
    Apologies for not sending the correct info to you!
    Attached are the current log files requested.
    Many thanks again,
    Cheers,
    scraggs:)
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Would be nice to have it gone completely! So, let's see if this helps.

    c:\documents and settings\John Gartland\My Documents\Downloads\ComboFix.exe <--- Combofix should be directly on your desktop, not here.

    You missed this step!
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Use Windows Explorer to find and delete the below folders:

    • C:\Documents and Settings\John Gartland\Application Data\MyHeritage
    • C:\Documents and Settings\All Users\Application Data\MyHeritage
    • C:\Documents and Settings\All Users\Application Data\IncrediMail

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Any better? Let some time pass, surf around and then pop back to let me know. :)
     
  9. scraggs

    scraggs Private E-2

    Many thanks again for your help!
    Did not get a "success" message, but the file shows in Desktop.
    The computer seems to be running faster now.
    I will attach the MGlogs.zip file for you.
    I will keep in touch and let you know how the computer is behaving.
    Have a wonderful Christmas and New Year.
    Once again thanks for all your help,
    Cheers,
    scraggs
     

    Attached Files:

  10. scraggs

    scraggs Private E-2

    Success!!!
    Retried loading the fixME.reg and this time it gave me the success message.
    Thanks again for all your help.
    Cheers,
    John
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Same to you! :)

    So your google searches are normal again now? If yes, then I will post final steps when I next log in.
     
  12. scraggs

    scraggs Private E-2

    Many thanks yet again!
    My machine is running sweet and doing all the right things when I'm browsing!
    Cheers,
    John
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. scraggs

    scraggs Private E-2

    Hi Kestrel13,
    Happy New Year!
    My computer is running sweet!!!
    Have not had any problems since I last contacted you.
    Many thanks again for all your help!
    Cheers,
    scraggs:wave
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Scraggs! Happy new year to you and yours too! :) Excellent to hear that the computer is still chugging along quite nicely ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds