HELP! Can't get rid of Redirect Virus and Firewall Error

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jlwinkel, Oct 25, 2012.

  1. jlwinkel

    jlwinkel Private E-2

    I've read thru several threads and tried several of the suggestions, but cannot get rid of the google redirect. I also noticed that my firewall has been turned off and when I try to turn it on I get Error Code 0x80070424. I have ran aswmbr.exe and mbrcheck. Logs are attached. I also ran tdsskiller.exe but it came up clean. I am not overly tech savy so detailed instructions would be great!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. jlwinkel

    jlwinkel Private E-2

    I have run everything as directed. The redirect is still there. The first couple of searches seemed to work, but by the third try it redirected. There is also an occasional ad playing in the background. I can hear it, but cannot see it or locate it. It plays for 30-60 seconds then disappears. I have also attempted to turn the firewall back on, but still received the error message described above.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 2 detections:

    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$a0a99ab8eb8513a47637aa156dc951ba\n.) -> FOUND
    • [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$a0a99ab8eb8513a47637aa156dc951ba\n.) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for Files/Folder tab entries

    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> FOUND
    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> FOUND
    • [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$a0a99ab8eb8513a47637aa156dc951ba\@ --> FOUND
    • [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-2114514035-2991071773-3569537649-1001\$a0a99ab8eb8513a47637aa156dc951ba\@ --> FOUND
    • [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$a0a99ab8eb8513a47637aa156dc951ba\U --> FOUND
    • [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-2114514035-2991071773-3569537649-1001\$a0a99ab8eb8513a47637aa156dc951ba\U --> FOUND
    • [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$a0a99ab8eb8513a47637aa156dc951ba\L --> FOUND
    • [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-2114514035-2991071773-3569537649-1001\$a0a99ab8eb8513a47637aa156dc951ba\L --> FOUND

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot your machine.



    Rescan with Hitman and delete everything it finds.
    Rescan again with Hitman and attach the new log to show me.
    Same for RogueKiller. (Just a scan and attach log)


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\ProgramData\-6ku81zM7IltUXE
    C:\ProgramData\-6ku81zM7IltUXEr
    C:\ProgramData\7be314
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{12FE0816-5CCF-4454-A817-174F373A5D09}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{73BCF034-EB81-475B-8380-D31E814A34EC}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{12FE0816-5CCF-4454-A817-174F373A5D09}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    -----------------------

    This next part takes a while, so go off and do something else for a bit...


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. jlwinkel

    jlwinkel Private E-2

    I have run into a problem. I have ran through everything to the OTM. I was asked to reboot after moving the items; but upon restart it has locked up. It popped up the warning asking permission to run OTM. After giving permission to continue the screen goes blank and appeared to be locked up after 10 or so minutes of nothing. So I turned computer off and back on. Started windows normally, but had repeat performance once I accept OTM. I have not turned the computer back off this time. What would you like for me to try? :(
     
  6. jlwinkel

    jlwinkel Private E-2

    After being locked up for a couple of hours the computer powered itself down. Once I noticed it had shut itself off, I went ahead and powered it back on to see what it would do. The third time was charm and it loaded right up. So I finished running the windows repair. It locked up on the reboot after running the windows repair, but after powering it off and back on, it seemed to load up fine. After the reboot I went ahead and ran the MGTools and rebooted again to see if it would lock up again. That time it rebooted fine.
    After running everything I checked the firewall and it is back on, along with the option for windows updates. (which had also been turned off) Both of those seem to be working fine. I have surfed a little on google chrome and have had no redirect in the past half hour. I have had NO ads running in the background. So far so good. For some reason it gave me extra RKReports, so I will be attaching 4, along with the Hitman, OTM and MGLogs. (will have to add last attachments on a 2nd post)
    Can you Let me know what further steps I need to take and let me know what I can delete, what I need to turn back on and what virus protection I should leave running. Currently I had AVAST free, but if there's something else you recommend would be willing to change to avoid this in the future.
     

    Attached Files:

  7. jlwinkel

    jlwinkel Private E-2

    Add'l attachments
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. jlwinkel

    jlwinkel Private E-2

    Thank you so much for all of the help! I have went thru the final steps and everything seems to be running great!! The tips are great and I've taken all of the recommended precautions. I think we're safe to close this thread. If I run into problems in the future I will definitely revisit. Thanks again!!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are very welcome, glad all is running nice again. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds