I seem to be having a Google redirect issue

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sally35, Oct 28, 2010.

  1. sally35

    sally35 Private E-2

    I seem to be having a Google redirect problem in FireFox running Windows 7. I get redirected to one of two sites: guide1.net or gimme answers. I've run MBAM, SAS, Avast, AVG and MS Security Essentials, but am coming up with nothing. I am attaching the files recommended in your removal guide. Please advise as to how I can get rid of this. Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Java(TM) 6 Update 21 <--- Uninstall this outdated Java

    Tell me what is inside of these folders, or show me with a screenshot
    • C:\Users\Tara\AppData\Local\{E2539D0F-2AE2-4611-976D-72FE89FAB9EB}
    • C:\ProgramData\MFAData

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    :files
    C:\Users\Tara\AppData\Local\Atetokaradewilul.dat
    C:\Users\Tara\AppData\Local\Bwociqusolet.bin
    C:\Users\Tara\AppData\Local\mugbsfist
    C:\Users\Tara\AppData\Local\ovjatxjmb
    C:\Users\Tara\AppData\Local\rioashvun
    C:\Users\Tara\Local Settings\TEMP\870A.tmp
    C:\Users\Tara\Local Settings\TEMP\ADDB.tmp
    C:\Users\Tara\Local Settings\TEMP\CA60.tmp
    C:\Users\Tara\Local Settings\TEMP\F4FB.tmp
    C:\Users\Tara\Local Settings\TEMP\F4FC.tmp
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Use windows explorer to find and delete these old remains from antivirus
    • C:\ProgramData\Alwil Software
    • C:\ProgramData\AVG10
    • C:\ProgramData\avg9
    • C:\Program Files (x86)\AVG
    • C:\$AVG

    You need to install some antivirus. (Just one!)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running for you now? Still having redirects or not?
     
  3. sally35

    sally35 Private E-2

    Thanks so much for all your help. Requested info is attached (files 2 of 4).
     

    Attached Files:

  4. sally35

    sally35 Private E-2

    I attempted to upload a screen shot of the folder contents you requested, but the file size was too large. It's Google Chrome files inside. I don't see the MFA folder. Not sure if I deleted it between now and then or what. Also, I have Microsoft Security essentials installed, which I thought had virus protection, but I'm on the verge of uninstalling and getting AVG back.

    The redirect problem seems to have stopped, but it wasn't always consistent, so I'll post back if I notice it again.

    Based on what you saw, should I be concerned for any personal info on my pc?

    Thanks again for all of your assistance - much appreciated! :)
     
    Last edited: Oct 28, 2010
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's fine, it relates to AVG anyway.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :dir
      {E2539D0F-2AE2-4611-976D-72FE89FAB9EB}
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds