Infected Computer. I think its the explorer.exe virus but google redirects

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by man_utd_99, Dec 17, 2010.

  1. man_utd_99

    man_utd_99 Private E-2

    Hi

    Firstly i really appreciate the help and time you are going to be giving and im sure you'll eventually fix my computer!

    What i have is a
    compaq v6000 laptop
    Intel T2080 1.73 pentium dual core
    2gb ram
    partitioned hard drive with vista home premium on the main computer
    and then the infected partition which is windows 7 ultimate with roughly 20gb of space for the windows 7.

    Basically ive had to use the vista as every search redirects when using google on the windows 7.

    can you guys please let me know what to do and if searches through vista by checking the partition G of windows 7 can be done aswell that way ill have to continually reboot windows 7 and then vista on and off?!

    if any HJT logs need to be added please just let me know too

    and just to add, recently ive been getting notifications of gstatic.com being accessed which the computer is refusing as it is detecting it was as a phishing site.

    thankyou
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. man_utd_99

    man_utd_99 Private E-2

    just to add, when searching for malware and spyware it finds nothing, and halfway through malwarebyte search, the programme crashes :(
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please just skip any scans that don't run. But in the meantime, I want you to also run this:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  5. man_utd_99

    man_utd_99 Private E-2

    combofix wont run as apparently i have AVG installed. i uninstalled it a while back so that search wont happen.

    ill attach the other log files when all scans are done

    thankyou
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. man_utd_99

    man_utd_99 Private E-2

    firstly i have to give it to you. you guys are good!

    right i firstly have to thank you as i think my computer is fixed. if you want ill attach the logs but ill give you a step walkthrough of what i did.

    did a search using malwarebytes and it found a few things but nothing major
    then superantispyware and it found a few cookies that werent of major issue
    then searched using the combofix which went all the way to "48 completed states" and it found the "explorer.exe" and "wininit.exe" issues which it detected, removed and whatever else it did.
    then searched using tdsskiller to be on the safe side and got nothing from that scan.

    so when looking and searching on google now, i dont get any redirects and really am happy with the help you've given me. i think all is well although the computer does seem a little slower than before.

    if you want logs to be attached let me know but other than that everything seems good and fine. thankyou once again. really appreciate the help you've given.

    cheers guys :wine
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi!
    You're welcome, and perhaps TimW can also help with your pc's slowness. Please attach these logs -
    • SASlog.txt log from SuperAntiSpyware.
    • Malwarebytes Anti-Malware log
    • RRlog.txt (from RootRepeal)
    • ComboFix.txt (normally C:\ComboFix.txt)
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    dr.m
     
  9. man_utd_99

    man_utd_99 Private E-2

    here are the logs of the scans that did run. please let me know if any problems still remain and tell me what i can do to speed up my computer.

    thankyou guys
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the C:\MGLogs.zip. You can not zip a zip.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can! ;) But we do not want them attached in a double layer zip. :)
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They never open correctly when they are double zipped for me. :(

    Well, the second try worked. So, no need to re-attach the log. I am not seeing any malware in your logs.

    I also do not know or see any reason for slowness. I suggest you post in the software forum for further assistance with that. ( You might want to first try disabling Spybot TeaTimer from running at start up. )

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
    Last edited: Dec 18, 2010
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which is why I said we don't want them that way. Some helpers do no have WinZip which can handle this.
     
  14. man_utd_99

    man_utd_99 Private E-2


    firstly sorry for the winzip but there were a few logs so i thought putting them into one package would be easier.

    secondly would it be possible for someone to move my thread to the software section or would it be better if i made a new one?

    thankyou for your help. really appreciate it.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would be best if you created a new one in the software forum and answer these questions for them so they can get an idea as to what is happening:

    Please explain what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly two contributors that I see:

    First low hard disk space on drive C which as an extremely small drive to be running Win 7 on.
    Second a combination of all of the below being installed:

    Ad-Aware
    Advanced SystemCare 3
    ALWIL Software Security 4.8.1296.0
    Ask Toolbar
    avast! Antivirus
    IObit Security 360
    Spybot - Search & Destroy
    ZoneAlarm Toolbar
    ZoneAlarm

    I would uninstall each of the below and then reboot and see how things run.

    Ad-Aware
    Advanced SystemCare 3
    Ask Toolbar
    IObit Security 360
    Spybot - Search & Destroy
    ZoneAlarm Toolbar
    ZoneAlarm



    EDIT: Providing answers to the questions TimW just posted would also help everyone better understand your problem.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed that your logs were from safe boot mode. You really needed to attach logs from Normal Boot mode for proper disgnosis. Also ComboFix had stated the below
    You should rerun ComboFix in normal boot mode and see if these still show as infected.
     
  18. man_utd_99

    man_utd_99 Private E-2


    ill get all the stuff uninstalled and will let you know. the computer isnt majorly slow, just a lot slower than it was before it got infected if that makes any sense?!

    and the smallness of space is because i partitioned with vista being the main OS. didnt think id like windows 7 as much as i do!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does. Quite frequently this happens after some infections because they can managed to break various aspects of Windows that are not detectable via any scans. The only real true solution in some cases is a reinstall as using System Restore or even a Repair Install will also not always be entirely successful.

    Make sure you rerun ComboFix too as suggested to see if the infections were truly fixed.

    Yes I noticed from your logs the 3 partitions. Win 7 should have a larger partition though.
     
  20. man_utd_99

    man_utd_99 Private E-2

    yeh i only did it as part of a little mess around. started off with ubuntu and then got rid and put windows 7 on. so yeh little experiment it was, didnt think it would stay tbh thats the only reason the partition is small. actually is there a way i can increase a partition without removing and redoing it all again?

    and i reran all scans.
    combofix was clear,
    superantispyware was clear
    however as before when computer was infected, malwarebytes doesnt complete its scan and crashes. "malwarebytes has encounted a problem and will close" or something like that appears, it however searches fully in safemode.

    computer seems ok for now. a little slow on boot up, and shut down and general multitasking or opening new windows and software. i guess theres nothing else i can do but to live with it yeh. :/
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    May just be due to all the things you are running. Did you uninstall ALL of the items I suggested? If so then also look into removing anything else not really necessary. Also consider uninstall Avast and rebooting just as a test to see what happens. Due to having multiple security programs installed, you may have cause some corruption.
     
  22. man_utd_99

    man_utd_99 Private E-2

    right ok i really dont know what or why i cant uninstall things. i tried to uninstall the toolbars and both failed. the zonealarm one said it couldnt find the install.DLL i think it was so that failed. and the ask one failed too.

    looked through all my programmes and i dont have another antivirus/firewall software so would removing zonealarm and avast be advisable?

    kind regards
     
  23. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Are they listed in CCleaner's "Tools > Uninstall" section? *Other tools that may be useful are -
    *For testing purposes, this should be done while your machine is physically disconnected from your internet connection.
     
  24. man_utd_99

    man_utd_99 Private E-2

    right ive a little problem that has arisen.

    windows 7 is now, thankfully all good and working. speed is more or less there so im happy about that. thankyou guys for that.

    what now has happened is that when starting vista, it loads up partially upto the little rectangular bar and then there is a blue screen with the problem "bad_pool_sector" and turns itself off.

    when running in safe mode i get the constant loop of "explorer has stopped working" it clears the screen of all applications, then comes back and then notifies me of the explorer not working again in a loop. so i am unable to start any applications and do anything and when clicking "repair this computer" i apparently i have no previous system restore points which is a serious issue to me as ive no idea why thats the case and an error and "bad sector" when it attempts to repair the problems.

    any ideas please?

    thankyou once again
     
  25. man_utd_99

    man_utd_99 Private E-2

    computer now doesnt boot in vista regardless of setting

    safe mode
    last known good configuration
    debugging mode
    recovery mode - has an error which i will write down and let you know exactly what it is
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your Vista CD? You may need to do a repair install.
     
  27. man_utd_99

    man_utd_99 Private E-2

    its come with a recovery partition but i downloaded a repair cd from microsofts website.

    inserted and pressed button to run from cd or dvd
    clicked repair
    and it "scans for problems on drive" and then the same error comes as if i were to click on "repair your computer" without the vista disc in it if that makes any sense?

    its just stuck on bad sector blue screen and turns itself off. i cant even get vista booted!
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest that you post in the hardware forum. Sounds like you also may be having hard drive issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds