Link redirection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by xabaddonx, Feb 7, 2009.

  1. xabaddonx

    xabaddonx Private E-2

    My comp recently started having a problem where when I click on search result links in google, it will sometimes take me to an ad site. I've run all the spyware and virus scans, originally SUPERAntiSpyware found a SENEKA rootkit so I thought it might be that, however after removing it the problem remains.

    Also after trying to fix this for awhile, when I reboot now sometimes windows will freeze on startup right as the windows logo starts fading in. I'm not sure if this is related. Manually restarting with the reset button after this will allow a normal reboot.

    I followed all the directions in the malware removal guide, here are my logs. They might look relatively clean since I had already run antispyware previous to following the guide. Thanks in advance for any help you can provide.
     

    Attached Files:

  2. xabaddonx

    xabaddonx Private E-2

    the rest of the logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not really seeing any problems in your logs; however I do have some questions and somethings for you to do.

    Questions:
    1. Does the search redirection occur when using both FireFox and Internet Explorer?
    2. Does it also occur in safe boot mode?
    3. Did you knowingly install WinVNC? It is not malware, but if you did not install it, it could be a problem.
    4. What is the below that I see in your boot.ini file?
      • multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Bankai Windows" /noexecute=optin /fastdetect
    There is a recent change to your user32.dll file. Do you know why this would have occurred? Did you have to replace it? Is this the date your problems began?
    Code:
    "C:\WINDOWS\system32\dllcache\"
    user32.dll    Feb  6 2009      578560  "user32.dll"
    
    Uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.

    Delete the below file:
    C:\WINDOWS\system32\rn.tmp

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the new C:\MGlogs.zip file
     
  4. xabaddonx

    xabaddonx Private E-2

    It appears to only affect Firefox. I can't reproduce the problem in IE.

    It does also occur in safe mode.

    Yes, I installed WinVNC, I use it to login to my home pc from work.

    This is leftover from old installation of Windows on another drive, I don't use it anymore.

    I don't know what changed this, but I believe my problems started before this date.

    Another thing I noticed is that when the redirection occurs, I can see at the bottom of the screen on the status bar that it is going through a site called "clickfraudmanager.com".
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What browser addons do you have with FireFox?

    We may have to try uninstalling FIreFox and then deleting all related folders before a reboot and then a reinstall.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before we bother thinking about uninstalling FireFox, please do the below exactly as written for me which will help collect some additional info we need.

    Download this View attachment FFFred.zip to your C:\MGtools folder. Then extract the FFFred.bat file from the FFFred.zip file into the C:\MGtools folder. Then double click the FFFred.bat file to run this batch file. It runs very quickly. A notepad log will popup. You can just close this notepad window because the log will already be added to the C:\MGlogs.zip file. Just attach the new C:\MGlogs.zip file.
     
  7. xabaddonx

    xabaddonx Private E-2

    My Firefox has the following addons showing under "extensions"

    AVG Safe Search 8.0
    AVG Security Toolbar 2.0.20080710
    Delicious Bookmarks 2.1.018
    FireFTP 1.0.2
    Flashblock 1.5.7
    Java Quick Starter 1.0
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is what I want you to do. Read ALL of this and/or print it because you MUST HAVE all FireFox windows closed before doing it.

    Locate the below file using Windows Explorer.

    C:\Program Files\Mozilla Firefox\extensions\{03CA0C23-8373-4D0F-B276-2C11E0ED47FC}\chrome\content\overlay.xul

    Then right click on the overlay.xul file and rename it to overlay.BAD

    Now restart FireFox and tell me if you still have the problems
     
  9. xabaddonx

    xabaddonx Private E-2

    That seems to have fixed it! Many thanks :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Then I suggest that you now delete the overlay.BAD file.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds