Malware redirects my searches and crashes my browsers

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by adavella, Apr 2, 2009.

  1. adavella

    adavella Private E-2

    When I search for something using Google or another search engine (IE) and click a results link, I am redirected to a page different than my results, such as a questionable search page covered in ads, or a site vaguely related to my search results.

    Spybot S&D does not recognize any kind of problem. My search results are still being redirected, and my computer is running slower than usual. I would really appreciate some help with this.

    Here is my HijackThis Log:

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Apr 5, 2009
  2. adavella

    adavella Private E-2

    I apologize for posting my HijackThis file inline with my previous message. I have since performed the necessary checks and am attaching the log files from the Windows XP Cleaning Procedure (http://forums.majorgeeks.com/showthread.php?t=139313). I am still facing the same problem. When I search for something using Google or IE and click a results link, I am redirected to a page different than the displayed URL, such as a questionable search page covered in ads, or a site vaguely related to my search results.

    One note of interest: I could not access bleepingcomputer.com to save and run the combofix.exe step of the process. My browsers just displayed a white screen when I tried.
     

    Attached Files:

  3. adavella

    adavella Private E-2

    Redirect.clickshield: Malware redirects my searches and crashes my browsers

    I discovered the hijacker is called redirect.clickshield.
     
  4. adavella

    adavella Private E-2

    MGLogs also attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Before we get started, I'm wonder why you have started two new user accounts and posted the samething in each thread. Are you really looking for help for your own PC?

    Why did you start the below thread we a new user account named Road124?

    http://forums.majorgeeks.com/showthread.php?t=186512

    The second thread has now been closed!
     
  6. adavella

    adavella Private E-2

    I put all the logs in one post since I made a mistake the first time, not thinking it would be read. Can you help me?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you create a new user account?
     
  8. adavella

    adavella Private E-2

    Since I did not follow directions properly the first time, I thought I would do it correctly in a new account. I apologize if this was a mistake. I have had this malware on my system for several days now and am at my wits end.

    I notice that other people have had redirect.clickshield, but I cannot seem to diagnose the issue on my machine from their posts. Can you? Please?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start with the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_04
    Java(TM) 6 Update 3


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 85.118.8.137 www.sessionswithcesar.imgdigital.org
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    We don't recommend putting anything in the Trusted Zone, so fix the below unless you are sure they are really necessary which is rare.
    O15 - Trusted Zone: http://*.salesonline
    O15 - Trusted Zone: http://*.salesonline (HKLM)

    After clicking Fix, exit HJT.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now let's flush the Java Cache
    • Click Start > Settings > Control Panel
    • Double click the Java icon (be patient, it may take a while to open)
    • Now click the General tab and under the Temporary Internet File area
    • Click the Settings button and then click the Delete Files... button.
    • In the next popup click OK.
    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches.


    Now let's flush the FireFox Cache
    To flush your FireFox Cache:
    • click Tools
    • select Options
    • select Privacy
    • in the section labeled Private Data click Clear Now
    Now let's flush the Internet Explorer Cache
    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.
    Now run Ccleaner!


    Now delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. adavella

    adavella Private E-2

    Thank you, chaslang! Everything seems to be working now.

    One minor issue: when I open up FF, it returns to the page I was last on when I closed the browser. For example, when I closed FF this time before the final CCleaner exercise and reopened the browser, I was brought right back to our thread exchange. Any reason why that might be?

    Also, are there any other settings I should restore now that my machine seems back to normal? And what would you suggest I keep running as protective measures? SuperAnti-Spyware loads on startup, for example. Keep that, right?

    I am attaching the logs to this post. THANK YOU SO MUCH!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not malware. It's how you have FireFox setup. You probably have it set to Show my windows and tabs from last time.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds