Redirect Malware Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bnmguy, Dec 23, 2009.

  1. bnmguy

    bnmguy Private E-2

    Hello,

    Like many others on here I have been having issues with Redirects, especially when using Google. I Ran all the scans as instructed and have attatched the logs.

    Not sure if there is still a problem yet or not. Thanks in advance! :)
     

    Attached Files:

    Last edited by a moderator: Dec 26, 2009
  2. bnmguy

    bnmguy Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why did you run the steps out of order? You ran ComboFix after MGtools.

    Also did you have any problems trying to run MGtools? The logs are extremely incomplete. Did you create your own log instead of attaching the one we requested? It sure looks that way based on the log which is incorrectly created. The correct log is ALWAYS c:\MGlogs.zip and I see it in your ComboFix log as below since you ran ComboFix after running MGtools:
    Code:
    2009-12-23 22:12 . 2009-12-23 22:15 40443 ----a-w- C:\MGlogs.zip
    Please do the below in the order written and attach the exact logs we request and not your own.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O23 - Service: 27e771c87399df39bb99f2893d00cd53 (bbfdeeddaeacb) - Unknown owner - C:\WINDOWS\bbfdeeddaeacb.exe (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

    After clicking Fix, exit HJT.


    You have left overs from Symantec to remove. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. bnmguy

    bnmguy Private E-2

    Ran steps as stated in exact order. No errors occurred. So far things seem fine, but sometimes the redirects kick in more in the evening, so I'll keep you posted as time passes.
     

    Attached Files:

  5. bnmguy

    bnmguy Private E-2

    Update*

    Redirects are still happening. :(
     
  6. bnmguy

    bnmguy Private E-2

    I forgot to mention that the following files where not found:

    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll

    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

    I did do some cleanup before your response though that may have deleted them in the process. Just uninstalled some programs I never used.

    I just continued without finding these files.

    Also, not sure if this is a big deal or not, but this is all happening in Firefox. I never use IE.

    Thanks again!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume your problem is with FireFox since you appear to be using it. There is one extension to FireFox which I suspect as a problem and we will remove. If this does not help, we will have to take more drastic steps including uninstalling Java and FireFox and deleting folders for them. Then rebooting and reinstalling...... but let's try the easier way first.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot. attach the below log:
    • C:\ComboFix.txt
    Make sure you tell me how things are working now! Do some surfing before responding to see if the redirect is gone or not.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds