Search and Link Re-directs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by esgdirect, Dec 8, 2010.

  1. esgdirect

    esgdirect Private E-2

    Hi

    I am having problems with search re-directs and link re-directs. I can click on a link and it opens a fake Google Search window or when in Google when clicking on a search result can be taken to a different site. This happens only once, it will open a new browser window, that I will close and the clicking on the search link or regular link again will open up the page I am supposed to go to. It is hard to catch the url but it has a r9.google.com/..... or some numbers before it. However the computer is running a bit slow now as well. The scans are not showing anything.

    About 10 days ago I got another search re-director that would always take me to other sites and was worse than this one. I downloaded SAS and TDSSKiller and they both found stuff and killed it, the TDSSKiller one did the trick. I was clean from that point on til now but this one seems a lot different, so I would assume it is a different malware. I deleted the SAS and am not sure if any logs were saved.

    I use XP Home and Microsoft Security Essentials. Anti-virus and Firewall were off for the scans. Scans attached. Thank you so much in advance.
     

    Attached Files:

  2. esgdirect

    esgdirect Private E-2

    Here is the last log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Let's see if the current version of TDSSkiller finds anything.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  4. esgdirect

    esgdirect Private E-2

    Here you go. It did not find anything.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's good. Are the redirects occurring in both Firefox and Internet Explorer. Try both but make sure the other browser is not opened/running at all when trying each.


    Also please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  6. esgdirect

    esgdirect Private E-2

    Yes it happens with 1 browser running either or. I think this found something.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No MBRcheck came up clean.

    There are quite a few infections around that may infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. After doing this, do you still have redirections?
     
  8. esgdirect

    esgdirect Private E-2

    Funny you mention that. I was just on my daughters computer and there is a wierd thing going on there. I was checking some mail from yahoo.com and I got redirected to a survey it was amazonaws.com with other stuff on it. I may have gotten this through her machine through the router? I have a netgear wgr614v10 wireless G. I'll find out how to do that and repost. In the meantime I will scan her comp as well.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but if there are problems on her PC, you will need to start a new thread for it.

    The router is currently a common item so, it could be the problem.
     
  10. esgdirect

    esgdirect Private E-2

    I reset the router while it was still powered up. It did reset and then after about 15 seconds the router reset itself and the internet came back on. Still re-directs. But then I powered the router and my modem down (Motorola from Time Warner) and after that reset no more re-directs so far and faster speeds. If that is the case how does that happen that the router gets infected? Is there something more I can do on my part to better protect the router? My son uses his PS3 as well playing games online. I don't want his stuff to affect my comp.

    Thank you for everything. I appreciate it! Enjoy your holidays!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you meant by "reset". Did this mean a simple reset like a reboot? Or do you mean you reset it to factory defaults as requested which is obviously different.

    They get infected because malware creators have learned that they are easy targets in many cases since many people do not have password protected network equipment or just leave them at factory defaults meaning anyone can play with them. ;)

    Glad to hear it fixed your problems. Enjoy your holidays, malware free.:)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. esgdirect

    esgdirect Private E-2

    I did a Reset with power on the router by inserting a toothpick into the reset hole. After it re-booted, it was still not good until I powered down both the router and the cable modem, then it was fine. Thanks.

    After running all those scans my computer was extremely slow to boot up and slow to power down, and the sound sucked. I had to run a repair install of XP and now I am back to normal again - almost - After that Microsoft Security Essentils wouldn't turn back on, so I uninstalled it, redownloaded it but it won't re-install now. I get an error code. 0x80070643. Now I am diligently trying to get that installed....

    Thank you very much again!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange since nothing was really found or removed. The only possible reason for slow down could be related to cleaning of temp files and browser caches which could have a temporary affect.

    The repair may have corrupted the previous installation. Did you get this fixed yet? This error usually indicates an issue with Windows Update. See: http://support.microsoft.com/kb/958052
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds