Stubborn Google Redirect

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MaitakeBoy, Oct 2, 2012.

  1. MaitakeBoy

    MaitakeBoy Private E-2

    I got a Google Redirect that is being stubborn as hell. I had run through twice with the usual tools: Anti-Rootkit scanner, Malwarebytes, HijackThis, ComboFix, Spybot, Hitman Pro. Some things were found the first time, but the redirect reappeared almost immediately. I've run it a second time, nothing found, but the infection continues. I had run these in Safe Mode with Networking. So now I come to you guys, and have tried to go through your malware and Google Redirect instructions to the T. HitmanPro found some Trojans, but I did not quarantine them as per your instructions. I am attaching all the requisite logs, etc. Any help you can give with this would be greatly appreciated. I'm usually able to take care of these things myself, but this one is particularly nasty.
     

    Attached Files:

    Last edited: Oct 2, 2012
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am currently reviewing those logs and will make a response asap.
     
  3. MaitakeBoy

    MaitakeBoy Private E-2

    Thanks Kestrel. I will patiently await your response. I am not seeing any other ill effects as of now. Simply redirects when I click on a Google search return. I'm simply not using Google at the moment.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One of those logs was incomplete. (Newfiles.txt) Let me just ask though, which browser does this affect?

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Attach the new MGlogs.zip.
     
  5. MaitakeBoy

    MaitakeBoy Private E-2

    It was affecting IE, Chrome and Mozilla. When I performed the command line run of MGtools, I got an error saying that this program couldn't run on a 64-bit machine. However, I just ran it again from the icon in the explorer window and it appears to be running. I will attach the log when it finishes.
     
  6. MaitakeBoy

    MaitakeBoy Private E-2

    Here's the MGlog I just ran from the Explorer window.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So when you say it WAS affecting, do you mean it is not now happening anymore? (Sorry, gotta be clear)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  9. MaitakeBoy

    MaitakeBoy Private E-2

    Sorry for the inaccurate verb tense. The redirects are still occurring. Here's the OTL logs. I will be heading off to a meeting in about 10 minutes that will keep me tied up until about 2. Just wanted to give you a heads up on that. Did the new MGtools log correct?
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing signs of anything strange in the logs except:

    What are these?
    • C:\Windows\tasks\bslrsscht.job
    • C:\Windows\tasks\Orkssuxb.job

    So this affects THREE browsers? Where are you being redirected to?


    Run this and attach the results.

    Using ESET's Online Scanner
     
  11. MaitakeBoy

    MaitakeBoy Private E-2

    Yeah, this has been a weird one. I have no idea what those two tasks are. They look pretty bogus, so I deleted them. There were some returns on the ESET, but nothing truly suspicious.
    Did you look at the HitmanPro log? It had found some trojans, but as per the website instructions, I didn't do anything. Maybe you could look at that log and tell me what you think.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not malware.

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except instead of uninstalling the standard way, we will use Revo Uninstaller) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Now uninstall Google Chrome with Revo too.

    Do not reinstall them yet. I want to check for any remnants before we reinstall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. MaitakeBoy

    MaitakeBoy Private E-2

    OK. First, thanks for all your help on this. I uninstalled Firefox andf Chrome and ran MGtools. The log is attached. This is quite mysterious. I had gone ahead and quarantined the items that HitmanPro identified as Trojans, just so you know, in reviewing the logs. What are those false positives?
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, is IE still redirecting? Where are you being redirected to please?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds