My Google redirection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by agiosotheos, Jun 17, 2011.

  1. agiosotheos

    agiosotheos Private E-2

    I was using the Google redirection sticky (because I'm having this problem and suspect I have malware causing it [Avast keeps indicating and finding malware but can't remove it for some reason]). I did steps 1&2. Now I am on step 3. It seemed to indicate that the gooredfix log should be posted here. So I have it attached. I'll also copy past it below. I would love some help figuring out what to do with this. :)

    GooredFix by jpshortstuff (03.07.10.1)
    Log created at 12:06 on 16/06/2011 (chris)
    Firefox version 4.0.1 (en-US)

    ========== GooredScan ==========


    ========== GooredLog ==========

    C:\Program Files\Mozilla Firefox\extensions\
    {972ce4c6-7e08-4474-a285-3208198ce6fd} [18:40 09/06/2011]
    {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [08:48 16/02/2011]

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
    "jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [08:47 16/02/2011]
    "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02:46 15/06/2011]

    -=E.O.F=-
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Then continue on with the below.

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. agiosotheos

    agiosotheos Private E-2

    Hi. I did run TDSSKiller. It detected the rootkit and cured it. Then had the computer do a reboot. Then I ran the TDSSKiller again to make sure it wouldn't possibly reveal anything more. It found nothing. After that reboot, my antivirus program stopped detecting malicious software. I tried Google but it still did the redirect. I figured maybe the malware had a habit of establishing cookies that would do this, so I cleared all my history with SlimCleaner. After that the redirect did not occur again.

    Should I continue on with the READ&RUN even thought the problem appears to have been solved? Is there any other program I should run in the aftermath of a malware infection? Is it possible that important files have become corrupt through this episode? If so, is there someway to scan my files to see if they are damaged?

    Thanks for the help. :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you need to continue on following my other instructions which I linked you! :) Attach all of the requested logs once finished.
     
  5. agiosotheos

    agiosotheos Private E-2

    OK, I'm back with the logs. Right off the bat I think it might be important to point out that I got error messages both when running combofix and when running MGtools, and I don't know if they ran entirely.

    The Superantispyware, Malwarebytes, and RootRepeal logs are attached in this message.
     

    Attached Files:

  6. agiosotheos

    agiosotheos Private E-2

    The Combofix and MGtools logs are attached to this message.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What are all these files, related to symantec doing in program files folder? You do not have anything symantec installed so get rid of them to tidy up?

    Code:
    C:\WINDOWS\Downloaded Program Files\"
    catalog.dat   Jun  8 2011        2584  "catalog.dat"
    ecbootil.vxd  Jun  8 2011        6895  "ecbootil.vxd"
    ecmsvr32.dll  Jun  8 2011      279992  "ecmsvr32.dll"
    naveng32.dll  Jun  8 2011      177520  "naveng32.dll"
    navex32a.dll  Jun  8 2011     1897840  "navex32a.dll"
    scrauth.dat   Jun  8 2011       98112  "scrauth.dat"
    symaveng.cat  Jun  8 2011        8707  "symaveng.cat"
    symaveng.inf  Jun  8 2011        1064  "symaveng.inf"
    tcdefs.dat    Jun  8 2011    17296196  "tcdefs.dat"
    tcscan7.dat   Jun  8 2011    22332690  "tcscan7.dat"
    tcscan8.dat   Jun  8 2011      169522  "tcscan8.dat"
    tcscan9.dat   Jun  8 2011      607737  "tcscan9.dat"
    tinf.dat      Jun  8 2011         453  "tinf.dat"
    tinfidx.dat   Jun  8 2011         148  "tinfidx.dat"
    tinfl.dat     Jun  8 2011        1957  "tinfl.dat"
    tscan1.dat    Jun  8 2011       74596  "tscan1.dat"
    tscan1hd.dat  Jun  8 2011        3934  "tscan1hd.dat"
    v.grd         Jun  8 2011        4988  "v.grd"
    v.sig         Jun  8 2011        2609  "v.sig"
    v1.sig        Jun  8 2011        2266  "v1.sig"
    virscan.inf   Jun  8 2011      106244  "virscan.inf"
    virscan1.dat  Jun  8 2011     1053958  "virscan1.dat"
    virscan2.dat  Jun  8 2011      573606  "virscan2.dat"
    virscan3.dat  Jun  8 2011      157484  "virscan3.dat"
    virscan4.dat  Jun  8 2011      320359  "virscan4.dat"
    virscan5.dat  Jun  8 2011    16122273  "virscan5.dat"
    virscan6.dat  Jun  8 2011      398102  "virscan6.dat"
    virscan7.dat  Jun  8 2011   143141510  "virscan7.dat"
    virscan8.dat  Jun  8 2011     1003270  "virscan8.dat"
    virscan9.dat  Jun  8 2011     5563255  "virscan9.dat"
    virscant.dat  Jun  8 2011          32  "virscant.dat"
    zdone.dat     Jun  8 2011         224  "zdone.dat
    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\~   
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\*9 *]
    "Asynchronous"=dword:00000001
    "DllName"="Service Pack 3"
    "Impersonate"=dword:00000000
    "Enabled"=dword:00000001
    "Startup"="WlStartupEvent"
    "Logon"="WlLogonEvent"
    
    File::
    C:\Documents and Settings\chris\Local Settings\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
    C:\Documents and Settings\All Users\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
    C:\Documents and Settings\chris\Templates\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. agiosotheos

    agiosotheos Private E-2

    As to the first thing you mention: which log were you seeing these files in? I couldn't find them in Windows Explorer, and I even did a search for the file catalog.dat in my C drive and it came up with nothing.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The are not all from Symantec. Some are from McAfee and they both are likely due to running some form of online scanners.

    Note to agiosotheos, you cannot see the files in C:\WINDOWS\Downloaded Program Files with Windows Explorer. You need to use the command prompt or another specialty file listing tool to see these hidden files and folders. They are protected from view in Windows Explorer.
     
  10. agiosotheos

    agiosotheos Private E-2

    Even after changing the viewing preferences as in Step 4 of READ & RUN?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's correct. This is a special folder in Windows and the files do not show unless viewed as I stated from the command prompt or using other programs that do not have the same restrictions as Windows Explorer. For example, you could install and use the below and you will see the files there:

    ExplorerXP
     
  12. agiosotheos

    agiosotheos Private E-2

    So are you guys sure about deleting all these files?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are not malware, so you really don't need to worry about them. They are just files you don't need. They were put here due to running some form of online scan from McAfee. If you deleted the files and then went to the online site to run the scans again, they would just redownload the files.
     
  14. agiosotheos

    agiosotheos Private E-2

    OK. I have SlimCleaner on my computer to keep my history, cookies, temporary files, etc. clean. I was running it yesterday and noticed some Symantec software show up in uninstall feature. Should I do this uninstall in SlimCleaner first and then use ExplorerXP to see which of those files are remaining? And does the shredding feature on SlimCleaner have any significance here? Does it assist in files being removed from being read on the hardrive in use, or is it only for the purpose of wiping it from examination of the drive?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attach the logs which were asked for in post # 7 please?
     
  16. agiosotheos

    agiosotheos Private E-2

    Hi. I just ran Combofix as instructed in post #7. However, another oddity occurred, so I figured post about it and post the log before proceeding.

    Near the end of the process it asked to delete C:/Documents and Settings/chris/WINDOWS. I was taken aback at this action, not really knowing what that folder consisted of, so I commanded it not to. Once it finished I checked out the folder and it appeared empty, so I guess it probably wasn't necessary for me to stop it from deleting it. But in the moment I didn't have enough knowledge to feel safe doing otherwise. I'll attach the log.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to complete all the steps in post number 7! :)
     
  18. agiosotheos

    agiosotheos Private E-2

    Here is my MGTools log. It seemed to have worked better than last time.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't see how or why that would be. I get the same amount of information in each anyway. Nothing different. :confused


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\documents and settings\chris\WINDOWS
    
    Driver::
    cusbohcn  
    
    File::
    c:\docume~1\chris\LOCALS~1\Temp\cusbohcn.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  20. agiosotheos

    agiosotheos Private E-2

    Thanks. You want me to run Combofix and MGTools again?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not the way you did before. Just follow the instructions as they are written.
     
  22. agiosotheos

    agiosotheos Private E-2

    I've performed the scans for the latest instructions and I'm pretty sure the pertaining logs are the ones that are attached.
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look good. Delete this file:

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s

    Tell me what problems remain.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds