Google Redirects to "30ksearches"

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bmatt, Jun 27, 2011.

  1. bmatt

    bmatt Private E-2

    I am having a Google Redirection issue. I have done full scans with Clamwin, RegRun, and all the tools listed on here, to no avail. The first few clicks on Google results (varying amount, sometimes 4 or so, more than 20 at the worst) lead to 30ksearches which redirects me to various pages offering adware etc. Nothing I have found as of yet has helped, can anyone offer any assistance?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to the Malware Removal Forum.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Then you must continue on with these instructions.

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. bmatt

    bmatt Private E-2

    Rerunning those to get logs, will post ASAP.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re running what exactly? If you have already followed our procedures then attach the logs. We do not want you running scans twice.
     
  5. bmatt

    bmatt Private E-2

    Well I'd already done MalwareBytes and SuperAntiSpyware, but not the other two (I'm on 64 bit so no RootRepeal). Unfortunately, I think either combofix or MGTools killed my startup... Windows only boots into "System Recovery Mode", where it won't access any of my backups and my only option is to to factory settings.... I'm currently booted into my old Ubuntu 9.10 LiveCD. I'll get into the Windows HD to get the logs now.
     
  6. bmatt

    bmatt Private E-2

    Didn't mean to bump, but I can't seem to locate the edit function.
    Where are the default log locations for SuperAntiSpyware and MGTools? I didn't get a chance to save them to an alternate location before my last reboot.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Users\Your Name\AppData\Roaming\SUPERantispyware.com\SUPERantispyware\Logs\Your log will be found here... (If on win 7 or vista)

    Combofix ---> C:\Combofix.txt
    MGTools ---> C:\MGlogs.zip
     
  8. bmatt

    bmatt Private E-2

    MGTools apparently didn't get to the point where it saved its logs (a reboot was forced by another program) but here are the other logs
     

    Attached Files:

  9. bmatt

    bmatt Private E-2

    I'm very sorry for bumping again, but I've looked around I made some sort of mistake with ComboFix that apparently prevents Windows from starting. I realize this isn't the purpose of this thread, but if I could get some assistance with that, it would be so appreciated.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What happened? :confused
     
  11. bmatt

    bmatt Private E-2

    I don't know exactly what happens, but when I searched "ComboFix Windows won't start", I got lots of results on Google. Is there something in the log that explains what happened?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The log is very incomplete. Are you able to boot into safe mode at all?
     
  13. bmatt

    bmatt Private E-2

    Nope. I'm currently burning a Trinity Repair Kit LiveCD to see if I can do anything from there.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me know how you get on.
     
  15. bmatt

    bmatt Private E-2

    No luck with bringing Windows back to life. I think I got the virus removed, but it appears that the damage I caused with ComboFix wasn't able to be fixed from there. The way I see it, I've got a few options...
    -Get an install disc for Windows 7 (I'm using a factory installed version) and use the repair console to do the "SFS /SCANNOW" command.
    -Find some way to do that^ within Linux.
    -Use the built in utility installed by HP on my hard drive to restore it to its "original settings."
    My worry with the last one is that it'll just wipe everything off, not reinstall Windows like I hope it will.
    Any ideas on what's the best path? (Or if any of those even make sense?)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You commented that you thought you made a mistake? In what way may I ask?

    • Did you run a script with Combofix un-assisted perhaps?
    • Did you mean that Combofix itself made the mistake and not you?
    • Perhaps it then deleted files? If so did you note what it was deleting?
    • Was there any kind of rootkit activity that you noticed that CF could have reported?
     
  17. bmatt

    bmatt Private E-2

    All I did with ComboFix was run the executable from my desktop. I assumed I did something since other people have had success performing the same operation. It is possible one of my system files was infected and it deleted it, however, I have no idea which, I left it to run when I went to do some other work :/
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am seeking further advice from my colleagues. I appreciate your patience.
     
  19. bmatt

    bmatt Private E-2

    I appreciate any help haha. I'd rather salvage as much as I can than be forced to do a completely clean install of Windows. Thanks again.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now, we have had a discussion and Chaslang wonders whether perhaps TDSSKiller may have removed an infected system file perhaps? MGTools definately will not cause any damage as it's just a scanner, it makes no deletions whatsoever. Let me know what happened when and if you ran TDSSKiller as it was my very first instruction.
     
  21. bmatt

    bmatt Private E-2

    I did run TDSSKiller, but I believe I restarted in between the time I ran it and ComboFix, leading me to think it didn't cause it. I can't say with absolute certainty it didn't, but it did detect some "viruses" that did not fix the original problem, so it is possible.
     
  22. bmatt

    bmatt Private E-2

    I received confirmation on another forum that I will need to just reinstall Windows. If I backup all of my hard drive to an external drive, could any viruses (if any are possibly still active) on that backup affect my new install?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They could, so you should first do the backup, then reformat and do a clean install. Then install all your protections software and then do scans on the external drive to be sure it is clean before you reinstall the backups.
     
  24. bmatt

    bmatt Private E-2

    Ok, thank you!
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let us know how you make out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds