redirect malware rdsrv.com

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by judd, Jun 2, 2015.

  1. judd

    judd Private E-2

    I'm having an issue with redirects through rdsrv.com. bringing up malware, out of date software, and virus warnings. The three computers on my home network are all infected. This appears to have started when Mediacom replaced my cable modem last week.

    Before finding this forum, in the approximate order, I ran a virus scan with Avira, ran CCleaner, ran adwarecleaner, ran JRT, installed and ran Malwarebytes and Malwarebytes Exploit, ran Hitman pro. Thinking it might be related to browser add-ons I reset firefox, chrome, and ie to the default state. i deleted Firefox and chrome and all of the references to them i could find.

    I ran your Read Me First, the problem remains.

    Malwarebytes catches most of outgoing redirects on ie, every click brings up an attempt. On the other computers which still have Chrome and Firefox, the issue is not so bad with Chrome, and rarely happens with Firefox, which has no-script running.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    We require the below other logs requested in the READ & RUN ME
    • RogueKiller
    • Hitman Pro
    • Malwarebytes
    Also since you already ran JRT, we would like to see this log too.
     
  3. judd

    judd Private E-2

    Here are the other logs. Apparently I did not read the ReadMe closely enough, I thought the MG tool collected all the logs into MGlogs.zip
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a Poweliks infection so we need to run another scan tool to collect more information before continuing.

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.



    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please also attach it to your reply.
     
  5. judd

    judd Private E-2

    here are the files.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.

    Download this >> View attachment fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Is there any change to your problem with rdsrv.com?
    If you still have a problem, is it only with Chrome and Firefox? Test Internet Explorer to see but no matter which browser you test, only have one running at anytime when you test for this problem.
     
  7. judd

    judd Private E-2

    problem is as bad as ever, malwarebytes is not stopping the redirect anymore.

    ie is the only browser installed on this machine.

    Avira keeps turning itself on, and the computer is shutting itself off at night, even though I have the power controls set to never sleep or shut down.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's reset internet explorer to defaults. See the below:

    Reset Internet Explorer 9, 10, and 11 to Defaults


    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java(TM) 6 Update 20



    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. Also if it asks if you want to install McAfee Security Scan Plus that you uncheck this too. You do not need to add these unncessary items and to your PC. Also just in case Oracle changes the Java installation in the future to possibly install other junk, uncheck all but just installing Java.



    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\Sharon\AppData\Roaming\Mozilla
    C:\Users\Sharon\AppData\Local\Google\Chrome
    C:\Users\Sharon\AppData\Local\Temp
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
     
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.



    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    By the way, you said other computers also have this problem. I'm wondering if your router has become infected. Does your router have a reset switch on it that can be used to reset it back to defaults? This infection could have impacted your DNS server in your router. If you cannot reset your router back to defaults, it may help to use an open dns server like Googles or OpenDNS.
     
    Last edited: Jun 6, 2015
  9. judd

    judd Private E-2

    I'm still getting redirects. Malwarebytes rarely prevents the outgoing requests.

    I did reset my router, both with software and the reset button, plus power off/on before starting this thread. I can remove the router from the path if you think it necessary. This is an Asus RT-N56U that I have used for several years.

    I had some hope after JRT ran, shutdown and startup times were much much faster. on reboot after jrt, ie displayed google instead of the usual homepage, but wouldn't load the MajorGeeks page. ie showed a message to turn on
    tls 1.0, 1.1, 1.2 even though they were checked, so i reset ie and rebooted, which got ie loading pages again, but slowed the startup and shutdown times.

    after resetting ie and rebooting, ie shows a dialog to choose recommended settings. I don't know if this is normal.

    I notice that when a redirect happens another ieplore.exe *32 process starts, I don't know if that is significant, but they each take up about 100 megabytes of memory.

    when running the MGtools getlogs.bat Avira blocks the hosts file, I don't know if that is significant.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a try just to see what happens because it really seems like this is where your problem is.

    Yes it is.

    When you did this reset to defaults did you also do the below? If not, try again.

    If a new tab opens, another process will show.

    No it is typical and it is why many of our procedures say to disable protection when running them. Protection software commonly gets in the way of cleanup procedures.
     
  11. judd

    judd Private E-2

    i found i was not doing the router reset properly. i also found that Asus had a firmware update with improved password security.

    i installed the firmware update, reset the router with the hardware switch, and setup more secure admin name and passwords, including the wireless.

    this appears to have stopped the problem.

    Thank you for your help and your patience.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear we were on the correct track with pursuing a router infection.

    Please complete all of the below final instructions before running any other scans to avoid false detections of things we have already quarantine or left overs from system restore.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. judd

    judd Private E-2

    Thanks, problems have not reoccurred, i have made a donation.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Thank you!

    Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds