Google Redirect Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by plin02, Feb 10, 2009.

  1. plin02

    plin02 Private E-2

    In need of assistance...

    Last night I was on the web and my McAfee OAS caught several objects in a quick succession. Before I was able to respond, my computer restarted. I got a "green screen of death" but I dont' remember what it said. After a hard shut down, windows xp started up fine. I ran Malwarebytes, it found a bunch of trojans. I went through a rather odd cycle of restarts and rescans until I ended up with a clean scan. Somewhere in the process it appeared if my desktop had been restored to a point several hours ago. Anyway I left my computer on overnight running a complete scan, and found nothing. Yet this afternoon I realized my google searches were being redirected. I ran a bunch of programs I found online - fixwareout, atf cleaner, combofix - to name a few. Nothing worked so here I am... Please find my log files attached.
     

    Attached Files:

  2. plin02

    plin02 Private E-2

    and the last log:
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does this happen in all browsers? If it is only FireFox then do this:
    Read ALL of this and/or print it because you MUST HAVE all FireFox windows closed before doing it.

    Locate the below file using Windows Explorer.

    C:\Program Files\Mozilla Firefox\extensions\{03CA0C23-8373-4D0F-B276-2C11E0ED47FC}\chrome\content\overlay.xul

    Then right click on the overlay.xul file and rename it to overlay.BAD

    Now restart FireFox and tell me if you still have the problems

    Now use windows explorer to find and delete:
    C:\WINDOWS\nhtomqef
     
  4. plin02

    plin02 Private E-2

    First, the file
    C:\Program Files\Mozilla Firefox\extensions\{03CA0C23-8373-4D0F-B276-2C11E0ED47FC}\chrome\content\overlay.xul

    didn't exist, but I found a similar file under

    ...{A74A5975-95CB-4CA2-AAD0-FC7CFE706435}\chrome\content\overlay.xul

    which I changed to bad and seemed to fix the problem.

    I also the file
    C:\WINDOWS\nhtomqef
    didn't exist.

    What should I do next?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and delete that firefox file.....and tell me what issues you still have. :)
     
  6. plin02

    plin02 Private E-2

    Ahh.. that feels good.

    Renaming seemed to stop the redirecting, but firefox still felt sluggish.

    Deleting that file seems to make pages load faster.

    Haha, am I just imagining that?

    So am I all clean? How do I change my date-time settings back to normal (combofix didn't change it back)?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will do that now:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  8. plin02

    plin02 Private E-2

    Thanks a lot TimW!

    I did all the steps, but my time/date is still in military time and in year-month-day format. It's not a big deal, but if there's something I can do, please advise.

    Again, thanks for your help.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the control panel / Regional and Lang. / customize / time and change it to the format you want. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds