Internet Explorer/Google Search Redirects

Discussion in 'Malware Help (A Specialist Will Reply)' started by zamorazeke, Jul 20, 2009.

  1. zamorazeke

    zamorazeke Corporal

    Continually getting redirected when clicking on Google search results in Internet Explorer. Started about 2 weeks ago when offered a "free" video player. I have run through the primary steps to get logs as directed. Some of the programs (malwarebytes...) would not run, but I continued with those that would run. I am attaching resultant logs and records, and I will follow directions to best of my ability and give many thanks to anyone who will help:confused.
     

    Attached Files:

  2. zamorazeke

    zamorazeke Corporal

    :-oActually, the combofix text is an old one... it wouldn't work today when I tried to use it...my mistake.
     
  3. zamorazeke

    zamorazeke Corporal

    In addition, I have run an infection search with SmitFraudFix, and am attaching those results.:(
     

    Attached Files:

  4. zamorazeke

    zamorazeke Corporal

    :wave Also, I forgot to mention that I stepped through the TDSSserve procedures when Malwarebytes and ComboFix wouldn't work, and the TDSSserv rootkit driver was not present to disable. Hope this additional info is useful. Many thanks to anyone who might read these logs and direct me in solving this problem.
     
  5. zamorazeke

    zamorazeke Corporal

    :cool Finally...got both Malwarebytes and ComboFix to work on this computer and am attaching their respective logs to this post. I am hoping, once again, that this will add to the evidence that someone can use to help me get this machine clean. Many thanks in advance.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It is 2 years out of date and of no use to us.


    Please double-click the RootRepeal.exe previously downloaded.
    • Select File then Scan
    • On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    • When the scan is complete - highlight each of the following file(s) if any still exist since you have run MBAM and the new ComboFix in between (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
      • C:\WINDOWS\system32\MSIVXcount
      • C:\WINDOWS\system32\MSIVXqhoylkdmxttkgnyrrciyojgpjuwqppas.dll
      • C:\WINDOWS\system32\MSIVXwusribgetymfgfwkwbwdtfrbemrwkthb.dll
      • C:\WINDOWS\system32\drivers\MSIVXmufxuxdqllxsmpuxryvcjexmbfxtvnri.sys
      • C:\Documents and Settings\Dan\Local Settings\Temp\MPSampleSubmit\msivxmufxuxdqllxsmpuxryvcjexmbfxtvnri.sys.xor
      • C:\Documents and Settings\Dan\Local Settings\Temp\MPSampleSubmit\msivxqhoylkdmxttkgnyrrciyojgpjuwqppas.dll.xor
    • After Wiping all files, immediately reboot your pc!
    After reboot, rerun Malwarebytes and ComboFix!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the Malwarebytes log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. zamorazeke

    zamorazeke Corporal

    :-D Thank you so much for responding so quickly to help me. I have attached the logs you asked for, and I will gladly continue to follow any directions you give based on what you find.

    It appears the DNS changer is not hijacking Internet Explorer browser windows or Google search inquiries any more (fingers crossed), nor am I having trouble with constant pop-ups that came along with all that other stuff.

    The only differences now are that my toolbar clock is displaying in 24-hour mode. Also, when booting up, Zone Alarm seems to take forever before it will allow anthing else to function on the computer. It seems to take alot longer for the computer to do a cold boot (Zone Alarm's hogging) than before these problems. Do you think I might need to change some settings in Zone Alarm?

    Once again I thank you so much for your help and direction, and I am looking forward to hearing from you soon.
     

    Attached Files:

  8. zamorazeke

    zamorazeke Corporal

    In addition, when clicking to open the Internet Explorer 8 Icon, it seems a double copy of IE8 opens (according to the processes window in Task Manager).

    I am not able to delete a history of search terms in "Google Search" for IE8. They (the past search terms) all show in a drop down list whenever I begin to type a new Google search term -- even after having tried to delete the old ones by going to IE8's "Tools>Delete Browsing History> ...and checking all boxes.

    Sorry I didn't include this in my initial reply to you earlier this evening.

    Thanks again.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This happens when ComboFix has been run and has not finished running properly. This is just a system setting you can change from Control Panel. If you still have it set wrong after the next fix then tell me and we will fix it.

    ZoneAlarm has long been quite resource intensive and causes slow bootups. Whether it has somehow been corrupted by malware I cannot say. You could always try uninstalling it, rebooting, and then reinstalling to see it it helps. However perform the next fix below before doing anything else.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below are questions you should be asking in the Software Forum, but I will answer them (this time ;) ) here. Any additional non-malware questions should be posted in the appropriate forum.

    Normal for IE8 since it uses tabs. If you open a second tab, you will see 3 iexplore.exe processes.

    Browsing history is not the same as search history. If you want to clear Google search history you need to click on the Google search pull down arrow and select View History and then click Clear History.
     
  11. zamorazeke

    zamorazeke Corporal

    :wave Thanks (again, alot) for your help. I have attached the logs you asked for, and I am looking forward to finding out how things have improved.

    I haven't worked on the computer since doing the operations to get the logs, but it feels like the computer is "getting healthier"...will know more when you look at things.

    Thanks also for clarifying the m.o. of IE8 and the method for clearing Google search history. I'll make certain to ask the right questions in the right forums in the future.:-D

    My time display is still in 24hr. mode, but that is the least of my worries at this point.

    Logs attached; best regards.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    Quite simple to fix and something you should know how to do anyway. ;) The below will teach you.:)

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. zamorazeke

    zamorazeke Corporal

    :) I am working through the assigned uninstall tasks; thanks for directions to change time display.

    However, even though I installed ComboFix on my desktop as directed, there is no place to click START then RUN and get a run box to enter the code to uninstall the program. At least I don't see anything other than the icon to click on, then it starts and says it is preparing to run...

    Meanwhile, until I can figure out how to uninstall ComboFix :confused, I will continue with the rest of the tasks. Many thanks.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start and Run are Windows items not ComboFix.:) Look at the lower left of your screen. ;)
     
  15. zamorazeke

    zamorazeke Corporal

    Thank-you for clarifying the ComboFix uninstall...:-o Seemed so simple after doing it. I guess I was making it too complicated.

    Everything seems to be running alot better now, especially Internet Explorer. Also, because I get automatic windows update notifications, I installed the latest patch of (holes in) IE 8 after having done everything else on our list.


    There is only one problem remaining that came about during this malware removal marathon. :)(Please let me know if I need to go to another forum to address the following, and I will be glad to start another thread elsewhere.):)

    I can print anything/everything when I'm logged on to my account. My wife cannot print anything at all when she is logged on to her account. From MY account we can print any/all those things in my wife's account that she cannot print from HER account.

    :-o I tried to find out if printer settings might have been changed but got confused again. :confused Sorry.

    Please let me know if I need to move to another support forum, and many thanks for rescuing my (our) computer.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    I suggest that you post this in the Software Forum but here are a few tips. Sounds like a permissions issue of some sort. Is your wive's user account a restricted user account? If so, first try changing to an admin account and see if anything changes. Also make sure when her account runs that the Print Spooler service is running (the spoolsv.exe process). Please continue this in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds