google redirect

Discussion in 'Malware Help (A Specialist Will Reply)' started by renny, Dec 16, 2009.

  1. renny

    renny Private E-2

    Not all but 1/5 (just a guess) links i open in Google are redirected to a website that Avast says is a virus so abort connection. Ive done all the stuff it says to do tried GooredFix still no luck. Done Avast, MBAM, SUPERantiSpyware and Spybot Search and Destroy 3 times each says ive found a few viruses but im still getting the problem. Im not that good with computers just to let you know
    As you know Combofix is down so i cant use that to get a log.

    Thanks in advance.
     

    Attached Files:

  2. renny

    renny Private E-2

    Ive been looking at other posts and i saw a few asking for GooredFix so heres the log. I dont think its working right the command box pops up then closes and a window pops up asking if i want to scan and fix or exit.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we start:

    Please put this machine into normal start up mode if you haven't done so already by using MSConfig.

    Please ensure that MGTools.exe is indeed sitting right on your c drive and not anywhere else like below:

    C:\Users\Renny\Desktop\MGtools.exe


    1. GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.

    Now delete the current mbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    
         "%userprofile%\desktop\mbr.exe" -f
    
    Now double click on the mbr.exe file and attach the new mbr.log


    2.
    • Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.
     
    Last edited: Dec 19, 2009
  4. renny

    renny Private E-2

    Ok heres the logs you asked for but i got a bit lost on the mbr logs, you wanted 3 right log1 is just double clicking it it log2 is from using run and log 3 is after using run just double clicking it again.
    I moved MGtools to C:\
    Thanks for the help.
    sorry for being so late
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. And how is the machine behaving now?

    2. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    3. Run the new MGTools.exe and attach the C:\Mglogs.zip into your next reply here.
     
  6. renny

    renny Private E-2

    Its looking good just did 40 or so links and none got redirected.
    Thanks for the help heres the log.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. I see you ran combofix on the 19th december, the log from this exists on your c drive. I would like to take a look at that if you do not mind. Attach it into your next reply please.

    2. Download the MBR Rootkit Detector to your desktop.

    • Doubleclick mbr.exe and follow prompts.
    • A black DOS window will quickly appear then disappear.
    • When mbr.exe is finished it will create a log on your desktop.
    • Copy and paste contents of that log file to your next reply.

    3. Delete the following folder from the beta version of combofix also on your c drive:

    C:\KittyFix

    4. Now download the current non beta version of combofix

    5. Run it as per the instruuctions in the below link and attach the log it generates into your next reply here.

    Vista Cleaning Procedure

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. And attach the log from running the combofix beta, and the log from MBR Rootkit Detector.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now! :)

    Thanks
    Kes13!
     
  8. renny

    renny Private E-2

    I think you've done it, there isn't anymore redirections.
    Ill keep going to random google links to see if i still have it but its looking good:-D
    Theres the logs you asked for, but when you said ComboFix is out of beta the notification pops up saying its still in beta just thought i would let you know.
    Thanks again.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)

    Did you do my step #2 post #7? If so please attach the log from doing so.
     
  10. renny

    renny Private E-2

    Ahh sorry i did it just didn't upload, i tried just then and it said
    upload errors
    mbr.log:
    You have already attached this file in thread : google redirect

    Its a small log so ill just put it in code.
    Code:
    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
    
    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK 
    
    Thanks again
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Almost there just a little way to go :)

    1. We need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    FCopy::
    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys | C:\Windows\System32\drivers\atapi.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableRegistryTools"=-
    "DisableTaskMgr"=-
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    2. Could you please get this: tsk_atapi.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following: be sure to scroll all away across the code box

    Code:
    %systemdrive%\MGTools\zip "%systemdrive%\collect.zip" c:\windows\system32\drivers\tsk_atapi.sys
    log retrievable @ C:\collect.zip

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and the C:\collect.zip

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Thanks
    Kes13!
     
  12. renny

    renny Private E-2

    Here you go.
    It seems like you've got rid of the redirection virus done 100 or so random google links and none have been redirected but if you see other wise lets keep going. Just followed your instructions and all worked easy.
    I just did a google search of tsk_atapi.sys and it looks like its part of the redirection virus.
    Thanks again
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi ya. Let's see what Jotti says about it.

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\system32\drivers\tsk_atapi.sys
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
     
  14. renny

    renny Private E-2

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome :)

    edit: do not use my last CF script that i just deleted from this post. I need to speak to chaslang. Thanks
    If you already ran it let me know.
     
    Last edited: Dec 21, 2009
  16. renny

    renny Private E-2

    Nah i didn't see it thanks for all the help, hope i don't have to come back :)
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I won't keep you waiting long, but I really would rather ask Chas about that file we uploaded to jotti for scanning before I have you do anything with it.
    Thanks for your patience.

    Kes13!
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The file is just something from TDSSKiller :)

    You can safely delete it:
    Your logs are clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. renny

    renny Private E-2

    Well I deleted C:\Windows\system32\Drivers\tsk_atapi.sys and went to make a new restore point but now I cant turn my computer on but I can get to cmd. I don't have any restore points to restore to. Windows Repair says that its used for boot and says its corrupt. I can also use some restore with a image but I don't have any images.
    Hope you can help with this.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you have already uninstalled MGtools? Is the collect.zip file still in your root folder? Also after deleting the tsk_atapi.sys file, had you emptied the Recycle Bin. If not, perhaps there is a way to copy the file out.
     
  21. renny

    renny Private E-2

    yea I deleted MGtools. tsk_atapi.sys I think it may still be in the bin, I got rid of collect.zip as well.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From the command prompt enter the below black bold print commands. The purple text is informational and questions

    cd C:\$*

    There is a space after the cd. And yes that is a slash, dollar sign followed by an asterik. Does the prompt change to C:\$Recycle.Bin>
    If yes, do the below.

    dir /s

    Do you see a list of folders and files and does one of them end with a .SYS and is it 21,584 bytes in size? If yes, what is the filename and what folder is it in?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Darn!!! I forgot you had Vista. Vista compresses the files into the Recycle bin so it will not be 21,584 bytes. It will be something like 544 and it will be a random name followed by the .sys and it should have the date from yesterday ( 12/21/2009) when you did the delete.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry!!! It seems that Vista actually creates two files for each one deleted. So one of the .sys file will be 544 bytes and the other will still be 21,584 bytes which is the one we want.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you have not answered for over 30 minutes I will have to assume you have gone offline or you had a problem.
     
  26. renny

    renny Private E-2

    Ok i just did what you said but

    cd C:\$*
    nothing happens

    dir /s
    lists lots of files
    650 dir(s)
    2500 files
    but will only show 200 lines in cmd and none of those files are .sys
     
  27. renny

    renny Private E-2

    I have to go to my mates house to reply so im taking a bit
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah!! How far is this?

    Since there are so many files in the Recycle Bin, it would seem likely that you have not emptied it in a while and I would expect the file to be there. There should be folders for each user and the one with the most recent date is where I would expect to find the file. Try the below.

    First get back to the C:\$Recycle.Bin folder if not still at that prompt. Then enter the below command which should show some folder names:

    dir /as

    This should show some folder names like S-1-5-21-xxxxx....etc where the xxxxx is variable. Find the one with the most current date and tell me what the first 8 characters of the xxxxxx area are.

    What you will be trying to do is a cd into this folder and a command like the below would do this. The * allows you to not have to type in the full folder name which is very long. You just need enough xxxxx characters to distinguish the correct folder name from others. Obiously the xxxxx has to be substituted with the correct numbers.

    cd S-1-5-21-xxxxx*

    Once you get into this next level folder, your prompt will now change to show it. Like C:\$Recycle.Bin\S-1-5-21-xxxxx >

    Then you can do the below command to see only sys files:

    dir *.sys


     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And I'm betting that your Recycle bin folder for your user account would be the below

    C:\$Recycle.bin\S-1-5-21-720296051-3918678802-2006979960-1001


    And something else just occurred to me that may work since it is a command prompt! At the C:\$Recycle.bin> prompt. Just type the below.

    dir /s *.sys

    This may show the correct 21,584 byte .sys file
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since it takes you a long time to go to go back and forth from your house to your friends, I will try to stay ahead of you and give you what may be the next steps. Also if this does not work out tonight, perhaps it would be easier to just bring your PC to your friends house to work thru steps like this. I could save a bunch of time.

    NEXT POSSIBLE STEPS,

    If my assumptions are correct about your account's Recycle bin folder name and you locate the .sys file then the below copy command should be able to restore the file:

    copy C:\$Recycle.bin\S-1-5-21-720296051-3918678802-2006979960-1001\$RGTPOEL.sys c:\windows\system32\drivers\tsk_atapi.sys

    You should get a 1 file(s) copied message if it gets copied. Note that I just assumed a filename ( the $RGTPOEL.sys ) yours will be different but the file size should be 21,584 bytes and the date should be from when you deleted it.

    Then you need to do the below to verify you really got it copied to the correct folder with the correct file name.

    dir c:\windows\system32\drivers\tsk_atapi.sys

    Does it show up? If yes, then see ifyou can reboot normally.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we will have to continue later since it is heading towards 3 AM my time and I need some sleep.

    See how far you can get with my previous messages.
     
  32. renny

    renny Private E-2

    I think I deleted tsk_atapi.sys and in cmd I cant get to the recycle bin folder.
    I tried some of my own like dir c:\$recycle.bin *.sys but says its empty.
    dir c:\windows32\drivers *.sys didn't find tsk_atapi.sys
    dir c:\windows32\drivers tsk_atapi.sys nothing found

    I have an idea if I plug my hard drive into another computer and download collection.zip off this site and put it in myself. But I don't want to take my comp apart unless I have to. I had a quick look at taking it out it looks easy but the power cord in directly into the psu.
    Thanks for all the help.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are not the commands I gave which is why they are not showing anything. In fact they are not even valid commands. You have to enter the commands exactly as I gave them. You first have to change directories into the c:\$recycle.bin folder like I previously instructed you using

    cd c:\$recycle.bin

    The prompt would then change to c:\$Recycle.bin> and now you could just do the below command.

    dir /s *.sys

    This would show all .sys files in all folders under the $recycle.bin folder.
    Once you find the correct file name, you can substitute it into the command below which was what I gave in my last message last night:

    copy C:\$Recycle.bin\S-1-5-21-720296051-3918678802-2006979960-1001\$RGTPOEL.sys c:\windows\system32\drivers\tsk_atapi.sys

    Then you would do the below to see if really copied. Notice the exact command!!!!!! There is another \ before the tsk_atapi.sys which you did not enter in your above stated examples.

    dir c:\windows\system32\drivers\tsk_atapi.sys

    You can do this if you wish but it would only be necessary if you cannot find the file. Since you have not run the commands properly yet, we don't know if the file is there or not. Also note that you would have to download the collection.zip file to your friends computer and then extract the tsk_atapi.sys file from the collection.zip file. Then you would have to copy or move the tsk_atapi.sys file into the x:\windows\system32\drivers folder. I say x: because the driver letter of your hard disk slaved in another computer would not be the C drive. It would be the next available driver letter so it could be anything.
     
  34. renny

    renny Private E-2

    cd c:\$recycle.bin wont change the directories all that happens is

    so I tried changing the directories to something else I tried c: as a test and I get
    so I don't know if that's doing anything.
    x:\windows32\system> may not bet right but you get the idea.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If x is your drive letter than you need to replace the c with x. Thus, cd x:\$recycle.bin

    But I would expect it to be drive c not x
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just checked back thru your logs. Apparently you are using Windows 7 not Windows Vista. There could be major differences to the file system just like Vista changed from XP. Thus I'm not exactly sure what it calls the Recycle Bin now. However if you first just change to the root ( the highest level folder ) using the below:

    cd \

    The prompt should change to c:\> assuming drive c
    Then run the below command to see system folders

    dir /as

    This should list all the system folders. One of them should be the Recycle Bin so we can see what it is named. In Vista you would see the $Recycle.Bin folder spelled exactly like this. You would see a <DIR> to the left of it. The <DIR> means directory which is the same as a folder.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have to go to your friends house to communicate, you should pack up your PC and take it there or you should try to borrow a PC to use to work this out. It is taking to long for us to communicate this way. And if I don't notice you online, you would be waiting 2 to 3 days in normal queue time just to get one reply from me every time I need to reply.

    The other alternative which could prove faster for you if you can do it, is to remove the hard disk and get the file copied back properly using another PC with your hard disk mounted as a slave.
     
  38. renny

    renny Private E-2

    My drive is c but its says x in the cmd and yes I have windows 7. Ill try post #36 if that doesn't work I think ill just take my HD out.
    Thanks for all the help.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the command prompt window is really showing x:\windows\system32> for your prompt and not c:\windows\system32> then you need to use x whereever I used c.
     
  40. renny

    renny Private E-2

    Ok i've got it to work by taking my HD out and putting in mates computer.
    Thanks for all the help.
    Turns out that it is all still in the bin. :cry
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Okay so is your computer booting up okay now?
     
  42. renny

    renny Private E-2

    Yep i got it to work fine now. Took a hour of fiddling around to get it to get the HD out but got there in the end.
    Works fine now no sign of virus as well.
    Thanks for all the help.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds