Yet another Google search redirect problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by davene, Feb 4, 2010.

  1. davene

    davene Private E-2

    Okay, apologies in advance because I can see that this type of problem is very very common at the moment, but no matter what I try I don't seem to be able to get rid of this issue.
    Basically I got the same problem as others have described i.e. Google search gave correct results but clicking on one of them took to me another site (other search engines etc).
    I've tried so many tools including Spybot Search & Destroy, Stopzilla, Sophos Rootkit Detector, and a couple of bootable anti virus CD's, not to mention that I had Norton 360 previously installed and resident (and still have).
    I've now followed the advice on the Read & Run Me, so have now removed old Java versions, installed the latest Java, and also used CCleaner, Super Anti Spyware, Malwarebytes Anti Malware, Combofix, Root Repeal, and MGTools.
    The problem now is that my laptop will no longer connect to the internet (although curiously Outlook still does and downloads e-mail etc), and the browser (Firefox) always tries to connect to a website called...
    The laptop no longer recognises that the DVD drive is a writer and uses it as a reader only, and any media loaded (CD's, DVD's or USB drives and memory sticks) don't auto run, but do open manually.
    I've attached the logs created by the various utilities, and would be grateful for any advice you can give.
    As a final point I ought to mention that Combofix identified rootkit activity when it started, and said it would reboot, but it just sat there for hours so I had no option but to manually reboot. The machine did reboot and Combofix then seemed to run through its scans as attached.

    Many thanks in advance.

    Dave
     

    Attached Files:

    Last edited by a moderator: Feb 9, 2010
  2. davene

    davene Private E-2

    Apologies, but I couldn't find the MGLogs.zip file, so attached this time.

    Thanks

    Dave
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\StopHid.exe

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. davene

    davene Private E-2

    Hi TimW,
    Many thanks for your help with this, it's greatly appreciated.

    Done - Norton 360 permanently disabled during the following

    Done. All went well.

    Done - All went well and the file merged successfully with the registry.

    Done - File deleted and emptied out of recycle bin. Machine was then manually rebooted.

    Done - Log file attached

    Internet explorer still not connecting, but I can see that whilst my homepage in the address bar is correct, the info at the bottom states that it's trying to connect to www.eatonvillerestaurant.com. It then times out after 10 seconds or so.
     

    Attached Files:

  5. davene

    davene Private E-2

    Sorry, I should have added that the same connection problem and same attempt to force the web page happens with both IE and Firefox in case it's helpful.

    Thanks again

    Dave
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not really seeing anything at the moment, but let's have you do this:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Since you have given Admin. privileges to all users, you also need to run SAS and MBAM on each user account.
     
    Last edited: Feb 9, 2010
  7. davene

    davene Private E-2

    Hi TimW,

    Thanks again for your help with this.

    Done - The program ran successfully but found nothing

    Log file attached.

    Thought that I had run these from the other accounts a few days ago, but ran them again just to be sure, after running TDSSKiller. No problem was found with either scan on either user account, but log files attached for ref.

    Any thoughts regarding the problem I had with Combofix originally i.e. that I had to do a manual reboot when it didn't do it automatically? Could this have caused a problem? Still have no internet connection from the PC (using another PC to post these), although Outlook still works fine for e-mails.

    Thanks
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open SAS and go to preferences / repairs. Scroll down to repair broken internet connection. Does that help?
     
  9. davene

    davene Private E-2

    Hmm..I don't have a repair internet connection in SAS preferences/repairs.
    There's a home page reset, which I've tried and the homepage is now trying to go to Microsoft, but still gets forced towards www.eatonvillerestaurant.com and times out. There's also a 'Reset URL Prefixes', and a 'Reset Web Settings' both tried and both had no effect.
    I've attached a couple of jpg's showing the web pages at startup and timeout so that you can see what I'm describing.

    Thanks once again.

    Dave
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    "Repair broken network connection" is what it should say.

    You can try also just uninstalling both IE and FF ( after you have downloaded and installed a different browser ). Then after reboot, reinstalling them.
     
  11. davene

    davene Private E-2

    Okay, I did wonder if that was the intent, but I've ran it now and rebooted as it recommended, but still the same problem persisted.
    I then uninstalled FF and IE8 and rebooted again. I then realised that IE7 was now installed (presumably resident in the OS of XP as there's no uninstall), and tried that - still the same result. I ran the 'Repair Network Connection' again and rebooted, but still the same.
    Finally I've tried reinstalling FF and running it, but still the same as previous.

    Any other thoughts?

    Thanks for your patience.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have cleaned out all your temp internet files, uninstalled and re-installed both browsers, tried downloading and using a totally different browser, then I suggest you post in the software section for further assistance as this would seem to be a non-malware issue. If going thru a router, reset it to factory settings. Then reboot and see if you can connect.

    Since you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds