Here's my log

Discussion in 'Malware Help (A Specialist Will Reply)' started by provobis, Mar 15, 2010.

  1. provobis

    provobis Private First Class

    Since there are evidently several kinds of redirect viruses, not sure gooredfix is the right way to go. When I use Google search in Firefox and click on results I will be redirected to what appears to be spam type solicitations to buy or use, or otherwise alternate places related to my search (but not what I wanted). Seems like gooredfix is the right tool so i posted my log here.

    I've seen advisories that if I have any redirect virus, and use on line banking and such, that I should immediately go off line and reinstall because the virus would have compromised identity or security, instead of just trying to remove the virus. Anyone know if that's good advice?

    I'll be very anxious to get some input, advice, and direction.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nope... I doubt that will help you in your case. Do the below:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Then continue on with the following:

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. provobis

    provobis Private First Class

    Kestrel12! Evidently something went wrong in the first part after I copied/pasted the following bold command into Run box and hit Enter. There were no instructions and the field disappeared. So before I continue with the "welcome to Major Geeks" part I'll wait for your advice.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Check your c drive for a log called something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt. If no log is present then just go ahead and continue the other instructions. :)
     
  5. provobis

    provobis Private First Class

    Did (already) check C drive..... no log so I'll continue with the other instructions, thanks :-o
     
  6. provobis

    provobis Private First Class

    I'm back! Kestrel13!....did everything from malware removal through running the (five antispyware/malware applications.
    Tried a few searches with Firefox/google but still getting the same redirecting bull---- Am I going crazy, do I actually have a virus, or have the search engine/browser wars resulted in this kind of hijack internet baloney (in other words is it normal?). The search results that are coming back are sometimes related to my search key words and sometimes not. Sometimes it would appear that the virus(?) has redirected me to a competitive page, product, service, or directory. Anyway I'm posting the text files as you indicate, using two posts because of the five files.
     

    Attached Files:

  7. provobis

    provobis Private First Class

    And here's the fifth
     

    Attached Files:

  8. provobis

    provobis Private First Class

    One thing more...I did use spybot as well as AVG free before and now. When I ran spy bot before I always came up with threats called "fraud.windows protection suite" (15 entries) and Microsoft.windows.redirected hosts (3 entries). however when fixing those problems spybot says "unexpected error in fixing problems, cannot create file C:\windows\system 32\drivers\etc\hosts access is denied" So I always assumed those were legitimate windows programs that could not be accessed and that spybot mistakenly thought they were threats. Now I'm not so sure and running spybot again now I get the same result. Could that be the trouble? And if so why didn't the malware cleaning get them?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you ran MGTools you neglected to agree to the Trend Micro HijackThis agreement. I think at this point it would serve us well for me to see a log from running it. So a little further down I will have you re-run MGTools, this time agreeing (there's a bug and you have to hit "accept" twice)

    You are not currently being protected by any antivirus, so ideally you ought to install some, but first let's do this:

    Freez FLV to AVI/MPEG/WMV Converter <--- I would advise you to uninstall this software, there are much better alternatives and this one's a bit shady.

    Now use windows explorer to locate and delete the below bold file:
    Now double click the C:\MGTools.exe again and remember to agree to HJT.

    Attach the C:\mglogs.zip into your next reply.
     
  10. provobis

    provobis Private First Class

    Here's my (mglogs.zip) log. However I think I messed up. If so sorry. I needed to use the computer and did not want to do so with the settings made to do the original cleaning process for this geeks procedure. So Now when I run MGtools.exe I get this message:

    FOR SOME REASON YOUR SYSTEM DENIED ACCESS TO THIS FILE, HIJACK MAY NOT BE ABLE TO FIX THIS.F THAT GAPPENS YOU NEED TO EDIT THE FILE YOURSELF. RUN & TYPE NOTEPAD C\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS and press enter. find the lines Hijack this reports and delete them. Save the file as "hosts" (w quotes) & reboot.

    In any case the message has no "accept" I can click twice, only "OK".

    Will I have to repeat the entire procedure? Sorry but this is getting difficult to do with my necessary daily online business and i could not put it all on hold...had to continue working while I was waiting for your reply.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's got it... and I can see what needs to be done... hang on and I'll post a fix.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. You have spybot S&D's Teatimer function running which will probably interfere with our fix, please refer to the below before we continue:

    How to disable Spybot's TeaTimer

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT

    3. Now run this-

    Running HostXpert to Reset Default Hosts File

    4. Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  13. provobis

    provobis Private First Class

    OK, first in step 2 (Run C:\MGtools\analyse.exe) I got an error message in the procedure which said "cannot create file C:\windows\system32\drivers\etc\hosts". But I proceeded with everything anyway after that message. Also in the various steps I was still getting other error messages which I ignored to the end.

    I posted the MGlogs.zip file and tried some searches using Firefox/google and it seems I'm getting the pages I request, and no redirect so far.

    Question(s). You recommend installing antivirus programs but I thought I already had that with AVG (free). Is that not sufficient or in your opinion is there something better.
    I was also using spybot but I'm not sure it was doing a good job. I have now reinstalled AVG but will use whatever you recommend. I also use the Windows firewall but if you think something else is better please advise.
    If there's anything else please do advise further. I'll keep my fingers crossed otherwise. Thank you! ;)
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry, ignore my comment about the AV. Please complete my last instruction and attach the latest C:\mglogs.zip :)
     
  15. provobis

    provobis Private First Class

    Sorry, I thought I had attached that in completing your last instruction. Trying again (MGlogs.zip)
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you complete the step where I asked you to run HostXpert? (I see it downloaded to your desktop) But it looks like you either didnt actually run it or something went wrong. If so we will try another way.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  18. provobis

    provobis Private First Class

    OK to this last procedure...file attached, but I got two error messages

    FOR SOME REASON YOUR FILE SYSTEM DENIED WRITE ACCESS TO THE HOST FILE etc, etc during the process which I ignored so i don't know if I was able to do everything you indicate.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Dammit! Try this please. :)

    Reset Host File

    • Open Notepad.
    • Copy and Paste everything from the Code Box below into Notepad: (Do not include the word Code:)
      Code:
      @Echo off
      pushd\windows\system32\drivers\etc
      attrib -h -s -r hosts
      echo 127.0.0.1 localhost>HOSTS
      attrib +r +h +s hosts
      popd
      del %0
    • Go to File >> Save As
    • Save File name as FixHosts.bat
    • Change Save as Type to All Files and save the file to your Desktop.
    Now double click on the desktop FixHosts.bat to run the batch file. It will self-delete when completed.[/QUOTE]

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. provobis

    provobis Private First Class

    SAME MESSAGE FROM HIJACK THIS BELOW

    "FOR SOME REASON YOUR SYSTEM DENIED ACCESS TO THE HOSTS FILE. IF ANY HIJACKED DOMAINS ARE IN THIS FILE, HIJACK THIS MAY NOT BE ABLE TO FIX THIS. IF THAT HAPPENS YOU MAY NEED TO EDIT THE FILE YOURSELF. TO DO THIS, CLICK START, RUN, AND TYPE NOTEPAD C:\WINDOWS\SYSTEMS32\DRIVERS\ETC\HOSTS AND PRESS ENTER. FIND THE LINE(S) HIJACK THIS REPORTS AND DELETE THEM. SAVE THE FILE AS "HOSTS" (WITH QUOTES) AND REBOOT.

    But I'm attaching the new MGlogs.zip file anyway. While I have the opportunity without bumping, I should advise you that whatever I did according to your previous instructions screwed up my wireless connection so that I could not connect with another computer on my wireless network. I was able to reconnect by logging into my wired computer, re-setting the configuration, and reconnecting. This was yesterday, but this morning before your message the connection was gone again. Looks like I'll have to reinstall Linksys and reconfigure. Hope there's nothing in what we did that will prevent success.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    and just to clarify... you did run the batch file, right?
     
  22. provobis

    provobis Private First Class

    Yes I did. BTW I still have redirects.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, I realise that :( You'll have to hang in there for a little while because my shift at work starts soon and I will have to think of other options for us to go about tackling the problem.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    also make sure your PC is in normal start up mode by using msconfig.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Last edited: Mar 20, 2010
  26. provobis

    provobis Private First Class

    OK, done, zip file attached, this time no error message. :-D
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's done it ;)

    Use windows explorer to find and delete the below bold file:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  28. provobis

    provobis Private First Class

    Done. Thank you kestrel13! Looks good so far. FYI I've uninstalled AVG free and windows firewall and installed Comodo Internet Security. Do you think those will be sufficient/enough or should I add others? I also used CCleaner regularly and still have it installed. Think I now have enough protection against this and other malwares?
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you should be ok. :)

    Take care and safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds