Google redirect virus is still here

Discussion in 'Malware Help (A Specialist Will Reply)' started by Devlish, Jun 5, 2010.

  1. Devlish

    Devlish Private E-2

    I am using Vista Ultimate. I ran the read & run first cleaning procedures. Things are better but not all fixed. I am not getting directed to new websites with every click but its opening a window with fake google page or at least it looks fake. I just close it.

    In process of running combofix I uninstalled zone alarm security suite and installed comodo internet security. I ran cpes cleaner. I reinstalled zone alarm and uninstalled it from the control panel. I reinstalled zone alarm and uninstalled it from the start menu. I manually removed files. I went to zone alarm forums and I deleted files and registry entries in safe mode per forum guru's instructions. I went to tech support and am waiting for their answer on how to get rid of all of zone alarm

    Every single time I tried to run combofix it says zone alarm on access scanner is still installed. I finally used it at my own risk.
     

    Attached Files:

  2. Devlish

    Devlish Private E-2

    Posting last log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below old versions of software:
    Java(TM) 6 Update 16

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} -
    O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} (Java Plug-in 1.6.0_14) -
    O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} (Java Plug-in 1.6.0_15) -

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Devlish

    Devlish Private E-2

    I am running MGtools right now.

    I have yet to hear back from tech support about the on access scanner still being there after uninstalling zone alarm. Can I still use combofix or should I wait to hear back from zone alarms tech support?

    I have Comodo installed now and it is no problem to turn off.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run my fix. It should remove some leftover SecurityCenter items belonging to ZoneAlarm.
     
  6. Devlish

    Devlish Private E-2

    Thanks, It was nice to know I could safely ignore the zone alarm warning.

    I had already uninstalled combofix so I redownloaded it and used you text file.

    After combofix ran I had to manually restart loging off was hanging for over 20 minutes. When I tried to open explorer after combofix finished running I got an error about registry entries slated for deletion and hand to restart again.

    The rest of your instruction worked great so far.

    When I hit the download link to download the java update google/fake google loaded in another window. I closed that and clicked the top of the window to allow downloads.

    I did an couple google searches and surfed some know safe sites.

    Google links seem to go right to the sight listed.

    The first time I clicked on to navigate a website it was redirected. Surfed for 15 minutes more. No redirects. Will update if I get more redirects.
     

    Attached Files:

  7. Devlish

    Devlish Private E-2

    OOPS!! I goofed and didn't run cc cleaner. Ran CC Cleaner and then re ran mgtools\getlogs.bat.

    New mgtools log attached.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Please let me know if you currently having redirect problems.
     
  9. Devlish

    Devlish Private E-2

    Thank you for all the help!! Its nice to know the logs are clean.

    I am having one small problem. I'm guessing one time in 10 when I hit a link a full size window pops up with google, yahoo, or another random site.

    For example, I was going to check email just a few minutes ago. I went to comcast.net. I hit the button to open email and instead what looked like the yahoo front page come up in a new window. I closed that window right away and hit the email button again. That time it opened my email in the same window like its supposed to.

    Nothing major but that is what the google links were doing for about 5 searches or so before the redirects got bad.

    Any help would be welcome as I find time I am running a full scan with comodo, spybot, and updating spywareblaster. I let you know if they come up with anything.
     
  10. Devlish

    Devlish Private E-2

    Just redirected again when I hit the download link to download an update for comodo from their site.

    Plus I think my last post was eaten I got a message that it needed moderator aproval if it shows up then you'll have the info twice.

    First thank you for all your help & I am very glad to know the logs are clean.

    I am not getting google searches redirected. I am getting random links that pop up a new window with google, yahoo, or random site. I was checking my email earlier today and a window opened with what looks like the yahoo main page. I closed it. Then I hit the same button/link again and got into my email in the same browser window as expected.

    I am running spybot & comodo scans then updating spyware blaster tonite. I'll post it if I get anything.
     
    Last edited: Jun 8, 2010
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then it is possible that you have a TDL3 aka TDSS aka Alureon infection that hides itself in valid system files which makes it harder to find. Based on the logs you previously attached, it did not look like you had any signs of this infection, but let's be safe and check. Also the symptoms you mention with not being redirected on Google make it sound like a non-TDSS infection.




    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    Do you have a router? When is the last time you reset it?

    Have you checked to make sure the DNS server setting for you network are valid?

    What browser are you using when these popups occur? Try a second/different browser (make sure the 1st browser is closed before)
     
    Last edited: Jun 8, 2010
  12. Devlish

    Devlish Private E-2

    I have a router and it was reset less than a month ago but I went ahead and reset it this evening. I'm curious why the router? Oh and in case you want to know its a linksys wrt54gs wireless g router.

    I tried to google it and got alot of technical info that is a little bit beyond me. I couldn't figure out how to check if the dns server is right. My ip address is correct and my WHOIS is accurate its showing comcast portland like it should. How do I check the server?

    I am using IE8. Updates are current. The google, yahoo, etc pop up with firefox too. I closed all windows and opened firefox and its still happening there. I am still testing Opera. So far nothing.

    The tdss killer found nothing or at least that is what it looks like. The logs are attached. I accidently double clicked it when moving the icon. Later I ran it correctly from your command.

    Nothing come up on comodo or spybot either both are clean scans. Adaware only found its normal ton of cookies.

    Where do we go from here? I can live with it if google just opens up occasionally and it stays that way. My worry is it will get worse again.
     

    Attached Files:

  13. Devlish

    Devlish Private E-2

    Within 10 clicks opera popped up gugle instead of google.
     
    Last edited: Jun 9, 2010
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your runkeys.txt log ( which is part of MGlogs.zip ) showed the below. Specifically see the items highlight in red
    Code:
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . : hsd1.or.comcast.net.
       Description . . . . . . . . . . . : Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 192.168.1.100(Preferred) 
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Lease Obtained. . . . . . . . . . : Sunday, June 06, 2010 9:40:30 PM
       Lease Expires . . . . . . . . . . : Monday, June 07, 2010 9:40:29 PM
       Default Gateway . . . . . . . . . : 192.168.1.1
       DHCP Server . . . . . . . . . . . : 192.168.1.1
    [COLOR=red][B]   DNS Servers . . . . . . . . . . . : 213.109.64.5
                                           213.109.72.21[/B][/COLOR]
       NetBIOS over Tcpip. . . . . . . . : Enabled
    
    I seriously doubt these are correct for you since they are in Russia.

    Try the below.

    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now let's see if that cleared them out.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. Devlish

    Devlish Private E-2

    I agree Russia would definitely be wrong. LOL unless its something bizarre comcast does.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the flush of the DNS server entries did not work. Thus the likely next step would be to check that your router has gotten infected.

    You need to follow the instructions for your hardware and reset it back to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    After doing this, see if your problem with redirects has been resolved. Also run C:\MGtools\GetLogs.bat again and attach the new MGlogs.zip file so we can be sure of the status.
     
  17. Devlish

    Devlish Private E-2

    I hit the reset button. Then I logged into the router checked the dns was still the same.

    I still don't know a program, method, or site to verify correct dns so I cheated and called my isp comcast.

    I tried to change the dns manually via logging into the router at its ip address but I don't think the first try stuck. It showed up with the wrong dns again. I ran mgtools\getlogs.bat. That is where mglogs1.zip is from.

    I unplugged the modem and router and then tried manually again. That time it stuck but I lost my internet connection. I had my modem reset from comcasts end.

    My connection came back. This time I'm sure the manual dns change stuck so I ran mgtools\getlogs.bat again. That is where mglogs.zip is from. I am attaching both logs.

    So far that seems to have worked. I am not sure what the problem was but could my modem have become stuck/infected. I used the reset button on it and uplugged everything and did the full restart thing myself before calling comcast. Whatever they do is the only thing I know of that unstuck the dns and got my connection working.

    I think I got rid of a few programs I had installed to try different defraggers after the dns was fixed but I may have uninstalled them before. It got a little late on me the memory gets foggy.

    I'm sure I'm probably proving just how little I know but I'm curious so I know what to look for if this should ever happen again.

    Thank you again for all of your time and hard work. I can't thank you enough.

    So far no pop ups, no redirects. I'm crossing my fingers that it stays that way.
     

    Attached Files:

    Last edited: Jun 10, 2010
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the new version of MGtools and run it. Then attach the new MGlogs.zip file. This new version checks a few additional registry locations and I want to be sure your infection is gone.
     
  19. Devlish

    Devlish Private E-2

    Okay, downloaded new version and ran it.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds