redirect problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by metal_benji, Jun 20, 2010.

  1. metal_benji

    metal_benji Private E-2

    hi there im afriad its another one of those redirect issues.
    I keep getting pushed to random pages containing search results and ask jeeves etc its getting quite annoying now, i have run the read me, run me first sticky as this has cured a similair problem in the past but i still have the problem.

    i could also not run rootrepeal as an error message kept appearing then the program stopped working

    please find attached the logs from the other steps

    regards
    metal_benji
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the C:\MGLogs.zip --> from running the C:\MGTools.exe.
     
  3. metal_benji

    metal_benji Private E-2

    sorry forgot that one here ya go
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you set this:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

    If not, please follow these instructions:
    Change Proxy Settings.

    Now:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  5. metal_benji

    metal_benji Private E-2

    here you are as requested. i went through the proxy settings and its set within firefox (my defualt internet browser) to no proxy.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That scan didnt find anything. Are you still being re-directed?
     
  7. metal_benji

    metal_benji Private E-2

    yes unfortunately, i can still use all my saved bookmarks, thats how im getting back here each time but im still getting random google results windows and being redirected to yell and searchanalytics and then to some shopping website. puzzling isnt it?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run this: GMER - running with a random name and attach the log from GMER.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  9. metal_benji

    metal_benji Private E-2

    here it is .... there was no error message's during the procedure
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need to see a new MGLogs.zip. Are the redirects happening in all browsers?
     
  11. metal_benji

    metal_benji Private E-2

    tbh its only appears to be happening in firefox now although IE was redirecting me last night

    here is the new log
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still have this proxy server set:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    Did you follow the instructions for both IE and FF in disabling this?

    Are you running any disc emulation software? Did you follow these instructions:

    Step 6: Disable Any Disk Emulation Software (like Daemon Tools..etc)
    • If you skip this step, we may be just telling you to start the cleaning process over again! DON'T SKIP THIS STEP.
    • This is become a critical step before continuing the cleaning process. Disk emulation software is making it difficult to separate real rootkit like malware from valid software.

    If you are running emulation software, it would explain why the logs still indicate an MBR infection.
     
  13. metal_benji

    metal_benji Private E-2

    i have followed the instructions and there is nothing to change according to your guuide my settings in both ie and ff are the same as your pictures...

    i do have disk emulation software installed but it has been disabled with no emulation or virtual drive active while doing the scans..

    i have now used defogger steps to make sure that there is no interference whatsoever
     
    Last edited: Jun 21, 2010
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have run defogger, please attach a new MGLogs.zip.
     
  15. metal_benji

    metal_benji Private E-2

    here ya go
     

    Attached Files:

  16. metal_benji

    metal_benji Private E-2

    after downloading and installing the latest version of superantispware and updating it i ran a scan... the results came back with 148 infections in total cleared those and i no longer seem to be getting redirected however after a new mgtools scan the proxy you have mentioned is still there
     

    Attached Files:

  17. metal_benji

    metal_benji Private E-2

    sorry to post again but i AM still getting redirected
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You logs are no longer showing the MBR infection. No doubt caused by running defogger. I am not seeing anything that could account for the re-directs. Let's see if a little cleaning will help.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run CCLeaner and then run ATF Cleaner by Atribune.

    Are the redirects still happening, and if so, in which browser?
     
  19. metal_benji

    metal_benji Private E-2

    still getting redirected unfortunately by both ie and ff
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please log into the other user account and run both SAS and MBAM and then also run the MGTools.exe on that account as well. Attach the logs.
     
  21. metal_benji

    metal_benji Private E-2

    here they are, the other accounts were set up while trying to update my crappy phone if i delete them does it take any problems with them out of the picture?
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is nothing in your logs to indicate a malware problem. If you are still being re-directed, is it in every user account? Or is is only in yours?
     
  23. metal_benji

    metal_benji Private E-2

    It appears to be every time I open ff or ie and search for anything. I get random windows with search analytics and something about results5dotcom and then i end up on all manner of websites ... some tame ones like yelldotcom and others are a bit on the questionable side but they are less frequent.

    Im glad it doesnt appear to be malware.
    It does appear to be happening in all user accounts though but I am going to remove them as they were only set up to try something with my phone the other day and are no longer needed as I am the sole user of this machine
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may need to uninstall both IE and FF to remove this problem. ( If you need assistance doing that, post in the software forums ). After doing a complete uninstall, then be sure by running CCLeaner and then download the latest versions of both IE and FF> come back and tell me if that worked.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If not already done, I suggest resetting router settings back to factory defaults and then reprogramming for required network setup. Many recent infections are getting into routers. ;)
     
  26. metal_benji

    metal_benji Private E-2

    I have reset the router to factory settings this morning and re-entered all the info. I have been online for about an hour now and no redirects or extra search windows opening so fingers crossed this has solved the problem finally.
    thanks for the help

    Ben
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds