Malware got me down!

Discussion in 'Malware Help (A Specialist Will Reply)' started by jamiesc, Aug 8, 2010.

  1. jamiesc

    jamiesc Private E-2

    Part 1 of 2

    I am having a heck of a time getting this figured out.

    1) It seems I have a Google redirect virus/malware when I use IE.

    2) Whatever it is, it is now re-directing my Mozilla Firefox.

    I have followed your Malware Read Me and Vista Clean Up Read Me about 4 times.

    Note I am not posting SuperMalWare log b/c nothing was infected and no log seems to have been generated.

    I cannot figure where this thing is and how to clear it! Please help.

    Thank you!
     
  2. jamiesc

    jamiesc Private E-2

    Malware got me down! 2 of 2

    Part 2 of 2

    I am having a heck of a time getting this figured out.

    1) It seems I have a Google redirect virus/malware when I use IE.

    2) Whatever it is, it is now re-directing my Mozilla Firefox.

    I have followed your Malware Read Me and Vista Clean Up Read Me about 4 times.

    Note I am not posting SuperMalWare log b/c nothing was infected and no log seems to have been generated.

    I cannot figure where this thing is and how to clear it! Please help.

    Thank you!
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your SAS log.txt is located here:
    C:\Users\<insert your user account name>\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs

     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also refrain from creating multiple threads across the malware forum. Attach the logs Dr M is requesting into THIS thread here only. :)
     
  5. jamiesc

    jamiesc Private E-2

    Thanks Dr. M and Colleagues:

    I am attaching the SuperMalWare log now.

    Did my other 5-6 logs get uploaded? I am not sure how to verify they were uploaded correctly.

    Thank you,
    Jamie
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I'm afraid not. After browsing to the file(s) you which to attach > clicking "Upload" > you should see what has been successfully attached by noting what's listed under "Current Attachments".

    dr.m
     
  7. jamiesc

    jamiesc Private E-2

    Dr. M:

    Here is 1 of 2 messages for attachments again.

    Thanks, Jamie
     

    Attached Files:

  8. jamiesc

    jamiesc Private E-2

    This is the file email (2nd attempt to upload) with the final document.

    This jpeg is a warning dialog box that popped up during the RR run. I thought it may be important so I am posting it just in case.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    jamiesc

    I am currently reviewing your logs and will get back to you with a set of instructions as my free time permits.
    Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  10. jamiesc

    jamiesc Private E-2

    Thank you, Dr. M.

    Please let me know if you need anything else.

    Your expertise is much appreciated.

    Jamie
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, jamiesc.

    *Delete this as it isn't located where instructed and no longer needed:
    c:\Users\James\Downloads\MGtools.exe

    Step 1: Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Now flush your caches:
    To flush the IE cache
    1. From the Safety menu in the upper right, click Delete Browsing History... .
    2. Deselect "Preserve Favorites website data", and select "Temporary Internet files,
    Cookies, and History".
    3. Click Delete.

    To flush FireFox cache
    1. From the "Tools/Options/Advanced/Network/Offline Storage" menu
    2. Click on the "Clear" button.
    3. Click on "OK" to close the window.

    To flush Java cache
    http://www.java.com/en/download/help/plugin_cache.xml

    To flush DNS for a computer running Windows, please follow these steps:

    Windows Vista
    1. Click the Vista icon to display the Start menu.
    2. Click the Command Prompt option.
    If that option is not available, type cmd in the search box at the bottom and press Enter.
    3. Within the prompt, type ipconfig /flushdns.
    4. Hit Enter
    5. Exit the command window

    Step 3:
    Running HostXpert to Reset Default Hosts File
    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited: Aug 9, 2010
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No need! They are already in MGlogs.zip ;)
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Thanks, chas! :-D
     
  14. jamiesc

    jamiesc Private E-2

    Dear Dr. M.:

    This did not go as well as I had hoped! I had a problem with HostXperts and 2 problems still exist.

    The issues that still exist:
    1) When I search from the upper-right Google search box in IE, I get re-routed to http://search.search-star.net/index...ch-star.net/?sid=10101040100&s=this+is+a+test

    It looks like a Google results page, but is not.

    2) The Google search box in the upper-right of Firefox is missing; this happened a couple days ago though. How do I get that back? Is it related to #1?

    I am attaching 3 files:
    a) MG log
    b) Combofix log
    c) Screen shot from the error box from HostXpert

    Thank you and I look forward on your next instructions.

    Jamie
     

    Attached Files:

  15. jamiesc

    jamiesc Private E-2

  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Consider updating Mozilla Firefox (3.5.11) to the current Mozilla Firefox 3 3.6.8 Final

    Step 1:
    Please re-download and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run.
    • Please attach this log to your next reply.

    Step 2:
    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 4:
    Please run this: GMER - running with a random name and attach the log from GMER.

    Step 5:
    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • the GMER log
    • TDSSKillerlog.txt

    *What problems are you still having?

    dr.m
     
  17. jamiesc

    jamiesc Private E-2

    Dear Dr. M:

    Please excuse the late reply; I was traveling.

    I did download and re-install the Firefox you recommended.

    I see that this search-start.com is an add-on in IE and it will not let me remove it from there.

    My firefox is also re-directing now.

    Thank you,
    Jamie
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix to fix some registry keys
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. jamiesc

    jamiesc Private E-2

    Dear Mr. chaslang:

    It appears I am not having any problems! I tested the issue, which was using the Google search in IE (the upper right search box) and that re-directed my IE. Then Firefox got infected and I started getting re-directed.

    Both browsers now seem to be clean; at least, they are not re-directing my searches.

    I made one change to IE. I cannot stand Bing; I wanted Google back. So I went to ieaddons.com and downloaded the Google Search box with suggestions. I that a safe add-on? A safe site? It's where IE automatically routes me for add-ons.

    I have attached the 2 logs as you requested.

    Just so I know, what was the name of this virus/malware? I'd like to understand this better.

    Finally, what antivirus do you suggest I use? I am using Zonealarm for a Firewall. I use UAC.

    I deleted Norton a while ago b/c it seemed to slow my computer down.

    Finally, what spyware do you suggest I use?

    Thank you and dr. m so much. What a wonderful service. Thank you for your expertise and generosity.

    Jamie :)
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no name for it since you really did not have any real malware. You just had installed a search engine from somewhere that you probably did not realize you installed.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds