redirecting please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by sparkki, Oct 19, 2010.

  1. sparkki

    sparkki Private E-2

    Hi! when ever I am on the internet and I click on a link to a tech help site my browser redirects. I am able to still copy and paste, and a generic win32 service encountered a problem window pops up and then my taskbar changes.:cry This started happening three days ago please help! Thank you!

    p.s Could not find combofix log.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this and report back to me how the computer is behaving as I review your other logs.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. sparkki

    sparkki Private E-2

    Oh thank you so much its back to normal!!!!:-D Words cannot express how overjoyed I am, and thanks for getting back with me on the same day I posted!! I will purchase some merchandise since you don't take donations. Here is my tdss log.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome.

    Before we continue you need to use MSConfig to put this machine back into normal start up mode.

    Update MalwareBytes by opening up the program, locating the update tab. Re-scan, fix anything it might find and attach the log it creates regardless of whether it finds any threats or not.

    C:\Documents and Settings\antoine manning\My Documents\Downloads\MGtools.exe <--- Delete this. Not where it should have been downloaded to and it is not needed now anyway.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\Temp
    • C:\Documents and Settings\antoine manning\Local Settings\Temp

    Download a fresh version of combofix to your DESKTOP and run it as per the instructions in the Read and Run me First.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. sparkki

    sparkki Private E-2

    Malwarbytes will not let me update even when I delete it and reinstall.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, well then skip that step and continue on.
     
  7. sparkki

    sparkki Private E-2

    sorry it took me so long to reply I tried deleting the temp folder but it stopped mid way and said another program was using one of the files and to close out that program. Also heres my avenger log.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue on, post again only when you have completed the rest of my instructions and then attach the remaining logs.
     
  9. sparkki

    sparkki Private E-2

    I deleted them I was in the wrong thing sorry I'm a noob.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What have you deleted?
     
  11. sparkki

    sparkki Private E-2

    Okay thanks much for your patience I'm attaching the mglogs and combofixlogs.

    P.s about the deleting temp files, what I had did I opened up the windows folder and went down to that temp file and tryed to delete it, it started deleting but it stopped half way through. So I did a google search on how to delete your files and I just typed into the run bar %temp% and that brought up the right files. Thanks again.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look good now. Try updating MBAM [URL="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_Database_d6025.html]manually[/URL].

    Manual update files that you can transfer over if needed. You will need to transfer the installer and update files over, install the software and then run the update files.

    Let me know if that works and then give a brief description of how the machine is running.
     
    Last edited by a moderator: Oct 21, 2010
  13. sparkki

    sparkki Private E-2

    Kestrel when I click on the manual link it takes me to the malwarebytes site but it says that the page is not found.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  15. sparkki

    sparkki Private E-2

    Okay here is my mbam log. Thanks
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That was clean, so tell us what issues you may still have, if any.
     
  17. sparkki

    sparkki Private E-2

    Tim my computer is back to normal no more issues and I really do appreciate you and Kestrel's help:)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will let Kes return to acknowledge your thanks. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  19. sparkki

    sparkki Private E-2

    When I typed that into run combofix looks as if it wants to run again, its asking me to turn of my virus protection
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Disable your AV software and it should run its course to uninstall.
     
  21. sparkki

    sparkki Private E-2

    I have completed all of the steps except system restore, I just have one more question how do I remove the tdsskiller zip folder from my desktop? Thanks
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can just right click it and choose delete.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds