Internet Redirect

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aclark88, Sep 29, 2010.

  1. aclark88

    aclark88 Private First Class

    Internets been playing up, redirects to other websites, etc

    Ran the cleaning procedure but it didnt come up with much. Dont know if im missing something...?

    Heres the logs (RootRepeal came up with nothing)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing anymalware in your logs. I also am not seeing any AV software. What are you using for protection?

    Are the redirects happening in all browsers? If you boot into safe mode w/networking, do you still get redirected?
     
  3. aclark88

    aclark88 Private First Class

    Uninstalled AVG last time and havent reinstalled. Will reinstall once sorted this out. It keeps asking for windows updates but dont trust this as last time this gave me virus aswell?

    Redirecting only seems to happen on few websites?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sorry for the delay, I was out of town yesterday.
    Are you going to the microsoft website to check on updates? Are you using a router? Have you tried plugging in directly to the modem and checking to see if you still get redirects?
     
  5. aclark88

    aclark88 Private First Class

    Tim,

    I know you couldnt see anything in the logs which seemed bit strange. Ive used my laptop for years and sometimes I can just feel when somethings not right.

    My fears came true this last week when things got worse. The internet page id be on would just disappear. Programs wouldnt load. Then when running the cleaning procedure the computer cut off.

    When I turned it back on I got the 'lsass.exe; error procedure' message, which im sure you're probably aware of as it seems its quite common when I searched google.

    I tried the basic fixes (enterting registry and rename security to security.bak and copying another file) but still get the message. Im currently writing this off my mums laptop. I dont want to try any other steps without your further assistance as I have years of work and about 100gb worth of files on my laptop which I dont want to wipe by doing something wrong.

    Ive seen a step using www.ubcd4win.com which seems complicated which may fix it but dont really know where to start with that.

    Please help Tim

    Many Thanks

    Adam
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It has been three weeks since your last post. We would need you to re-run all the scans again. You can also try running this online scan:

    eSet Online Scan.
     
  7. aclark88

    aclark88 Private First Class

    I dont know if that was a preset response but I cant get into my computer. I dont know if I explained very well. When the computer starts up before it gets to the windows xp log in screen it comes up lsass.exe error and asks to end procedure and then just goes to a blank screen.

    It wont boot in any of the safe modes. Last known good configurations didnt work either and only thing I can get into is the registry editor.

    Does this sound familiar?

    Adam
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. aclark88

    aclark88 Private First Class

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's easy enough to follow, though you may want to create one of the other discs first in case it is malware that is blocking you from starting up properly.
     
  11. aclark88

    aclark88 Private First Class

    How do they work Tim, i know this probably sounds like a stupid question to yourself but theres no chance of me wiping my computer clean with these procedures?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No. You will not be any worse off than you are now. Do you have your OS CD?
     
  13. aclark88

    aclark88 Private First Class

    OS CD? Is that original windows cd that came in the box with the laptop? I dont think so. Is that a problem? Ive burned the kapersky rescue file onto a cd. How do I get this to boot in my laptop as I cant actually get on to log on and run the cd? Is there a special function in the f8 section when i turn my laptop on?

    Thanks
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to get into the bios ( maybe F2 on startup? ) and change the boot order to cd-rom as first boot device. Then put the cd in the drive and reboot. It should ask if you want to boot to the cd.
     
  15. aclark88

    aclark88 Private First Class


    Held f2, got into the bios, changed boot priority order to:

    internal hard disk drive
    internal optical drive
    floppy disk drive
    network

    hit f10 to save and exit which restarted my laptop, it then started and then loaded up as it normally would until it got to the same lsass.exe error page.

    Any idea why? Sorry to be such a pain but this is such a worry to me.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still have the boot order with the hard drive being the first choice. You need to move the optical drive to first boot device and then the hard drive down to second boot device.
     
  17. aclark88

    aclark88 Private First Class


    Thats what it was to begin with before I changed it.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this how it is now set?
    internal optical drive
    internal hard disk drive
    floppy disk drive
    network
     
  19. aclark88

    aclark88 Private First Class

    Yes. Thats how it was set then I changed it thinking thats what it was supposed to be but now it is set back to this and everytime I start up my laptop it just does the same thing. As that is what it was set to before I even changed anything Im guessing it would? Am I doing something wrong?

    I downloaded the kaspersky.ios file (190mb), burnt it to a cd, set the optical drive as first and f10 save changes and restart and then it restarts and nothing. Does exactly the same?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this. It will create a disc of just the Recovery console in xp. You can then try booting to the RC and typing in fixboot.

     
  21. aclark88

    aclark88 Private First Class

    I can get into the recovery console already, do I need to do this step?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not if you can already access the Recovery console.

    You can try the various commands ( thought you might want to post in the software forum for additional help with this ):
    Fixmbr
    FixBoot
    chkdsk /r
     
  23. aclark88

    aclark88 Private First Class

    Ok so got into recovery console, and it only lets me log onto c:windows. Typed fixboot and got 'the target partition is c: are you sure you want to write a new bootsector to the partition c, i said 'y' and it said
    the file system on the startup partition is NTFS

    fixboot is writing a new boot sector

    the new bootsector was successfully written


    and then goes back to C:\Windows

    Any sense of that?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The question is does it now boot up? I suggest you post in the software forum as we need you to be able to boot to a stable system before we can address any malware issues.
     
  25. aclark88

    aclark88 Private First Class


    Ok Tim, will do, I'll explain and refer them to this thread. Thanks for all your help Tim, will be back hopefully to see what malware was to blame for this.

    Many Thanks

    Adam
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will try to keep an eye on your software thread!! Good luck. Do consider trying to find, beg and borrow an xp cd of the same version as what you have installed.
     
  27. aclark88

    aclark88 Private First Class

    Ok so TimW, I dont know if you was following the software thread, but I sort of stumbled upon the answer through someone elses thread and had a go using ubuntu which gave me access to all my files and I toggled a system restore copying some files from the restore point into system32/config folded.

    Anyway Im back on my laptop (whoooo) and I thought Id post the logs I got the day it crashed to see if you can see anything?

    Also there is a settings DAT file that is sitting on my desktop and doesnt seem to be attached to any program and everytime I delete it always just comes back?

    Many Thanks

    Adam
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your combo log is showing a file replicator virus. First case of that that I have seen.

    You were also infected with this file:
    c:\program files\microsoft\desktoplayer.exe which also corrupted your winlogon reg. key.

    And these files needed to go as well:
    C:\Documents and Settings\Adam\Application Data\YTKIQ
    C:\WINDOWS\explorerSrv.exe

    As to the file on your desktop, you need to reset files to be hidden. Do that in the control panel, folder options, view. Set your system files to be hidden again.
     
  29. aclark88

    aclark88 Private First Class

    Something you've never seen before? Wow, feel priviledged. Files is set to be hidden? Thats why I dont understand why its there? As to those files you've written down, shall I manually delete them, as the desktopplayer.exe is still there and so is explorerSrv.exe are still there? Some programs still being funny, and slow. Google isnt loading search pages, etc.

    But this morning I couldnt even turn my computer on so I'll take today as a victory so far!!

    Thanks Tim

    Adam
     
    Last edited: Oct 27, 2010
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are saying that you already have system files set to be hidden? If so, I don't know why it is there. Right click it, choose properties and tell me what it says.
     
  31. aclark88

    aclark88 Private First Class

    Literally nothing. That its a .DAT file, and its location is the desktop. Created withing last few days. If I delete it it'll be back within a few days. May have something due to the fact those files you typed out are still there? Maybe once they are gone this file will go to? So shall I manually delete this files?
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You mean that the files I found in your logs are still there? I thought this was from before you fixed it. Ok, then let's remove them. You will need to have ComboFix downloaded to your desktop.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\program files\microsoft\desktoplayer.exe
    C:\WINDOWS\explorerSrv.exe
    Folder::
    C:\Documents and Settings\Adam\Application Data\YTKIQ 
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe,c:\program files\adobe\photoshop elements 4.0\photoshopelementsfileagentsrv.exe"
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  33. aclark88

    aclark88 Private First Class

    Ok so did as you asked and google and other programs started working better. Here are the logs....
     

    Attached Files:

  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are still very badly infected.

    Please immediately do the below. You must do this immediately and you must complete all 3 scans one after the other with only the delay to post logs in between. DO NOT use your PC for anything else but these instructions.

    Run this Using ESET's Online Scanner and immediately attach the log.

    Then run the Eset scan a second time and attach the 2nd log.

    Then run the Eset scan a third time and attach the 3rd log.

    After attaching the 3rd log, if any Ramnet infections were found by Eset, try to repeat the above until it comes up clean. The only infections of Ramnet you can ignore, are ones that may be found in the System Volume Information folder which is System Restore and cannot be cleaned. We will remove them later by disabling System Restore.

    Now run combofix again by double clicking it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  35. aclark88

    aclark88 Private First Class

    Just when I thought things were looking good, It found 398 infected files!

    Heres log...
     

    Attached Files:

  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you have a Ramnit infection. Please continue running the eSet scans. Attach the logs. Keep doing it until we tell you to stop.
     
  37. aclark88

    aclark88 Private First Class

    Scan 2
     

    Attached Files:

  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run it just one more time. In the meantime, see if you can use windows explorer to find and delete:
    C:\WINDOWS\system32\termsrv.dll

    After this next scan, when it is done, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  39. aclark88

    aclark88 Private First Class

    Wont let me manually delete it, says access denied. Will post 3rd log when done and the mglog with it also.

    Thanks Tim
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will use Combo to remove it once you are finished with the scans.
     
  41. aclark88

    aclark88 Private First Class

    3rd scan finished, found same 2 files infected.

    Heres log.

    EDIT: Wont let me upload it. Says Ive already uploaded it in this thread. I take it that as its exactly the same 2 files in the log that may be the reason why?

    Anyway how do we remove these 2 files with combofix?
     
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to replace it (the one that could not be cleaned) from another location on your machine. ESET seems to think there is something wrong with it.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FCopy::
    C:\WINDOWS\ServicePackFiles\i386\termsrv.dll | C:\WINDOWS\system32\termsrv.dll
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know how things are running.
     
  43. aclark88

    aclark88 Private First Class

    Ok here the log. Things seem to be getting better now.
     

    Attached Files:

  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good, let's continue to sweep up -

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\documents and settings\Adam\Application Data\Lyond
    c:\program files\tmp
    c:\documents and settings\Adam\Application Data\Sabu
    File::
    c:\windows\system32\tojedel.dll
    c:\documents and settings\Adam\Application Data\Sabu\mubo.exe
    c:\documents and settings\Default User\Start Menu\Programs\Startup\toiz.exe
    C:\Windows\System32\toiz.exe
    c:\documents and settings\Administrator\Start Menu\Programs\Startup\ubfis.exe
    C:\Windows\System32\ubfis.exe
    c:\documents and settings\My Guest\Start Menu\Programs\Startup\yzyx.exe
    C:\Windows\System32\yzyx.exe
    DirLook::
    c:\program files\windows
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "{6537A7C6-510E-82F3-550E-4D08BD773C4B}"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run another ESET scan, attach the results.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  45. aclark88

    aclark88 Private First Class

    Ok did the combofix and eset scan. When doing ComboFix a pop up came up saying 'rootkit activity had been found and needs to be restarted' and then at the end of the process a pop up came up saying something along the lines of 'need to scan for added malware files'. Ive never seen that in all my combofix experience. So I've added the log for that aswell.

    Here we go...

    EDIT: It still saying that the ESETScan already exists in this thread, as it was the same 2 files found in threats!
     

    Attached Files:

  46. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell us how things are running now. I am not seeing any malware remaining in your logs. But you need to be aware that you have very little hard drive space left which could be the cause of your slowness.
     
  47. aclark88

    aclark88 Private First Class

    Thanks Tim, it now feels like as it did when I first made this thread, what feels like years ago! As I remember there was no malware in my logs then either and then all hell broke loose. Im just hoping the same doesnt happen again now.

    Thanks for your help

    Adam
     
  48. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should pare down what you have on your hard drive or get a backup external and transfer as much as you can. In the meantime, why don't you let this ride for a day or two and see how things are working.
     
  49. aclark88

    aclark88 Private First Class

    Shall I reinstall AVG Tim?
     
  50. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can reinstall AVG, but I am concerned about how little hard drive space you have left. You have too little to even do a defrag.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds