Browser Redirect/Hijacking Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ingvald81, Dec 26, 2010.

  1. Ingvald81

    Ingvald81 Private E-2

    I had my comp reformated because of a trojan that got into it. Still after this I am having redirection problems with my Internet as well as it not formatting pages or going to website ads. I have run all cleaning instructions and it is still happening. I'm sure I'll have to delete some registry keys as it will not be cleaned by these programs. I have attached all logs as possible. I cannot get the RootRepeal to work. Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There are a number of infections around that will infect hardware external to your PC. Thus reinstalling your PC would not fix the problem. Let's see if that is your problem.

    Some of these infections are known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. Then after the reconfiguartion, power down your router and also power down your cable or DSL modem too. Wait a minute and turn everything back on. See if there is any change.
     
  3. Ingvald81

    Ingvald81 Private E-2

    Thanks for the reply, however, after resetting my router and powering down I am still getting redirection problems. For instance, now when I click on a link I also get a new window which goes to some kind of add. So I am sure I am still infected with some kind of malware. What do my logs show?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  5. Ingvald81

    Ingvald81 Private E-2

    I have attached the log after running but it did not find anything.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of your logs show any problems. When you said you reset your router, do you mean that you actually reset it back to factory defaults?

    Do you have any other PCs connected to this router? If yes, do any of them display the same problem with redirections?


    Let's do one more scan.

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  7. Ingvald81

    Ingvald81 Private E-2

    Okay, Yes I pushed the reset button and held it down in the back of my wireless router and then power downed the modem and router and got it back up.

    I attached the logs for this next step. I have also run a Hijackthis log as well and can attach this. I think I have this key on it which I think might be bad:
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll

    But I can attach the Hijackthis log if it would be helpful as well.Thanks!
     

    Attached Files:

  8. Ingvald81

    Ingvald81 Private E-2

    Oh and No I only have my lap top connected to my network. This is it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't need a HijackThis log as we already have the info. That file is part of your Kaspersky antivirus.


    What browser are you using when you get redirected?
    Have you tried more than one browser?
    Have you tested to see if it occurs in safe boot mode?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another question, why are you running original Vista with no service pack updates? You are way out of date.
     
  11. Ingvald81

    Ingvald81 Private E-2

    Okay, yes I use Chrome but I have experienced the problem in IE as well. I have not tried to see if the problem exists in Safe Mode however.
     
  12. Ingvald81

    Ingvald81 Private E-2

    when I got my comp back from the place they installed this OS. I tried to install the Service Pack 1 update but I received some kind of error.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay hangon I think I see the problem. I had assumed this was something you installed but now I'm betting it is the problem.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. Ingvald81

    Ingvald81 Private E-2

    Okay, I did as requested. I am still experiencing certain issues. Especially when clicking on links in a Google search. It will come up with some kind of ad. I attached the logs.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown Chrome completely. Then run Internet Explorer and see if you have the same problem (make sure that Chrome is not running).
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why is Veetle always showing as running in your logs? You should only be running it when you want to use it which should not be 100% of the time. Did you knowingly install this and did your problem show up around the same time?



    I have one more fix I want to apply using ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. Ingvald81

    Ingvald81 Private E-2

    Yes, I did download the plugin for Veetle. I had this also installed on my old system without any instance and my current problem did start around the time of me downloading this when I got my new system back. I do not know why it is always showing up. Suppose this could be a problem?

    I ran the next steps and attached the logs. This might have fixed the issue:)
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be related to how you got the infection. All of the below and this Spigot stuff showed up at the same time
    Code:
    Dec 20 2010              "PDFCreator"
    Dec 20 2010              "pdfforge Toolbar"
     Dec 20 2010              "Veetle"

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. Ingvald81

    Ingvald81 Private E-2

    Hrmmm well, I don't know what's going on still. I still get new windows coming up with ads randomly when i click on unrelated links. It's not as bad as it has been before. I will try to monitor it and give you more explanation as to what is exactly going on. Before these steps my Internet was almost useless as it would not go to the page, redirect, be completely reformatted or come up with an error. Now it seems to be going to pages but still popping up random ads. Let me know if there is anything else I can do.

    I appreciate the help very much.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please test using Internet Explore with Chrome shut down.

    Also see what happens in safe boot mode.
     
  21. Ingvald81

    Ingvald81 Private E-2

    Alright, well looks like when Chrome is shut down IE has issues. It does not got to designated link when clicking on them and redirects. Sometimes it goes to the desired link on the second or third try.

    In safe mode, both Chrome and IE seem to be fine and go to link on first try and no redirection happens.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then in normal boot mode with Chrome shutdown, right click on your IE icon on your Desktop and select Start Without Add-ons

    Does it run okay with no add-ons?
     
  23. Ingvald81

    Ingvald81 Private E-2

    Yes, this seems to have cured the IE problem. It goes to link on the first try and does not get redirected.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you need to slowly enable/disable addons from within IE ( i.e., click Tools, Manage Addons ) and figure out which is the problem.

    See if you can do similar with Chrome. If not then uninstall it. Delete all folders for it and then reinstall. I don't use or like Chrome at all so I cannot assist you with how to manage addons with it.
     
  25. Ingvald81

    Ingvald81 Private E-2

    Okay, thanks! I will for sure be able to do this. I really appreciate your help. It's been very informative and timely!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let me know the results.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds