Browser Redirect issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by motc7, Jan 5, 2011.

  1. motc7

    motc7 Vice Admiral (Starfleet)

    I have a machine at home where three different browser's search engine results are being redirected.

    For example, I can type in www.majorgeeks.com in the url field and things will work fine. No redirects. But if I type in majorgeeks into Google, MSN, whatever, then click on the search results, it redirects to some spam site.

    I have done the following:

    Malwarebytes
    Combofix
    SuperAntiSpyware
    ATF
    Dumped Temp directory

    Still i am having this issue. I see the following post.

    http://forums.majorgeeks.com/showpost.php?p=1577253&postcount=1

    TDSSkiller - would this be a good option to try next given my scenario?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes indeed. Run that, attach it's log, and attach all of the other requested logs.
     
  3. motc7

    motc7 Vice Admiral (Starfleet)

    Will be late tonight. At work right now and the machine is at home.
     
  4. motc7

    motc7 Vice Admiral (Starfleet)

    Is this something new for 2011 btw? I mean, I've never seen anything be resistant to Combofix before.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of the scans will find a router infection. Please attach the requested logs when you are ready. One suggestion to rule out the router being infected would be to do a direct connect to your modem and see if it stops.
     
  6. motc7

    motc7 Vice Admiral (Starfleet)

    Well, this same thing is happening at two different locations with two different routers.

    Does that shed some light?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not necessarily. Both could be infected. It is just guess work until we can see the logs.
     
  8. motc7

    motc7 Vice Admiral (Starfleet)

    FYI - I tried running TDSSKILLER and nothing runs at all. I'm assuming that I don't have that thing then?

    I ran through part of the malware removal guide and when I dumped the java cache that seemed to help, search engine was working normally. Also dumped all cookies too.

    But on the next restart, poisoned search results from all browsers.

    Running the Malware removal for XP.
     
  9. motc7

    motc7 Vice Admiral (Starfleet)

    Combofix bluescreened my computer.
    RootRepeal wouldn't even launch the executable.

    I had all antispyware and antivirus disabled and turned off frankly.

    The other logs are posted.


    I cannot understand what else is on here causing problems.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since I am not seeing any malware in your logs, I want you to do this:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  11. motc7

    motc7 Vice Admiral (Starfleet)


    I will do that, but what are your initial suspicions right now?

    Again, this is someone else's pc i'm troubleshooting. This problem happens in two completely geographical locations.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Router infections or MBR infection. I won't know until I see the log.
     
  13. motc7

    motc7 Vice Admiral (Starfleet)

    MBR log
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nope, no MBR infection. What browser are you using that gets redirected? Does it happen in all browsers? Does it happen if you bypass the router and connect directly to the modem?
     
  15. motc7

    motc7 Vice Admiral (Starfleet)

    Happens whether there is a router or not.

    Happens in all browsers.

    Just ran Goored.


    Edit: Panda scan running. 13 files it's found infected and almost done.
     

    Attached Files:

  16. motc7

    motc7 Vice Admiral (Starfleet)

    Panda scan found stuff.

    Edit: GMER running now
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing any malware. Have you deleted all your temp internet files? Have you run ATF?

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run an online scan:
    eSet Online Scan.
     
  18. motc7

    motc7 Vice Admiral (Starfleet)

    Ran both of those yesterday ATF found nothing, ESET found infections, cleaned them, but still having issues.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not sure what to do with this. What happens when you try to run TDSSKiller? I haven't seen it not work on most system. Tell me if you are getting error messages or what exactly happens.
     
  20. motc7

    motc7 Vice Admiral (Starfleet)

    Exactly nothing happens. No hour glass showing it's running. I don't see it register in the processes in task manager.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you download the correct version to your desktop?
     
  22. motc7

    motc7 Vice Admiral (Starfleet)

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right.

    Here are the instructions in case you need them:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  24. motc7

    motc7 Vice Admiral (Starfleet)

    got it working. Thanks. Found 1 threat.

    Servicename VolSnap
    Service type kernel driver (0x1)
    service start: Boot (0x0)
    File C:\Windows\system32\drivers\Volsnap.sys

    and then there is some other stuff. What should I do?


    edit: Nevermind, it identified itself as a TDSS rootkit.

    I killed, it rebooting now. will report in a minute.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the log. And you should have selected cure if that was an option. Once done, test your redirect issues.
     
  26. motc7

    motc7 Vice Admiral (Starfleet)

    TDSS log
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So if you have rebooted, is the issue continuing?
     
  28. motc7

    motc7 Vice Admiral (Starfleet)

    Tim, you are the man. Didn't see that part about renaming it if it doesn't run.

    I was going off this guide initially.


    http://forums.majorgeeks.com/showpost.php?p=1577253&postcount=1


    Look at the bottom. The renaming part is not listed. Might need to update that.


    I'm going to reboot a couple of more times and see if it's gone. But I would like an explanation about this a bit further. Is this a new variant, or has it been around awhile?
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will update that post. Thanks.

    No, this has been around for a few months now in various forms. Let me know if you still have any issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  30. motc7

    motc7 Vice Admiral (Starfleet)

    Done, close thread.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your welcome.
     
  32. motc7

    motc7 Vice Admiral (Starfleet)


    Thanks. Sorry, just man when you are so elated that the crapstorm is over, you forget your better senses.

    I now defer to you as ObiTimKenobi...
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know you are working again. Safe surfing, man! ;)
     
  34. motc7

    motc7 Vice Admiral (Starfleet)

    So I see you are not denying your new Jedi title....that's pretty narcassitic...and I love it!!!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds