Already Ran the READ ME, Still getting Redirected

Discussion in 'Malware Help (A Specialist Will Reply)' started by markozimek, Jan 23, 2011.

  1. markozimek

    markozimek Private E-2

    Dear Majorgeeks -

    One of the two computers on my home wireless network is getting redirected about every 3-5 times I use google, yahoo mail, etc. The problem originally started on the other laptop (here is the thread http://forums.majorgeeks.com/showthread.php?t=226445e), but the problem seems to have manifested itself to my new laptop.

    I ran the complete READ ME FIRST set of procedures. Attached are the first few logs. As always, I appreciate your thoughts. Thanks!

    Mark
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. markozimek

    markozimek Private E-2

    Here is the log from TDSKiller. please let me know what you think. thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. markozimek

    markozimek Private E-2

    Hi Chaslang -

    Are there any different options? I tried running ComboFix twice with the text listed below and both times the process created errors, including disabling my wireless connection. After each, I ran a system restore.

    I hope I can try something different as the redirects still occur. Thanks,

    Mark
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were both McAfee ( all pieces of it - AV, AS, firewall ) and Windows Defender disabled?
     
  7. markozimek

    markozimek Private E-2

    Dear Chaslang -

    I disabled the McAfee firewall and real time scanning. I have no idea what "AS" and windows defender are. Do you have a tutorial on how to turn those off?

    Thanks,

    Mark
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the log from your last run of ComboFix anyway. Do this before continuing.

    AS means antispyware. Your McAfee program also includes antispyware protection along with their antivirus and firewall. Also Windows Defender is a Microsoft program which came with Windows 7. See:
    How to disable Windows Defender | Windows Vista, XP and Windows 7

    So in addition to disabling McAfee's realtime protection, disable Windows Defender too and then try the below fix:

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. markozimek

    markozimek Private E-2

    Dear Chaslang -

    I'm afraid the solution did not work. Pop ups are still occuring. I ran the Avenger, although I could not find the log in the specified location. I also ran the GetLogs.BAT file in MG Tools. That log is attached.

    Please let me know if you have other ideas. Thank you.

    Mark
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try again. It did not run properly which is why there is no log. ALL protection must be shutdown, including Windows Defender which you had not been shutting down. If Avenger does not run properly and produce a log in normal boot mode then run it in safe boot mode. You will continue to have redirects until we get those registry entries for your dhcpnameserver fixed. ComboFix is actual the better way to fix it but you have problems running it ( which may be due to McAfee and Windows Defender ) ComboFIx probably fixed the problem in the past but when you ran System Restore, you reinstalled the malware. You should not use System Restore. All you had to do was fix your DNS settings and also set your PC to use DHCP.
     
  11. markozimek

    markozimek Private E-2

    Avenger is still not creating a log.

    I started the whole process in safe mode. Disabled the firewall and scanning within McAfee. Windows Defender does not appear when I restart in safe mode. Even if I click "start" and search "windows defender" in the search field.

    I double click Avenger, the program starts and I insert the script you asked me to paste. The program proceeds to ask me if I want to restart and I click yes and restart in safe mode. When it reboots, I check the C: drive for the log. Nothing.

    I'm real sorry. Not sure what I am doing wrong.

    Mark
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing to be sorry about. It may not have anything to do with you doing anything wrong.;)

    Boot in normal mode. Then uninstall McAfee. After uninstalling run the below too to make sure it is removed

    McAfee Consumer Product Removal Tool

    Then make sure you have followed the instructions in the link I gave you to disable Windows Defender.


    Now delete any copies of ComboFix.exe that you have.
    Now download this copy combofix.exe and save it to your Desktop. After saving it, right click on it and select rename. Rename it to 123cf.com Then simply try double clicking on it and see it it runs. If it runs, attach the C:\combofix.txt log. If you lose network connectivity, avoid running System Restore and just check that your network settings are correct to allow setting an IP Address Automatically ( called setting your PC for DHCP ). See the below if you don't know how to do this:

    http://uits.iu.edu/page/aiyy


    No matter what happens with ComboFix, do the below.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
     
  13. markozimek

    markozimek Private E-2

    Hello Chaslang -

    I ran the procedure you suggested and attached the files. Note - upon rebooting during the ComboFix procedure, I recv'd the following error:
    * c:\windows\system32\GfxUI.exe
    * A device attached to the system is not working

    Please review the logs and let me know what you think. THANKS!

    Mark
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below:
    McAfee Virtual Technician

    Download OTL by Old Timer and save it to your Desktop.
    • Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
      Code:
      :processes
      :otl
      O4 - HKLM\..\Run: [combofix] C:\123cf.com\CF4492.cfxxe /c C:\123cf.com\Combobatch.bat
      O4 - HKLM\..\RunOnce: [combofix] C:\123cf.com\CF4492.cfxxe /c C:\123cf.comCombobatch.bat
      :services
      mferkdet
      McOobeSv
      mfewfpk
      McMPFSvc
      McNaiAnn
      mfefire
      mfevtp
      cfwids
      mfefirek
      :reg
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
      "mcui_exe"=-
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
      "PendingFileRenameOperations"=""
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
      "DhcpNameServer"=""
      [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
      "DhcpNameServer"=""
      [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
      "DhcpNameServer"=""
      :files
      c:\windows\system32\drivers\cfwids.sys
      c:\windows\system32\drivers\mfefirek.sys
      c:\windows\system32\drivers\mferkdet.sys 
      c:\windows\system32\drivers\mfewfpk.sys
      c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe
      c:\program files\Common Files\McAfee
      C:\combofix
      C:\QooBox
      C:\123cf.com
      :commands
      [PURITY]
      [EMPTYTEMP]
      [RESETHOSTS]
      [CREATERESTOREPOINT]
      [CLEARALLRESTOREPOINTS
      [REBOOT]
      
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the OTLlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. markozimek

    markozimek Private E-2

    Good morning -

    I ran the OTL, but the redirect is still occuring. I also disabled McAfee AS and Virtual Technician as well as Microsoft Defender. The logs are attached.

    Could this have something to do with the other laptop that I run on my home network?

    Mark
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and it will remain until we manage to get those registry entries fixed. They seem to be locked by something and we need to get them unlocked. You can see what registry keys 'm referring to in the C:\MGtools\runkeys.txt log. You will see the below lines
    Code:
        Checking for DNS Hijacker - aka Wareout 
        ------------------------------------------------------------------------
              Possible DNS hijacker found! 
    HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
       DhcpNameServer REG_SZ          213.109.66.15 213.109.77.225 1.1.1.1
    --
    HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters
       DhcpNameServer REG_SZ          213.109.66.15 213.109.77.225 1.1.1.1
    --
    HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters
       DhcpNameServer REG_SZ          213.109.66.15 213.109.77.225 1.1.1.1
      
        ------------------------------------------------------------------------
    This is why you have redirections. This infection has been known to infect router hardware. Does you other PC have the same redirection issue? If yes, it could also have the same infected keys and also your router could be infected.

    If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    After resetting the router to factory defaults and reprogramming as needed, test both PCs you have and see if they have redirection issues.
     
  17. markozimek

    markozimek Private E-2

    Well, it seems to be getting better (see attached). The log is still showing one possible hijacker instead of three.

    Mark
     

    Attached Files:

  18. markozimek

    markozimek Private E-2

    Here is the log from the other laptop. All seems to be going well on both computers. :) Cross your fingers.

    Mark

    PS Thanks a million!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still need to know if your other PC was having similar hijack issues?

    Also did you reset your router to factory defaults?



    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
      Code:
      :reg
      [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
      "DhcpNameServer"=""
      :commands
      [PURITY]
      [EMPTYTEMP]
      [RESETHOSTS]
      [CREATERESTOREPOINT]
      [CLEARALLRESTOREPOINTS
      [REBOOT]
      
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the OTL log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see you posted a log for your other computer and it shows the same problem. Repeat my last fix on this computer too.
     
  21. markozimek

    markozimek Private E-2

    I think you got it! :) Attached are the logs for the first laptop. I will post the logs for the second laptop in a few minutes. It's a little slower and the GetLog.bat is still running. You may want to wait until seeing that next file to reply.

    Thanks,

    Mark
     

    Attached Files:

  22. markozimek

    markozimek Private E-2

    This one looks good too. Please check the logs if you don't mind. Thanks,

    Mark
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Note you were using an out of date version of MGtools on your Win XP system. You should not keep old versions of MGtools around. Be sure to follow all of the below instructions on both PCs.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds