google redirect problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chronicv420, May 16, 2011.

  1. chronicv420

    chronicv420 Private E-2

    i've done what was said in the "read and run me" guide and the "fixing google redirection/hihacking problems" and nothing worked, i still have the issue. mbam found nothing, and neither did superantispyware. it only seems to be happening in firefox. in ie, and google chrome, i don't have the redirecting issue. thanks in advance if someone can help.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!
    *Not quite - you didn't attach the requested C:\MGlogs.zip.

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    Now reinstall FireFox from the file previously downloaded.
    Then import your bookmarks file. (similar process to exporting).

    Please attach the C:\MGlogs.zip and answer this: "Is FireFox working okay now?"

    dr.m
     
  3. chronicv420

    chronicv420 Private E-2

    sorry it didn't have the zip log the first time i ran mgtools. i still have the issue of redirecting, even after doing what you asked. here's the logs you asked for.

    i also got an error message while running mgtools.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Bring up Device Manager by right clicking My Computer and selecting Properties. Then click the Hardware tab and then select Device Manager.

    Look under System Devices section, do you see something like [cmz vmkd] or [cmz vmkd] Virtual Bus

    If you find a match to what I said to look for then right click on it and select Disable ( not select Delete at this time )

    Did you see anything like that?
     
  5. chronicv420

    chronicv420 Private E-2

    no, nothing like that is there.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove files to uninstall:
    Messenger Plus! 5

    Now, use windows explorer to find and delete:
    C:\ProgramData\AVG10
    C:\Windows\1226A4C56F274C4EAE372B5512DE125A.TMP

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. chronicv420

    chronicv420 Private E-2

    it wouldn't allow it to. it said it's not a registry script and i can only import binary registry files from within the registry editor.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do this:
    Be sure the "Save as" type is set to "all files" ??
     
  9. chronicv420

    chronicv420 Private E-2

    yes, of course.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va001]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
    
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7EB441B5-39E5-43FB-9087-56BCDC83CA67}]
    
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{00121B5A-4A42-4DAA-A9ED-A8675DCB2443}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  11. chronicv420

    chronicv420 Private E-2

    okay, here's the attachments you asked for. i'm still having my google redirect issue and while doing the MGtools scan thing, i got this error "the ordinal 1108 could not be located in the dynamic link library WSOCK32.dll."
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you re run TDSSKiller and attach the log please?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  14. chronicv420

    chronicv420 Private E-2

    here's the logs you asked for. gmer didn't give me a log, when i saved it, it came out blank but it said "gmer hasn't found any system modification"
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Scan With RKUnHooker
    • Please Download Rootkit Unhooker Save it to your desktop.
    • Now double-click on RKUnhookerLE.exe to run it.
    • Click the Report tab, then click Scan.
    • Check (Tick) Drivers, Stealth, Files, Code Hooks. Uncheck the rest. then Click OK.
    • Wait till the scanner has finished and then click File, Save Report.
    • * This can take a while. Please be patient *.
    • Save the report somewhere where you can find it. Click Close.
    • Copy the entire contents of this log in you're next reply.
    • This log can be lengthy you may have to post it in separate replies.
    • Note: You may get the following warning - it is ok - just ignore it:
    • "Rootkit Unhooker has detected a parasite inside itself!
    • It is recommended to remove parasite, okay?"

    Run this too, attach results from each.

    Using Radix To Detect Rootkits
     
  16. chronicv420

    chronicv420 Private E-2

    i can't use radix on my computer. it said it only works for 32 bit, and i have a 64 bit. the site you provided for rkunhooker wouldn't connect.

     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I want you to try a new tool:

    http://www.geekstogo.com/forum/files/download/413-roguekiller/


    * Download RogueKiller on the desktop (use the link above)
    * Close all the running processes
    * Under Vista/Seven, right click -> Run as Administrator
    * Otherwise just double-click on RogueKiller.exe
    * When prompted, type 1 (SCAN) and then Enter
    * A report should open, attach the log to your next reply. (RKreport could also be found next to the executable)
    * If RogueKiller has been blocked, do not hesitate to try a few times more. If it really won't run, rename it to winlogon.exe (or winlogon.com) and try again.
    * Attach the log.
     
  18. chronicv420

    chronicv420 Private E-2

    here's the log for roguekiller.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Trying very hard to find at least one tool which will reveal the malware so we can target it.

    1. When in Device Manager, (under system devices) have you checked "View" and "Show hidden devices"? Does anything like [cmz vmkd] or [cmz vmkd] Virtual Bus or similar show?

    2. Boot into safe mode and run TDSSKiller yet again and attach the log.
    Download the MBR Rootkit Detector to your desktop.

    3.
    • Doubleclick mbr.exe and follow prompts.
    • A black DOS window will quickly appear then disappear.
    • When mbr.exe is finished it will create a log on your desktop.
    • Copy and paste contents of that log file to your next reply.

    4. Run this Running Rootkit Revealer


    5. Then run this and attach the results.

    Using ESET's Online Scanner
     
  20. chronicv420

    chronicv420 Private E-2

    do you want me to scan with rootkitrevealer and mbr rootkit detector in safe mode as well?
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, just TDSSK in safe mode, the rest can be run normally.
     
  22. chronicv420

    chronicv420 Private E-2

    i went to boot my computer in safe mode, and it wouldn't start up then i tried in normal mode, and it wouldn't start up. i fixed it by doing a system restore so i can try again though if you want.

    however, the rootkitrevealer showed the software and licence terms. i clicked "accept" then it just disappeared, and i couldn't open it or scan or anything. here's my log for mbr rootkitdetector and i'm doing my eset scan now so i'll attach that when it's done.
     

    Attached Files:

    • mbr.log
      File size:
      227 bytes
      Views:
      2
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue with ESET but I also want you to try something else afterwards.

    Download the file to your desktop

    Kaspersky Virus Removal Tool

    Run the program you have just downloaded to your desktop (it will be randomly named )

    First we will run a virus scan.
    • On the first tab select all elements down to Computer and then select start scan.
    • Once it has finished select report and post that.

    Do not close AVPTool or it will self uninstall, if it does uninstall - then just rerun the setup file on your desktop.

    Now an analysis scan

    • Select the Manual Disinfection tab
    • Press the Gather System Information button
    • Once done Open the last report saved folder then attach the zip file to your next post.
    • The file is located at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip
    Please attach that too.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your problem is related to the [cmz vmkd]Kestrel is havoing you looking for. Check other areas in Device Manager. For example, under the View menu selection, enable Show Hidden Devices. Then select Non-Plug and Play Drivers and see if it appears there.

    I can see other signs from this infection in the procdll.txt file which is part of MGtools. In it you will see the below hooked into many processes.

    \\.\globalroot\systemroot\syswow64\mswsock.dll

    Yours may be the second PC running x64 where I have seen this. And due to it being x64 ( which really is harder to infect than previous systems ), it is also more difficult to fix. Reinstall may be the only option. Also do note that this infection is also considered a backdoor infection which is a high security risk and in many cases really means you need to reinstall from scratch anyway in order to ensure security of your PC.
     
  25. chronicv420

    chronicv420 Private E-2

    okay, i'll do this. i attached my eset scan.

    i checked my device manager, and it wasn't there. how would i go about reinstalling from scratch if i don't have an installation cd? my computer has the option to restore to factory settings but i don't think that will work. i don't do much on my computer, including using credit cards. it's just annoying being redirected on google when i use firefox, or IE. it doesn't happen on google chrome or anything. i just want it gone.
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would recommend that you backup your important files and data to a cd and then do a system recovery using the recovery partition. Off hand, I don't recall which F key to hit on start up ( it may be 0 for Toshiba or F9 for others).

    Having this type of infection will leave you very vulnerable for additional infections as well as data stealing.

    I highly recommend you do the restore to factory settings. Then once back up and running, with AV and AS software in place, you can create a restore disc.
     
  27. chronicv420

    chronicv420 Private E-2

    what does a restore disc do?
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What it says, it will restore your computer to what ever time you create it. This is a subject for the software forum. They can guide you in creating a backup disc in case your computer ever crashes. ;)
     
  29. chronicv420

    chronicv420 Private E-2

    ah makes sense. the virus removal tool found a trojan in system 32. consrv.dll? backdoor.win64.zaccess.a
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unfortunately, this is the main infection which we have no methods of removing:
    \\.\globalroot\systemroot\syswow64\mswsock.dll
     
  31. chronicv420

    chronicv420 Private E-2

    it asked me if i wanted to remove it, and i did and now my computer won't load.
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you have no other choice but to try to restore to factory settings. :(
     
  33. chronicv420

    chronicv420 Private E-2

    i'm in system recovery now, but i was wondering, if i do a system restore, would the virus be removed even if i did a system restore?
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You would have to go back to a point before the malware got on your system. The only way to check that would be to again run MGTools for us to check you logs.
     
  35. chronicv420

    chronicv420 Private E-2

    ah i see. i tried that before, it was the first thing i did and it wouldn't even let my computer do a system restore. ah well, looks like i'm bringing my computer to factory settings. this will get rid of my virus?
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that should get rid of any infections you have. First thing to do after restoring is to download and install your protection software. You may wish to read this:
    How to Protect yourself from malware!
     
  37. chronicv420

    chronicv420 Private E-2

    okay, good. i did all that stuff that thread you linked me to said to do. i always checked my computer for malware, did daily scans, etc. but anyway, if this doesn't get rid of the virus, what do i do?
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's not get ahead of ourselves. Do a system restore to as far back as you feel is necessary and then download MGtoolsagain and run the exe. Then attach the new C:\MGLogs.zip for me to check the logs.
     
    Last edited: May 24, 2011
  39. chronicv420

    chronicv420 Private E-2

    i can't. my computer doesn't save restores for a long period of time. i can only go as back as the 22nd, and it was there since the 14th - 15th.
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you may be stuck with only having the option to do the restore to factory settings.
     
  41. chronicv420

    chronicv420 Private E-2

    k thanks for your guys help, i'll just do that.
     
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Sorry there was no easy fix.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds