Gogle Browser Redirect with HTTP 404 error

Discussion in 'Malware Help (A Specialist Will Reply)' started by toolmom, Jul 29, 2011.

  1. toolmom

    toolmom Private E-2

    I'm working on a laptop that wouldn't open the Internet when I got it.
    Ran Malwarebytes in safemode from admin account. It found several items that were fixed. Then ran Ccleaner on drive & repaired the registry. Also removed duplicate AV programs. At this point I was able to open IE, but received an HTTP 404 redirect error when performing any kind of a search. My searching led me to your site. Followed your directions and renamed the removal tools and am now attaching the log files. I did notice some odd things in the HiJack This file. Also, the MBRCheck log file was not easily found. I had to do a search to find it. Said it was on the desktop, but was not, even though I have shown all hidden files. HELP!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    You did not finish the instructions of the READ & RUN ME FIRST. You left out the logs from the below:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • MGtools
    However your MBRcheck log shows that your Master Boot Record has been infected. Do you have your Windows XP boot CD?
    I also want you to run the below.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
     
  3. toolmom

    toolmom Private E-2

    Re: Google Browser Redirect with HTTP 404 error

    This occurred when running the MGtools on the infected system. The program got pretty far along, and then said that it couldn’t find the ProcessDll.exe. This JIT Debugger error window popped up immediately after. I have not been able to run the ComboFix, because it keeps telling me that AVG is installed and running. The system has Avast and I have disabled it for now. I ran a search for AVG and nothing showed.

    I found the AVG Removal Tool on your site, and ran it. It rebooted the system, so I again tried to run ComboFix...same error. I have installed SUPERAntiSpyware and it is running now. In the morning, I will run HostsXpert and Root Repeal, and then send you those logs and the various Malwarebytes logs that I have.

    Thank you for your help.
     
  4. toolmom

    toolmom Private E-2

    Also, the owner of the laptop doesn't have a Windows XP boot CD, but I can probably scrounge one up. I am attempting to remove the malware & viruses as she has several programs on it that she can't replace. She is a photographer and a singer. This is why I haven't performed a wipe & restore. I have backed up her files, but have not made an image of the drive yet.
     
  5. toolmom

    toolmom Private E-2

    I ran the HostsXpert Restore Microsoft's Hosts File and then closed it out. Attached are the logs that you asked for. I am running the MalwareBytes report with the program renamed to MB as requested in the R&R Me 1st instructions.

    The owner needs to record a song in the next couple of days. Thank you for your help!
     

    Attached Files:

  6. toolmom

    toolmom Private E-2

    The AVG Removal report did not attach. I will send it with the MBAM report. Thanks!
     
  7. toolmom

    toolmom Private E-2

    Here is the MBAM and AVG logs. The original AVG Remover log was avgremover.log and I tried to rename it as avg-remover.txt and it still wouldn't attach. I had to copy & paste to a new text document & save it with a different name in order for it to upload.

    Let me know what to do next. Thank!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Google Browser Redirect with HTTP 404 error

    You need to attach the C:\MGlogs.zip file from MGtools.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are going to need it so that you can boot to the Recovery Console to repair the Master Boot Record.
     
  10. toolmom

    toolmom Private E-2

    Here is the MGlogs zip file.
     

    Attached Files:

  11. toolmom

    toolmom Private E-2

    I looked through several posts on the MBR showing a corruption and noticed that if there are 2 HD's or partitions, like this one has (C: & D: ), then this seems to show up. Is it possible that this is the case? Also, I installed AVG again, ran it, removed the issues found (Systems Security 2009, etc.), and then uninstalled it. ComboFix then updated and ran. I am also now able to do searches with Google, etc. and updated MBAM, Windiws XP, Ccleaner, and others. Do you see anything else in the logs that I sent that would need to be removed or fixed?
     
  12. toolmom

    toolmom Private E-2

    We have a Windows XP boot CD. What should I do from here?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are asking.

    You should only be doing what we ask you to do and nothing else as requested in the READ & RUN ME FIRST.

    Since you previously ran an old version of TDSSKiller, lets run a scan with the current version and see what it finds.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller

    Also run another scan with MBRcheck now and attach the new log from it too.
     
  14. toolmom

    toolmom Private E-2

    I'm sorry. Attached are the 2 logs that you requested.

    The laptop was shipped from the factory with the HD split, one partition (C: ) was used normally and the other (D: ) was the recovery partition. Somehow, the owner is now using it as an alternative storage disk for music, etc. As she is not technically savvy, I don't think she made any changes, so is it possible that the MBR having an unknown code is related to her using the partition for storage?
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. But this other partition should not be used for storing data by the end user.

    You need to boot the Recovery Console. See Option 2 of the below link to see how.

    http://support.microsoft.com/kb/314058


    Once at the command prompt of the Recovery Console, type fixmbr and hit enter. This will repair the infected MBR. Then reboot the PC ( type exit to reboot and remove the CD ). After booting back into Windows, run MBRcheck again and attach a new log.

    Also do the below:


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. toolmom

    toolmom Private E-2

    I performed the items that you requested. Everything appears to be working normally now, not getting the errors as before. Attached are the logs that you requested. Thank you, :major!!!
     

    Attached Files:

  17. toolmom

    toolmom Private E-2

    Re: Google Browser Redirect with HTTP 404 error

    Was there anything additional that you noticed in the logs that I sent or are they clean? The laptop seems to be OK, but I just wanted to be sure that there wasn't anything else that I needed to clean up. Your expert assistance has been invaluable! Thank you!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds