Google Redirect infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kdzgon, Aug 23, 2011.

  1. kdzgon

    kdzgon Private E-2

    Hi,
    I apparently have had a Google Redirect infection for some time now. I had an issue months ago where I could no longer log on to my company VPN. I also mentioned to the IT guys that I was having issues with Google, in that I would get strange results when searching. After many hours of (billable!) hours working on my machine, the company "experts" declared my machine as fine, with the only issue is I had not upgraded to Windows 7 Ultimate (?).

    I ran multiple scans and programs regularly, including Malwarebytes, Spybot and CCleaner, but the problem continued to worsen. I searched for a solution, and ran Tsskiller, catchme and Gooredfix multiple times, but all showed nothing found. Several weeks ago Malwarebytes found and (allegedly) rectified an infection, but the issue worsened still. Yahoo recently warned me my email had likely been compromised and I should change my password (which I did) and suddenly instead of intermittently an issue Google searches became near impossible.

    I finally did what I know I should have done long ago, and came here. I have worked through all the steps in order, even if it repeated something I had done a short while before. I did get new "hits", and allowed the fixes as proposed. I am in the process of checking my husband's machine right now, as he is beginning to show some of the same symptoms.

    Now, for my request: While my google searches seem much better, i would like someone to review my scans and see if perhaps I need to do anything else before I clear my restore points and reset my options, etc. I am attaching my scans in two (2) posts as required. I also still have my logs from prior program scans if anyone thinks they might be helpful at all.

    Thank you in advance for any assistance - this site is an invaluable resource!

    Laurie
     

    Attached Files:

  2. kdzgon

    kdzgon Private E-2

    OK - I have a 64 bit system, so I guess I could have done one post, but here's the last log.

    Thanks again!
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am reviewing your logs and will get back to you with a response later on. :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ask Toolbar <--- Uninstall this garbage.

    Please attach the SAS log:
    C:\Users\LLP\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 08-23-2011 - 18-25-48.log

    Copy the bold text below to notepad. Save it as fixIT.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    I would like you to report no redirects at all when you are googling. "Much better" to me means that problems still remain when browsing, correct?

    If you are still experiencing redirects you need to answer the below:

    • Do you use a router?
    • Do you have you Win7 boot CD?
     
  5. kdzgon

    kdzgon Private E-2

    Thank you for the courtesy of a post letting me know you had seen my issue, and for the quick response!

    ASK toolbar (I HATE that thing!) - Cannot uninstall through add/remove - I had tried but I get an error message saying it is on a network resource that is unavailable. It tells me to try again or enter an alternate path to a folder containing..."Ask Toolbar.msi" in the box. The use source that shows (in that box) is: C:\Users\LLP\AppData\Local\Temp\{25CF8A9C-F716-4B09-8E24-0B6ED2F5B06C}\. I had thought about reinstalling then trying a clean uninstall, but figured I'd wait for instructions instead.

    File attached.

    Received success message with fixIT.reg

    "Much better" referred mostly to better speed, and I was not having redirects, but after hours of computer work I didn't stay on long at the time. I am now getting redirects again today, so nix my prior statement completely.

    I do have a router.

    I have a Win 7 reinstallation DVD from Dell.

    Also:

    Do I need to reboot after the registry fix? (If you are not online now, I will likely do it soon as a precaution).

    While maybe you can already see this, please note I messed up following the directions. I somehow missed not to run combifix on a 64 bit system.

    Thank you.

    Laurie
     

    Attached Files:

    Last edited by a moderator: Aug 25, 2011
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    For ask Toolbar junk-

    Try Revo Uninstaller.

    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    Good. It very well could be your router. There is a little button on the bottom ( on most models ) to reset it to factory settings. Do that. You may then need to go back into it to set any special setting that you may have set up originally. But do that first and see if that doesn't take care of it.

    You can test this theory by connecting directly to your modem and if the redirects stop, then you know it is the router that is infected.

    Also good because if the router reset fails and you are still being redirected then we may need that disk.

    No, you were correct in running it as it is indeed 64 bit compatible.
     
  7. kdzgon

    kdzgon Private E-2

    I did reset my router while following the original set of instructions, even though while there are always at least three (3) computers connected, only one has ever had the issue. (I figure if you ask the experts for help, you follow the instructions given as closely as possible.)

    My next step was going to be test my system as suggested - ie, connected directly to my modem, so I thought I'd first see if/how quickly the redirects occurred. However, since using Revo-Installer for the Ask junk, I have not yet experienced any redirects despite at least 40-50 attempts. I am going to try a bit longer, but either way I will reset my router once more.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, can you give me an update on how things are running for you at this point? :)
     
  9. kdzgon

    kdzgon Private E-2

    The redirect issue seems to be gone - I have only had one issue, but I think it was an incorrect link on the site rather than a redirect.

    I am having a couple of other issues. After the last fix and subsequent restart, my computer would not boot up completely. I kept getting an error telling me the restore could not be completed. I had the choice to retry or delete the restore data. After several retry attempts, with fingers crossed I deleted the restore data. Everything loaded fine, but now on startups it seems to pause for a very long time on the black screen with just a small line cursor in the upper left corner, which is where it would hang up with the restore error message issue.

    So far it does eventually load, but I don't believe it would do that before (appear to pause so long at that point) so I'm not sure what if anything is going on.

    I had some issues connecting to my wireless (it didn't find it, or wouldn't connect automatically despite the settings) but I have resolved that issue by resetting the router once more and running some basic diagnostics.

    I also have not yet reset everything as outlined in the Malware Guide as I was waiting for your post. I so appreciate your assistance, I didn't want to bump my thread by posting "can I finalize everything now?"! Since it appears you did not find anything else of note in my logs, I will finish the steps in the basic guide, unless you tell me otherwise.

    Again, thanks so much for everything!!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As long as the browser redirection is gone -

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds