Another Google Redirct. Nasty!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Theo2323, Jul 19, 2012.

  1. Theo2323

    Theo2323 Private E-2

    I have looked into the stickied threads and followed the steps posted in the forums. As you can see by my posts, I'm a newbie. So hopefully you aren't to harsh on me.

    Please see the attached logs for the provided information. I am being redirected when using the google search bar.

    It goes to google.com/webhp... etc.

    I get repetitive trojan alerts from AVG and they aren't being repaired.

    Help will be greatly appreciated, as I'm a university student that would hate to lose work that I have worked hard to achieve.

    Also, I think I may have used 'private browsing' accidentally, thus disabling my Chrome extensions that are my safeguard.

    Look forward to hearing back.

    Regards,
    Theodore
     

    Attached Files:

  2. Theo2323

    Theo2323 Private E-2

    Additionally, when attempting to browse the internet, I receive this message for most websites that require identification.

    "The site's security certificate is signed using a weak signature algorithm"

    This makes me think that I'm being redirected to an alternate web page, that may log information, thus, I don't want to really go into any websites with personal information.

    Thank you.

    Regards,
    Theodore
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have a ZeroAccess infection.

    Rescan with HitmanPro
    • When it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    • Leave any other detections alone (Ignore them).
    • Afterwards, click the Next button.
    • HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    • After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log. (See How to attach files)

    Then rescan with RogueKiller and if the below show on the Registry tab, select them and click Delete
    Then look on the Files tab and delete the below if still there:
    Then reboot your PC again.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new HitmanPro log and a new RogueKiller log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Theo2323

    Theo2323 Private E-2

    Hopefully the process went well.

    Here are the requested logs follow the aforementioned directions.

    Just like to say thank you for devoting your time to helping out.

    Let me know how the logs are, a virus may still be apparent.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\installer\{19200867-2d31-f25d-c2e0-8ea4e9c26cf7}
    C:\Users\Theodore\AppData\Local\{19200867-2d31-f25d-c2e0-8ea4e9c26cf7}
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Theo2323

    Theo2323 Private E-2

    Here are the requested logs. Sorry for the late reply! Cheers for the help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The infected services.exe has come back or Hitman was unsuccessful at removing it. Let's use a different approach.


    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  8. Theo2323

    Theo2323 Private E-2

    Thank you. File is attached.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was wrong, the infected services.exe did not come back. The last MGlogs.zip file you attached had not been fully updated. Either you did not let it finish or something blocked you from running it. Make sure all protection software is shutdown and do the below again. Make sure it runs until it is finished. Last time you only let the first to scans run.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Theo2323

    Theo2323 Private E-2

    Please see files attached.

    Sorry about the late reply! Uni' has started back up.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your Windows Firewall and a couple other services are broken. Let's see if we can fix them. Shutdown your protection software before doing the below.


    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. Theo2323

    Theo2323 Private E-2

    Logs are attached. Once again, thank you!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That did not work. Did you get Windows Repair to run properly and all the way thru without any errors? Please try rebooting into safe mode and running Windows Repair in safe mode. Make sure it finishes and tell me about how long it takes to run. After it finishes, reboot into normal mode the run the same C:\MGtools\GetLogs.bat file again and attach the new MGlogs.zip file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds