Another Google search redirect malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by |-|ybrid, Jun 26, 2010.

  1. |-|ybrid

    |-|ybrid Private E-2

    Hi there, I've tried all the conventional things and I'm at a loss.
    Two days ago, I was surfing the net with Firefox when I was hit by crippling lag in my YouTube videos, and my browser got hit with a "Your flash extension has crashed" message on all my videos. Throughout the day, my YouTube videos were just as slow as I discovered for the first time a program running in the background called plugin-container.exe. As it turns out, it was harmless, but it still took a lot of system resources.
    Later in the afternoon, in an unrelated incident, I was on a file-hosting site (that I wasn't familiar with) and Avira told me that it had found something, and that it had taken care of it.
    This is when I started noticing the Google search redirection. Every time I searched something, about 1 out of 3 links would link to random web pages, usually marketing or webhosting services, but one thing was consistent: the logo was always either a green sphere or a stylized 'e' of a bluish color. Web pages of this kind have also been occasionally popping up in separate tabs.

    It's been two days now, and the issue has not gone away. I have scanned with AVG, Avira, Malware-bytes (log attached), Spybot-S&D, AdAware, SmitFraudFix (log attached), GooredFix, cleaned the registry with CCleaner, logged with HijackThis (log attached), MGTools (log attached) and Anvir, flushed the DNS with ipconfig, cleaned my internet history and Java history repeatedly... to no avail. Every time one of these processes finds and kills something, it seems to have been solved only to reappear 5 minutes later.
    I did find one file: iexplorer.exe. This file is meant to look like the Internet Explorer process, but is in fact a Trojan. It might be unrelated though, as when I dug deeper, I found that it had disappeared.
    This problem doesn't seem to occur with IE6 (yeah I haven't updated it), but I'd rather fix this issue with Firefox instead of ignoring it on the count that it might be damaging other parts of my system... or worse, logging my information.

    I know that you guys have a formality whereby one must run all these programs and upload their respective logs to get some help with this, but I just discovered your forum and I'm the end of my rope here. I've lost so much sleep trying to fix it; it is not the most destructive virus I've had on this computer, but it is the most persistent. I've tried all the other snake-oil measures put forth in the other forums without any results. HELP!


    P.S.: I'm not sure I did it right with the whole MGTools thing, so bear with me
     

    Attached Files:

  2. |-|ybrid

    |-|ybrid Private E-2

    Nobody has a solution?
     
  3. |-|ybrid

    |-|ybrid Private E-2

    This is my ComboFix log.
     

    Attached Files:

  4. |-|ybrid

    |-|ybrid Private E-2

    Nevermind, I think ComboFix fixed it.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes it did which is why ComboFix is in our default cleaning procedure (READ & RUN ME FIRST. Malware Removal Guide ) which should have been run before posting and it should have been run before MGtools too. ;)

    Also for future reference, see this sticky: Don't Bump! It Only Hurts You!!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds