Browser re-direct: help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by GeekyBilly, Feb 18, 2007.

  1. GeekyBilly

    GeekyBilly Private E-2

    Greetings,
    I am new to the forums here, but have heard great things about this site.

    My girlfriend got the trojan.zlob virus on her laptop 02/15. While I think it is completely gone, our Google and Yahoo search results are now being redirected to other search engines instead of the desired destinations in Internet Explorer only (this doesn’t happen in Firefox). I searched the forums and see that others are having this problem too, but I’d like advice on what to do next before going any further.

    Last night, I read and followed all of the instructions in the ‘Read & Run Me First. Malware removal guide’, and in ‘Downloading, Installing, and Running HijackThis’, -- I’ll post all the logs.
    I also looked in ‘Special Removal Procedures - TitanShield… etc’ post -- I thought it would be in the ‘Win32.Zlob’ section, but that seems to be the wrong direction.

    I realized this morning that I did not have the most current version of Sun Java Runtime Environment. (doh!) I’m uninstalling the old/ installing the current after I post this, but I don’t think it affected my scans. Please let me know if this assumption is wrong.

    I will attach (in 2 posts):
    1. Counterspy.txt
    2. Bitdefender: I could not run this in safe mode w/ networking as I could not connect to my wireless internet, so I ran it in normal mode.
    3. Panda: Activescan.txt
    4. Runkeys.txt
    5. Newfiles.txt
    6. hijackthis.log

    Please let me know what else you need from me. I appreciate your time and assistance.
    -Bill
     

    Attached Files:

  2. GeekyBilly

    GeekyBilly Private E-2

    Here are the next 3 files:
    Runkeys.txt
    Newfiles.txt
    hijackthis.log

    Thanks again,
    Bill
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please delete this folder:
    C:\Documents and Settings\All Users\Application Data\Viewpoint

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://orca.aifs.com/ORCA/Security/Login.aspx?ReturnUrl=/orca/Common/default.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
    F2 - REG:system.ini: Shell=
    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - (no file)

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  4. GeekyBilly

    GeekyBilly Private E-2

    Hi TimW,

    Thank you for your help thus far! Here's what I have:

    DELETED.

    Done. Successful.

    Ran HJT.
    Found all above mentioned entries.
    Checked them off.
    Closed my Firefox window.
    Clicked 'Fix'.
    Exited HJT.

    ATTACHED.

    After running these again, I closed each program. I then opened Internet Explorer, typed "www.google.com" in the address bar, then performed my search (this time, "Blink 182"). I clicked on the link to Blink's home page, but it still redirected me to another search engine.

    I notice 2 things:
    1. When I open IE7, the main Toolbar (File, Edit, etc) is permanently visible, yet I never set it to be this way (I used to have to push the 'Alt' key for it to appear).
    2. Before doing your suggestions, the Status bar in my Google or Yahoo search results page would show some crazy-long address. After doing your suggestions, when i hover over a results link, the status bar shows the correct address, yet clicking it still redirects. It first goes to some long address starting with '216.133.243.28', then goes to some random search page.
    I don't know if this info helps, but figured I'd share it anyhow.

    Please let me know if you need further info.
    Thanks again,
    Bill
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the new logs that were requested.
     
  6. GeekyBilly

    GeekyBilly Private E-2

    I'm sorry. Here they are.
    :eek:

    Thank you,
    Bill
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you cleaned out your internet temp files?
    These are showing in your registry:
    C:\\DOCUME~1\\PAULAP~1\\LOCALS~1\\Temp\\CLCLEA~2.SH! C:\\DOCUME~1\\PAULAP~1\\LOCALS~1\\TEMPOR~1\\Content.IE5\\8BXAN5GR\\APP_1_~1.SH! C:\\DOCUME~1\\PAULAP~1\\LOCALS~1\\TEMPOR~1\\Content.IE5\\8BXAN5GR\\NO_CON~2.SH! C:\\DOCUME~1\\PAULAP~1\\LOCALS~1\\TEMPOR~1\\Content.IE5\\8BXAN5GR\\DW_PAS~1.SH! C:\\DOCUME~1\\PAULAP~1\\LOCALS~1\\TEMPOR~1\\Content.IE5\\HRT1DZMV\\DC_1_~1.SH! C:\\DOCUME~1\\PAULAP~1\\LOCALS~1\\TEMPOR~1\\Content.IE5\\8BXAN5GR\\DW_PAS~2.SH! C:\\DOCUME~1\\PAULAP~1\\LOCALS~1\\TEMPOR~1\\Content.IE5\\6P47HF88\\IN591D~1.SH!

    Have you run CCleaner ...both the cleaner and the issues (making sure to do the backup when prompted!)
     
  8. GeekyBilly

    GeekyBilly Private E-2

    Hi again,

    I'm Sorry about that. I did run it when following the initial instructions, but my girl had gone online again.

    I have just run CCleaner (both Cleaner & Issues) in Safe Mode, in each of the profiles (Admin, my girls, & mine) and backed up each time. After that, I ran SpyBot in each profile and it found no problems.

    After that, I ran GetRunKey, ShowNew, and HJT. These fresh logs are attached. Please let me know if you need anything else.

    At your convenience, let me know what you see. Sorry for the time-waste! Thank you again for the help.
    -Bill
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean:

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  10. GeekyBilly

    GeekyBilly Private E-2

    Hi TimW,

    First and foremost, thank you for all of your help. It feels like I'm 97% done.

    1) We did not use Pocket Killbox -- I downloaded it this morning in case I will need it later.
    2-5) N/A -- didn't use
    6) I removed the .reg files from my desktop.
    7) Deleted the .zip & .txt filed mentioned.
    8) Toggled the System restore per instructions.
    9) Working on it.

    Now, the Internet Explorer hijack/redirect is still being attempted, with Google searches only. Yahoo search results are no longer being redirected.

    In my Google searches, if I search for a Google service (I typed in 'Gmail' and 'Google Maps'), the search result links can be followed without problem. But when I search for other things (this a.m. I used 'Green Day', then 'Chamber Music'), these search result links yield a message when I try to follow them, saying something like 85.255.119.188 is trying to redirect to 64.111.198.178. Do you want to allow this? I click No, and get the 'page cannot load' message. (I looked up these IP addresses and they seem to be linked to spammers, which I kinda figured would be the case).

    Please let me know what you think.
    (note: I'm back at work today, so cannot access the laptop until 6p.m.)

    Thank you again for all of your time and assistance.
    -Bill
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you remove all google programs and toolbars. It is trying to redirect to spammers, though it is not showing in your logs.

    To be certain:

    Please download FixWareout by LonnyRJones from one of the two below links and save it to your desktop.

    http://downloads.subratam.org/Fixwareout.exe
    Or
    http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

    * Run Fixwareout.
    * Click Next,
    * then Install,
    * make sure Run fixit is checked
    * and click Finish.
    * The fix will begin; follow the prompts.
    * You will be asked to reboot your computer; please do so.
    * Your system may take longer than usual to load; this is normal.

    When you run fixwareout, just follow the prompts, you will need to restart when prompted.

    After rebooting (restart) back into normal boot mode, make sure you have all web browsers closed.

    * Go into Control Panel -->Network Connections.
    * Right click on your connection
    * and click Properties.
    * On the Properties page, highlight Internet Protocol(TCP/IP)
    * Click Properties. This will bring up another page.
    * Select Obtain DNS Server Automatically.
    * Click the ok button. The page will close.
    * Press ok on the page in front of you.
    * Restart the computer.
    * Reconnect to the Internet using Internet Explorer.
    * Now come back here and attach the log from fixwareout. It is located at c:\fixwareout\report.txt

    Also attach the ShowNew, GetRun and HJT
     
  12. GeekyBilly

    GeekyBilly Private E-2

    Hi Tim,

    Thanks for that. It seemed to do the trick!

    All seems to be working correctly, searches working properly.

    I'll attach 3 logs here; the 4th (Fixwareout log) after.

    We'll use the computer more this evening, I'll let you know how it goes.

    Thanks again,
    Bill
    :)
     

    Attached Files:

  13. GeekyBilly

    GeekyBilly Private E-2

    Here's the Fixwareout report.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That does look like it found the hidden remnants ....your logs look clean. You can uninstall any software that we had you download, as per the previous post.
     
  15. GeekyBilly

    GeekyBilly Private E-2

    Hi TimW,

    24 hours later, and everything is working correctly!

    A big, huge THANK YOU, from me and my girl to you and MajorGeeks. You solved our problem in less than 3 days -- I didn't think that was possible!

    You rock. Keep it up.

    :wave
    -Bill
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome ....safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds