Browser Redirects via Search Results and Various Links

Discussion in 'Malware Help (A Specialist Will Reply)' started by needsageek, Jul 24, 2010.

  1. needsageek

    needsageek Private E-2

    I'm having the same problems as some of the other people with browser redirects.

    Basically when i click on a link found thru a google or yahoo search i am being redirected to various spam sites. I thought this was exclusive to searches but find the same thing when i click links on websites as well.

    I've run various antivirus including HouseCall by microtrends and they all come up clean

    I'm posting the various logs i got. i was unable to run rootrepeal.

    MBRCheck, version 1.1.1

    (c) 2010, AD



    \\.\C: --> \\.\PhysicalDrive0

    \\.\F: --> \\.\PhysicalDrive1

    \\.\K: --> \\.\PhysicalDrive7

    \\.\L: --> \\.\PhysicalDrive8

    \\.\M: --> \\.\PhysicalDrive8



    Size Device Name MBR Status

    --------------------------------------------

    465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected

    465 GB \\.\PhysicalDrive1 Unknown MBR code

    931 GB \\.\PhysicalDrive7 MBR Code Faked!

    298 GB \\.\PhysicalDrive8 Unknown MBR code





    Found non-standard or infected MBR.

    Enter 'Y' and hit ENTER for more options, or 'N' to exit:
     

    Attached Files:

  2. needsageek

    needsageek Private E-2

    superantispy
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are the drives 1, 7, and 8? Are they partitions or actual physical drives?
     
  4. needsageek

    needsageek Private E-2

    those are externals 7 an 8 are the same drive partitioned
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK.....

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.


    Now if you wish to continue and fix the malware - please do the following:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now you will have to repeat this for each of your physical hard drives.

    Now please re-run MBRCheck.exe and attach that log also.
     
  6. needsageek

    needsageek Private E-2

    ok ran the mbr without a hitch. got all codes regulated except for my one external

    MBRCheck, version 1.1.1

    (c) 2010, AD



    \\.\C: --> \\.\PhysicalDrive0

    \\.\F: --> \\.\PhysicalDrive1

    \\.\K: --> \\.\PhysicalDrive2

    \\.\L: --> \\.\PhysicalDrive7

    \\.\M: --> \\.\PhysicalDrive7



    Size Device Name MBR Status

    --------------------------------------------

    465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected

    465 GB \\.\PhysicalDrive1 Windows 7 MBR code detected

    931 GB \\.\PhysicalDrive2 MBR Code Faked!

    298 GB \\.\PhysicalDrive7 Windows 7 MBR code detected





    Found non-standard or infected MBR.

    Enter 'Y' and hit ENTER for more options, or 'N' to exit:
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. needsageek

    needsageek Private E-2

    ok ran that file attached. browser is still redirecting :cry
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now follow these instructions to make sure you do not have any proxy settings:
    Change Proxy Settings.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner! Then make sure these folders are emptied:
    C:\Windows\temp\
    C:\USERS\VIVARANT\LOCALS~1\TEMP\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. needsageek

    needsageek Private E-2

    ok ran everything my local settings temp folder would not empty completely

    tried ff and ie and still redirecting
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you plug your computer directly into your modem, does it still redirect? Are there other computers that you have running through your router and do they also have redirect issues. Is it with all browsers?
     
  12. needsageek

    needsageek Private E-2

    i connected directly to the pc and yes i still get the redirects. i have my macbook connected to the network and no it doesn't have the same problem
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. needsageek

    needsageek Private E-2

    i'm baack! sorry i've been so busy at work. here's the requested scan

    oh and yes still getting redirected sooooo frustrating
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall IE, then run CCleaner and then re-install IE8.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      wininit.exe
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  16. needsageek

    needsageek Private E-2

    here you go
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    C:\Windows.old\Windows\System32\wininit.exe | C:\Windows\System32\wininit.exe
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop

    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  18. needsageek

    needsageek Private E-2

    I'm not having so much luck with this one. I can't get the combofix to complete. it gets to stage 2 and then my pc shuts down and reboots. Upon reboot the CFscript.txt and TDSSKiller are no longer on the desktop.

    Is this normal, should i resume with the treatment or is something amiss?
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if Avenger will move it for us.

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  20. needsageek

    needsageek Private E-2

    Avenger wouldn't complete either. upon reboot the system wouldn't start without running repair with the only option as system restore
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you can boot to the recovery console and type in this command:

    copy C:\Windows.old\Windows\System32\wininit.exe C:\Windows\System32\wininit.exe

    Hit enter and then exit and next re-run ComboFix and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  22. needsageek

    needsageek Private E-2

    well this is embarrassing. i'm not quite sure how to boot recovery. can you give me a heads up on that. i'm on win7
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try using the newer version of TDDSKiller:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  24. needsageek

    needsageek Private E-2

    that was almost too easy. scan completed didn't take very long. nothing was found and log attached
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Now please create this disc using a different computer:
    Vista and Win7 Recovery disc
     
  26. needsageek

    needsageek Private E-2

    ok here you go. still having this trouble now the browser crashes if i go to any search engine
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this drive:
    931 GB \\.\PhysicalDrive2 MBR Code Faked!
    SHA1: 4A5BDE0B1A960DDBAF71013ADB04BCBB1B1E7F28

    Is it an external storage drive?
     
  28. needsageek

    needsageek Private E-2

    that is an external i use for storage
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run ComboFix and attach the log. Also, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds