Browser Search Result Redirect/Hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by Aircrew123, Jan 21, 2013.

  1. Aircrew123

    Aircrew123 Private E-2

    Hello

    I have a stubborn redirect virus thats affecting all my search engines. (Yahoo, Bing, and Google that I know of).

    The syptoms are that when I click on a search result, it redirects my browser to a different website. This only happens on after the first 1-2 clicks, that is to say my, first one or two results send me to the correct link, then the virus kicks in and redirects all subsequent clicks on search result links.

    I ran the Malware Removal Guide from your website and it initially appeared to have cured the problem. However, the next day the virus reappeared and subsequent rerunning of the steps in the guide did not cure the problem.

    I have attached all logs indicated in the Malware Removal Guide. When I ran the Guide, I followed all instructions to the very letter.

    The only indication of a problem I saw in any of the logs was that Hitman Pro found a file that it called Malware (C:\windows\sysWOW64\drmmgrtnf.dll). As directed in the Guide, I clicked IGNORE for all threats found by Hitman Pro.

    When you get a chance, please look over my logs and let me know if/how I can get rid of this infection. Thanks in Advance for your help and thanks for being one of the Good Guys! Cheers...:)
     

    Attached Files:

  2. Aircrew123

    Aircrew123 Private E-2

    1234
     
  3. Aircrew123

    Aircrew123 Private E-2

    All

    Another interesting manifestation of this virus is that when I open I.E. 9, the Processes Tab in Task Manager shows two (2) separate instances of the program. Whe I try to close one of them - they both end up closing.

    In my experience, this is not normal.

    R-
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to read this: Don't bump!! It only hurts you!!

    Babylon toolbar on IE <--- uninstall this junk.

    Re run Hitman and have it delete Potential Unwanted Programs and Malware. Show me the log from this please.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:

    • [TASK][SUSP PATH] thpm8596896086346983635 : \\.\globalroot\Device\HarddiskVolume2\Users\Ross\AppData\Local\Temp\thpm8596896086346983635.tmp -> FOUND

    Place a checkmark next to this item leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;*.local;<local>
    • O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
    • O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
    • O4 - HKCU\..\Run: [Google] "xidpwooedd.exe"
    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Program Files (x86)\WhiteSmoke Translator
    C:\Program Files (x86)\BabylonToolbar
    C:\Program Files (x86)\1cres.dll
    C:\Windows\tasks\ktetisz.job
    C:\Windows\system32\xidpwooedd.exe
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Re run RogueKiller - just a scan and attach log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. Aircrew123

    Aircrew123 Private E-2

    My apologies for the bumps, I'm forum challenged and an Old Guy so I don't know any better.

    Well Done Malware Ninja!!! All traces of the infection are gone.

    How do I donate $$$ to the good guys?

    Cheers and thanks again for being on the right team.

    :cool
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Aircrew. Attach those logs so I can be sure all evil is gone! :)


    See the link at the end of all my posts about Geekwear? You could show your appreciation by purchasing a T shirt perhaps!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds