Browser search results redirected

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sealowet, Apr 11, 2011.

  1. Sealowet

    Sealowet Private E-2

    I've read many threads with similar problems being repaired and noticed that each computer requires a specific analysis. I've downloaded atf-cleaner, tdsskiller, gooredfix and combo fix to my desktop to prepare for the possibilities of them being needed to solve this problem. Please contact me at your earliest convenience to assist me with the process of detecting and removing the infection. Any help you provide will be greatly appreciated!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Sealowet

    Sealowet Private E-2

    After going through all of the steps, #4 using TDSSKiller appears to have fixed the redirection problems I was having with the search results while using google chrome and yahoo internet explorer. I started the process yesterday, but I was very cautious about rebooting to remove the file located by TDSSKiller without knowing that I would have a professional to chat with if something did not go the way I hoped it would. Fortunately, I didn't have to take up as much of your time as I thought! Thanks TimW for responding back so quickly!

    Information like this is why I always choose MajorGeeks.com first when having computer issues or for reliable files! I should have registered to become a member a long time ago!!! :major
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's make sure it is fixed:
    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  5. Sealowet

    Sealowet Private E-2

    Thanks for checking up! Something else was detected when I ran MBRCheck.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is that an external drive? If so, it's nothing to worry about.
     
  7. Sealowet

    Sealowet Private E-2

    My external drive is on F:\ I disconnected it, and the check results show that no problem was found. Is it NOthing to worry about with my external drive? Or, is it a small thing that I shouldn't have to worry about?
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can deal with it. Plug the external back in and let's do this:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 1 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  9. Sealowet

    Sealowet Private E-2

    I have attached the log that was done before and after the reboot. My external drive is not being recognized now.
     

    Attached Files:

  10. Sealowet

    Sealowet Private E-2

    When I went to Computer Management to inspect my Disk Management, it has my external drive listed as Disk 1 Unknown Not Initialized with unallocated space. What needs to be done now? :confused
     

    Attached Files:

  11. Sealowet

    Sealowet Private E-2

    A file named MBRCheck_MBR_Backup_04-12-11_20-19-32.bak was created on my desktop. After trying to see if it would work in a different computer, it was initialized and now showing as being online, but it's still unallocated and not showing up to allow the files to be accessed. That's all the information I can think of to provide before you respond which will help with determining the possibilities of a solution. The MBRCheck doesn't erase all of the data on an external drive, does it?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBRCheck shouldn't have erased anything. It is notorious for not understanding external drives and gives an "Unknown" report for them. Please post in the software forum for additional guidance with getting the external drive recognized again.

    Are you still having any malware issues?
     
  13. Sealowet

    Sealowet Private E-2

    Would you happen to know how to use the .bak file created by MBRCheck to restore things back to a previous state?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It should just be a matter of double clicking it. Let me know.
     
  15. Sealowet

    Sealowet Private E-2

    Ok... I'll try that now.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know, as I have never had to do that.
     
  17. Sealowet

    Sealowet Private E-2

    Double clicking on the file didn't work. Windows cannot open this file: To open this file, Windows needs to know what program created it. That's the message that popped up. Do you know of a program that can open it?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try right clicking and choose Open with and then point it at MBRCheck.
     
  19. Sealowet

    Sealowet Private E-2

    Right on time! I was just thinking about partitioning all of the space of my external hard drive without formatting it to see if it would alter the MBR to make it accessible. I just opened The MBRCheck.bak file the way you suggested. Unfortunately, it didn't recognize the drive.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you post in the software forum for help with this issue. I don't have a clue as to why it is suddenly not being recognized.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  21. Sealowet

    Sealowet Private E-2

    Ok... Thanks for your help with fixing the problem with being redirected! I'll check out the software forum as you suggested.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck and safe surfing. :)
     
  23. Sealowet

    Sealowet Private E-2

    Testdisk recovered my partition and repaired the bad boot sector on my external hard drive by analyzing it and finding a backup boot sector file on it to overwrite the one with errors! The file system on my external hard drive was changed to RAW, but Testdisk changed my file system back to FAT32 allowing my drive to be recognized so that I can access all of my files again! I attached the testdisk log just in case my problem was slightly different from others and can be used in any way for assisting others with similar problems in the future.

    Thanks for all of your knowledgeable assistance! :major
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is good news!! Glad you are back up and running with the external. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds