Goggle Redirect

Discussion in 'Malware Help (A Specialist Will Reply)' started by CURIOUS1555, Jul 25, 2009.

  1. CURIOUS1555

    CURIOUS1555 Private E-2

    Hi, I truly appreciate any help you can give me on this: I keep getting redirected to ads and other places whenever I do a search. Also, my Windows updates fail to update. I'm new to this; I hope I have ran everything I was supposed to. I run Windows XP and hopefully I did everything you asked of me regarding reports and logs correctly.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Kes13!
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like to point out to you something regarding the below files:

    • c:\windows\virus071909.exe
    • c:\windows\erdnt071909.exe

    It is a very bad idea to download and permanently save files here. And if you want those files, you should move them somewhere safe. I almost included those in my fix as I suspected them as being malware considering they were located here. And infact, the virus071909.exe really looks like malware since it does not represent a recognized program name. I'm guessing that the virus071909.exe is actually mbam-setup.exe and if this is true, it was an extremely bad idea to rename it like this since it is not a virus, it is not an antivirus program, and in this name does not allow me to figure out what the file really is which would be a problem in the future.

    Let's carry on now --

    1. Please go to Add/Remove Programs and uninstall the following softwares:
    • Java(TM) 6 Update 11
    • Error Fix

    2. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    File::
    c:\windows\Tasks\Error Fix Scan.job
    C:\Documents and Settings\Brandi\My Documents\virus071909.txt
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    4. Now we need to replace a file, to do this please see the below:

    Running SFC Scannow

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  4. CURIOUS1555

    CURIOUS1555 Private E-2

    I followed your directions, copied the "Killall" lines and saved it as CFScript.txt. When I draged the file over Comboxfix, I got a txt error. It asked if I was trying to run CFScript.txt. It said that the file was misspelled???? When I put ok, the file quits running. They are both saved under desktop and the CFScript is not misspelled. Now what should I do?

    Thank you very much for your help, by the way.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like for you to go to the C:\MGtools folder, locate the ShowNew.bat file, double click it > let it run to completion and then attach the newfiles.txt log that it creates into your next reply.

    Thanks
    Kes
     
  6. CURIOUS1555

    CURIOUS1555 Private E-2

    I ran the newfiles.txt log. Here are the results. Thank you so much for any help you can provide.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please go to add/remove programs and uninstall the following software:

    • Ask Toolbar

    2. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds