Google Browser Hijacked - help needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by simon1066, Feb 21, 2011.

  1. simon1066

    simon1066 Private E-2

    When accessing google search results in Firefox I am redirected to various random sites instead of the intended page. I think the problem also occurred in IE but have been unable to recreate it. Problem started 1-2 months ago and occurs randomly. Examples of the redirects are: 'admarketplace' and 'arehntogniog'. As well as 'resetting' Firefox, I have tried these fixes, in order:

    Fixing Google Redirection/Hijacking Problems
    http://forums.majorgeeks.com/showthread.php?t=230267

    READ & RUN ME FIRST Malware Removal Guide (incl. spyware, virus, trojan, hijacker)
    http://forums.majorgeeks.com/showthread.php?t=35407

    Vista Malware Removal/Cleaning Procedure
    http://forums.majorgeeks.com/showthread.php?t=139681

    and even

    Alternative Scans
    http://forums.majorgeeks.com/showthread.php?t=80343

    The various logs are posted below (no additional post needed). Any help would be appreciated.

    saslog.txt - attached

    mbam.txt - attached

    MGlogs.zip - attached

    gooredfix.txt - attached

    Root Repeal did not complete:
    Failed with error: 'Attempt to read from address: 0x00000004'
    (A number of files in c:\Windows\* are 'Locked to the Windows API!')

    ComboFix did not complete:
    Combofix failed, stuck on: 'Attempting to create a new system restore point'
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does each and every user on this machine need to have admin privileges?? Not a wise idea anyway.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
    • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix exit HJT.

    Use windows explorer to find and delete these files:

    • C:\Users\Simon\AppData\Roaming\inst.exe
    • C:\ProgramData\xml26E5.tmp
    • C:\ProgramData\xml285D.tmp
    • C:\ProgramData\xml28EA.tmp
    • C:\ProgramData\xmlAAFE.tmp
    • C:\ProgramData\xmlABF8.tmp
    • C:\ProgramData\xmlACB5.tmp

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now rename Combofix.exe to cf123.com and try again to run it, if not in normal mode then try safe mode.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Still having redirects? It very well could be your router. There is a little button on the bottom ( on most models ) to reset it to factory settings. Do that. You may then need to go back into it to set any special setting that you may have set up originally. But do that first and see if that doesn't take care of it.

    You can test this theory by connecting directly to your modem and if the redirects stop, then you know it is the router that is infected.

    If the redirects are STILL occurring after that then you can let me know and we will uninstall Firefox and reinstall after cleaning up properly.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. simon1066

    simon1066 Private E-2

    Point taken regarding the admin privileges, thank you.

    Have followed all your instructions.

    'Make sure that you tell me if you receive a success message about adding the above
    to the registry' - Yes, success message received.

    Running Combofix (cf123.com)
    Normal mode: Hangs (45mins) on 'Attempting to create a new system restore point'
    Safe mode: Hangs (20mins) on 'Combofix is preparing to run'
    Note: on starting Combofix an alert appeared stating that my avast shields were still running, even though I had disabled them. This alert also appeared previously when following the various help threads. I had uninstalled avast but still the alert appeared.

    MGlogs.zip attached.

    I will check to see if the problem persists and try the router reboot again.

    Will get back to you either way.

    regards

    Simon
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes do report back with the status of the machine. I am off to work soon but shall return in a few hours time.
     
  5. simon1066

    simon1066 Private E-2

    Ok, the problem persists. Have reset the router and still no joy. I guess we need to reinstall firefox.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Back up your bookmarks, uninstall Mozilla Firefox, ensure that after uninstallation that no leftover folders remain such as:
    • C:\Program Files\Mozilla Firefox
    • C:\USERS\Your account\AppData\Roaming\Mozilla
    • C:\USERS\Your account\AppData\Local\Mozilla

    Run Ccleaner.
    Reboot the machine
    Reinstall Firefox.
    Let me know how things are running.
     
  7. simon1066

    simon1066 Private E-2

    Have uninstalled FF, removed all folder instances of 'Mozilla Firefox' and 'Mozilla' from all users. Rebooted and reinstalled, have not imported previously saved bookmarks. Unfortunately I am still getting FF google redirects.

    I guess we're running out of options?
     
  8. simon1066

    simon1066 Private E-2

    Also, just noticed that I am also getting the redirect in IE8. As I mentioned, I thought that this had happened previously but until now have been unable to replicate it. At least we know it's not just a FF problem.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  10. simon1066

    simon1066 Private E-2

    Ran OTL as per instructions. Only OTL.txt was created - attached
     

    Attached Files:

    • OTL.Txt
      File size:
      141.2 KB
      Views:
      2
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Think I found the problem, which showed all along in the newfiles.log, I had missed it.

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the Image textbox. Do not include the word Code

    Code:
    :files
    C:\Windows\System32\drivers\ute4nzcz.sys
    
    :otl
    DRV - (ute4nzcz) -- C:\Windows\System32\drivers\ute4nzcz.sys ()
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/burn4free/{4D749F45-5517-4C92-9C51-E00BBF7E32CA}
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
    @Alternate Data Stream - 76 bytes -> C:\Users\Simon\My Widgets:Roxio EMC Stream
    @Alternate Data Stream - 451 bytes -> C:\ProgramData\TEMP:05EE1EEF
    @Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:DBAC2017
    @Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:7250CDF6
    @Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:587EB586
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1CA73D29
    @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:6724CB45
    @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:BEB71B81
    @Alternate Data Stream - 1214 bytes -> C:\Users\Simon\Desktop\SO GREEN AND STILL KIDS LOVE THEM - New online shop an answer to eco-friendly kids entertainment.eml:OECustomProperty
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:E965A533
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:CE6885F1
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:3447AB86
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:2A096472
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    How're things running at this point? Any joy?
     
  12. simon1066

    simon1066 Private E-2

    OTLfix ran successfully - log attached.

    Getlogs.bat completed - MGlogs.zip attached.

    It may take me a while to determine if the issue's been resolved. I'll have to get back to you (UK time here)

    In the meantime - thank you very much for your help

    cheers

    Simon
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, UK time here for me too. The logs look good now. C:\Users\Simon\AppData\Roaming\inst.exe <--- Delete this file.

    Let me know if the redirects persist or not now that we have deleted the file I missed before.
     
  14. simon1066

    simon1066 Private E-2

    Alas, the redirects persist.
     
  15. simon1066

    simon1066 Private E-2

    I should add that I deleted the file, rebooted - problem persisted so I then ran CCleaner
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  17. simon1066

    simon1066 Private E-2

    Ok, that scan took a while.

    Rebooted into safe mode - no browser hijack problems evident with google in FF.

    Back into normal mode - immediate detection of a virus by Avast:
    Name: msaud32V.dll
    Original location: C:\Windows\System32
    Virus: Win32:MalOb-EI [Cryp]
    Action: moved to virus chest

    Ran ESET scan in normal mode: log attached

    I'm about to reboot and check google browser to see if problem persists, will post findings.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, when you have chance let me know. :)
     
  19. simon1066

    simon1066 Private E-2

    Google redirect seems to have been resolved. I've been through about 150 google search results with no redirects. I guess the virus flagged by Avast might have done the trick.

    So, unless anything was flagged by the ESET scan, I think we're done here.

    I'll get back to this thread if the problem arises again in the near future.

    Many thanks for all your help

    Simon
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's great! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds