Google Link redirection virus and security center inactive + Claro

Discussion in 'Malware Help (A Specialist Will Reply)' started by olivier.chagnefercoq, Feb 9, 2013.

  1. olivier.chagnefercoq

    olivier.chagnefercoq Private E-2

    Dear Computer Doctor,

    I am having trouble with a virus for some time. In the beginning, it was benign problems that disappeared after a while. However, since yesterday, the Google results are all redirected to unwanted websites. This is also true for Yahoo but not for www.voila.fr. The security center and Windows Defender do not work but my Antivirus is OK. I had AVG but I changed it to Avast in case it had been corrumpted. I first tried to find the virus by following various forums, unsuccessfully. Finally, I read your read and run me first malware removal guide and I run it.

    You will find the logs of the various softwares attached. Nothing serious appeared up to HitmanPro scan where it detected a threat called Claro. The information I could see on this matches well my case but I seem to have got the well hidden version of the virus. As you clearly tell us not to do any attempt with HitmanPro, I am waiting for your instructions.

    Thank you a lot for your help.
    Best regards,
    Olivier
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Some left overs from AVG still exist. We will remove them in the below fix.

    Uninstall the below very old versions of software:
    Java(TM) 6 Update 13
    Java(TM) 6 Update 7

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
     
    :Files                 
    C:\Users\Olivier Fercoq\AppData\Roaming\Microsoft\Windows\Templates\731v358827u4o32305lpp73
    C:\Boonty
    C:\Windows\Tasks\WNZSX.job
    C:\Windows\temp\*.*
    C:\Users\Olivier Fercoq\AppData\Local\temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{80490945-CE48-45CF-9CCA-CA0EF44D9FE4}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1E1300BC-6DBA-476B-8CCF-4AA81ED4DF6A}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\Boonty Games]
    [-HKEY_USERS\S-1-5-21-2292164982-347243382-2611293809-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{0BF43445-2F28-4351-9252-17FE6E806AA0}"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.txt log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. olivier.chagnefercoq

    olivier.chagnefercoq Private E-2

    Hello !
    I first uninstalled Java 6 update 7 but I could no uninstal Java 6 update 13 because the file jre1.6.0_13-c-l.msi does not exist on my computer.
    I followed your instructions and I had to launch OTM twice because it frozed up the first time.
    Well, there seems to have been some work done (see the logs attached) but my problems remain. Google and Yahoo links are redirected, the security center and windows defender do not work.
    I am looking forward to hearing of you again.
    Best regards,
    Olivier Fercoq
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm assuming your problem is with Internet Explorer. Try running it without addons and see what happens. Also you can run IE and click on Tools, Manage Add-ons and try disabling all addons to see if that changes anything.

    For you problem with Windows Defender and Security Center, you need to check to make sure the services are running. Based on your logs ( hard to read due to non-English language ) it seems that they are not running.
    Code:
        ----------------------------------------------------------------------------
        Windows Defender service   -WinDefend-               is NOT running  
     
    [SC] QueryServiceConfig r‚ussite(s)
    SERVICE_NAME: WinDefend
            TYPE               : 20  WIN32_SHARE_PROCESS 
            START_TYPE         : 4   DISABLED
            ERROR_CONTROL      : 1   NORMAL
            BINARY_PATH_NAME   : C:\Windows\System32\svchost.exe -k secsvcs
            LOAD_ORDER_GROUP   : COM Infrastructure
            TAG                : 0
            DISPLAY_NAME       : Windows Defender
            DEPENDENCIES       : RpcSs
            SERVICE_START_NAME : LocalSystem
        ---------------------------------------------------------------------------- 
        ----------------------------------------------------------------------------    
         Windows Security Center service  -wscsvc-           is NOT running  
     
    [SC] QueryServiceConfig r‚ussite(s)
    SERVICE_NAME: wscsvc
            TYPE               : 20  WIN32_SHARE_PROCESS 
            START_TYPE         : 4   DISABLED
            ERROR_CONTROL      : 1   NORMAL
            BINARY_PATH_NAME   : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
            LOAD_ORDER_GROUP   : 
            TAG                : 0
            DISPLAY_NAME       : Centre de s‚curit‚
            DEPENDENCIES       : RpcSs
                               : winmgmt
            SERVICE_START_NAME : NT AUTHORITY\LocalService
        ----------------------------------------------------------------------------
    But the registry entries do exist.

    Try running the below.



    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
    Last edited: Feb 12, 2013
  5. olivier.chagnefercoq

    olivier.chagnefercoq Private E-2

    Hello !

    Sorry for the language, I have the French version of Windows. I did not know it was important for the logs because they seemed to be in English. Do you think I should contact a French equivalent of this forum (if there exists one)?

    Well, I have disabled all the add-ons of Internet Explorer and launched Windows repair but the situation has not changed. In fact, when I try to start the Security Center manually from the Service Panel, it does start but stops after a few seconds. For Windows Defender, even this trick does not work: I get a message saying that Windows Defender has started but then has stopped because some services stop when they are not used.

    It does not seem normal to me that services stop without reason and it looks like a virus (HitmanPro's Claro threat or something else).

    Best regards,
    Olivier
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I have been on vacation for the last 10 days.

    I do not know about any similar forums that are French speaking.


    Please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
     
  7. olivier.chagnefercoq

    olivier.chagnefercoq Private E-2

    Hello !
    It seems that you have sent me good vibes during your holidays because when I tried to use Google today, it did work fine. I then went to the Security Center: no problem to open it and Windows Defender works again. Well, thank you very much for your help. All the things we have done must have cleaned the computer and then two weeks rest finished the work (although I did not know that computers could rest...) Thank you again and good luck!
    Best regards,
    Olivier
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds