Google Links Redirecting

Discussion in 'Malware Help (A Specialist Will Reply)' started by ranchwood, Jun 23, 2010.

  1. ranchwood

    ranchwood Private E-2

    I have followed all the steps for malware removal and cleaning of my computer. It seemed to work at first, searches were back to normal. But after a few searches, the links are redirecting again. I am attaching my logs. RootRepeal did not run on my system, it cause a blue screen. Thanks!
     

    Attached Files:

  2. ranchwood

    ranchwood Private E-2

    IE seems to be working, but Firefox is the problem.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put ComboFix directly on your desktop, not here:
    Running from: c:\downloads\cleaning\ComboFix.exe

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  4. ranchwood

    ranchwood Private E-2

    Here are the log files for Combofix and TDSS
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download HelpAsst_mebroot_fix.exe and save it to your desktop.
    Close out all other open programs and windows.
    Double click the file to run it and follow any prompts.
    If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.
    Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command, then hit Enter.

    helpasst -mbrt

    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.


    *In the event the tool does not detect an mbr infection and completes, click Start>Run and type the following bolded command, then hit Enter.

    mbr -f

    Now, please do the Start>Run>mbr -f command a second time.
    Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.
    Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.

    helpasst -mbrt

    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.

    No matter what happens with the above, attach the above logs and then immediately continue with the below in normal boot mode!

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    File::
    C:\WINDOWS\Temp\$$$dq3e
    C:\WINDOWS\Temp\$67we.$      
    C:\WINDOWS\Temp\mmw4
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * HelpAssistant log
    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. ranchwood

    ranchwood Private E-2

    I have attached the files that you asked for and a picture of an error message that occurred while running C:\MGtools\GetLogs.bat. I just let the bat file finish running and closed out that window first and then the error message disappeared. The other problem I have is that Combofix always tells me that AVG Internet Securty is running. I uninstalled this program a few weeks ago and have searched everywhere to try and find instances that it may be running but to no avail.

    Thanks for your help with this. The search works with Yahoo, but I assume this will quit working soon since the search with Google on Firefox is still redirecting.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your HelpAssistant user was not removed. Please do the last fix again. Make sure all protection software is disabled.

    Close out all other open programs and windows.
    Double click the file to run it and follow any prompts.
    If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.
    Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command, then hit Enter.

    helpasst -mbrt

    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.


    *In the event the tool does not detect an mbr infection and completes, click Start>Run and type the following bolded command, then hit Enter.

    mbr -f

    Now, please do the Start>Run>mbr -f command a second time.
    Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.
    Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.

    helpasst -mbrt

    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.

    No matter what happens with the above, attach the above logs and then immediately continue with the below in normal boot mode!

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):

    Code:
    KILLALL::
    File::
    C:\WINDOWS\Temp\$$$dq3e
    C:\WINDOWS\Temp\$67we.$ 
    C:\WINDOWS\Temp\hlktmp
    Folder::
    c:\documents and settings\HelpAssistant\
    Driver::
    AVG WatchDog
    AVG Firewall
    AVG9IDSAgent
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  8. ranchwood

    ranchwood Private E-2

    Ok, ran the new tests as instructed. I am attaching th logs. Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the new HelpAsst.log for TimW, but it appears that the fix failed again and a different method will be necessary. Do you have your Windows boot CD?

    Is this a Windows based PC or are you a Windows emulation enviroment under another OS. I see the below in your logs
    Code:
    System Manufacturer Sun Microsystems 
    System Model Sun Ultra 20 Workstation
    You may not be able to fix this if this is a non-standard environment with a non-standard boot record.
     
  10. ranchwood

    ranchwood Private E-2

    I am attaching the HelpAssist log as well. The machine is a Sun machine but is not running emulation.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to see the below log before creating the next fix.
    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
    • Command prompt window text can be copied to the clip board by right click on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.
     
  12. ranchwood

    ranchwood Private E-2

    Here is the output from remover.exe:

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    \\.\E: -> \\.\PhysicalDrive1
    \\.\Z: -> \\.\PhysicalDrive2
    MD5: 4b73686c4943d2450ca8a6222af5e06c

    Size Device Name MBR Status
    --------------------------------------------
    232 GB \\.\PhysicalDrive0 Controlled by rootkit!
    232 GB \\.\PhysicalDrive1 Controlled by rootkit!
    465 GB \\.\PhysicalDrive2 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]

    Boot code on some of your physical disks is hidden by a rootkit.
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Press any key to quit...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have all important data on the C and E drives backed up? If so, where? The Z drive which is a removable device.

    While much of the time, repairing the MBR can be safe, there is always the chance of a problem occurring especially when malware is at play. You don't have too much of a choice though since the only way to fix you infection is to attempt repair of the MBRs or you will have to manually delete all partitions, repartition, format, and reinstall from scratch which I would assume you want to avoid this second option.
     
  14. ranchwood

    ranchwood Private E-2

    Thanks for all your help with this problem. I figured it wouldn't be an easy fix. My C: and D: drives are not full so I was thinking of backup up the D: Drive to the C: Drive and then reformatting D: changing it to the master and reinstalling windows. Then slowly transferring data from C: to D: so that eventually I could get C: wiped clean too.

    Would this be a problem with the type of infection that I have? I wasn't going to transfer any programs, but reinstalling them instead.

    Again, thanks for the help.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Both the C & E ( Not D. According to your logs, D is a CD drive) are infected according to your log and both will need to be either cleaned or repartitioned to even have a chance to remove the MBR infection.

    The Z drive may or may not be infected. The unknown boot code could just indicate that it is really an unknown boot partition type, but could even be a sign of infection. I'm leaning towards it just being an unknown partition type.

    I recommend that you backup are important data first to the Z drive. Then we could attempt to fix your infected boot records. If the fix works, you will not have to repartition and reinstall. But at least if you backup, it is safer to try the fix afterwards.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds