Google Redircts AGAIN

Discussion in 'Malware Help (A Specialist Will Reply)' started by Deans, Apr 4, 2012.

  1. Deans

    Deans Private E-2

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please tell me, which browser(s) are suffering with the redirection? Is it Internet Explorer?
     
  3. Deans

    Deans Private E-2

    Hey

    Yeah IE
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    c:\windows\Tasks\At1.job <--- Delete this.

    I would like to make an observation, and that is, that you seem to like to download a HELL of alot of games/demos etc. This is something that could be inviting in something untoward, although as it stands, I am not seeing ANY malware in those logs.

    You also didn't ever work this one thread of yours through to completion.

    I think it might be worth you installing Internet Explorer 9 and then tell me how that behaves please.
     
  5. Deans

    Deans Private E-2

    I am downloading IE9 now, hopefully this fixes it.

    In my last thread, I should everything that I was told to do, whatever the google redirect was, did go away but came back whenever I restarted the computer. Eventually it went away and I left it, but now its back. I havent download any huge file games in a while as I was hesitatant from the google redirect last time.
     
  6. Deans

    Deans Private E-2

    oh and I changed virus protector from that silly titanium one to now Norton 360
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK when you get chance let me know how IE9 behaves.
     
  8. Deans

    Deans Private E-2

    Ok im still getting redirects
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download Firefox and tell me if you have redirects in that too.
     
  10. Deans

    Deans Private E-2

    still redirects
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to elaborate on this. Tell me exactly what is happening when you say you are being redirected.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you still with me? :)
     
  13. Deans

    Deans Private E-2

    Yes still with you, sorry stopped using the computer as the redirects are driving me insane.

    Whenever I try googling something anything, and then follow a link within google, I will then be redirected to another completely different site. This will happen every time and redirects me 3 times before going to the actually site im after. Sometimes it redirects me to unsafe sites that my norton will stop thank god.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (How to attach)


    ----------------------


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  15. Deans

    Deans Private E-2

    Ive uploaded the logs but I never got the extra.txt from OTL only the OTL.txt
     

    Attached Files:

    • FRST.txt
      File size:
      74.5 KB
      Views:
      5
    • OTL.Txt
      File size:
      126.1 KB
      Views:
      4
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seeking advice on something. Determined to get to the bottom of this.
     
  17. Deans

    Deans Private E-2

    ok thanks, is there something really wrong with my comp?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes something is wrong for you to keep having the redirects. Now some advice from thisisu...
    • I want you to uninstall Daemon Tools.
    • Then download and run the latest TDSSKiller version 2.7.28.0 and attach the new log for me to see.
    • I also want you to run a scan with Hitman Pro 3.6.0.152 see what that comes up with. Let me know.
    • Now, when you are being redirected, the sites you end up on, I want you to private message me the links of a couple of these sites please.
     
    Last edited by a moderator: Apr 14, 2012
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also: (Advice from Chaslang)

    You are using a DNS server within your router. Try two things:

    By pass the router completely and see if you still get redirected.
    If you do not, then reset the router back to factory defaults and also update the firmware if there is a new version available.

    Obviously this assumes that your router is not built into an ISP's modem of any form and is a separate external device.
     
    Last edited by a moderator: Apr 14, 2012
  20. Deans

    Deans Private E-2

    I tried exactly what you asked with by passing the router and reset router, both still had redirects. Is it bad using a DNS server?
     
  21. Deans

    Deans Private E-2

    logs attached below
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Give TDSSKiller another run that was an incomplete log. :)
     
  23. thisisu

    thisisu Malware Consultant

    This log is both incomplete and is from an old version of TDSSKiller.
    As previously advised, please download and run the latest version here. - v2.7.28.0
     
  24. Deans

    Deans Private E-2

    Ok new log, hopefully this is completed.

    Also still getting redirects
     

    Attached Files:

  25. thisisu

    thisisu Malware Consultant

    The log you keep attaching is from running an old version of TDSSKiller.
    In order for us to be thorough we need you to complete a scan using the latest version of TDSSKiller.

    It is also supposed to be run with the parameters requested here: TDSSkiller - How to run
     
  26. Deans

    Deans Private E-2

    Ok ill try again, but I am clicking on the link provided and running scan through that so not sure why its using the wrong version.
     
  27. Deans

    Deans Private E-2

    When clicking on the link provided for the new version of TDS Killer, once downloaded, it will go straight to "choose program to open" then wont work???
     
  28. thisisu

    thisisu Malware Consultant

    I'm not sure I understand the question. Please rephrase it.
     
  29. Deans

    Deans Private E-2

    When I click on the TDSKiller link that you have provided, it downloads but once downloaded and I try to run the program, it opens up with a dialog box asking to pick a program to open TDSKiller, if I cancel the box then it saves on my desktop as a blank file
     
  30. Deans

    Deans Private E-2

    the only version I can get to work on my computer is 2.7.31.0
     
  31. thisisu

    thisisu Malware Consultant

    Please scan with this one then. Refer back to TDSSkiller - How to run if you need help
     
  32. Deans

    Deans Private E-2

    Ok I have attached the log
     

    Attached Files:

  33. thisisu

    thisisu Malware Consultant

    This log looks clean. Please PM me the link you are being redirected to.
     
  34. thisisu

    thisisu Malware Consultant

    I received the links, thank you.

    Please follow these instructions:

    http://img805.imageshack.us/img805/9659/rktigzy.gif Please download RogueKiller to your desktop.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    When it is finished, there will be a log on your desktop called: RKreport[1].txt
    Attach RKreport[1].txt to your next message. (How to attach)

    __

    http://img205.imageshack.us/img205/1894/otl.gif Please download OTL by OldTimer.

    • Save it to your desktop.
    • Right mouse click on the OTL icon on your desktop and select Run as Administrator
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      /md5start
      acpi.sys
      Wdf01000.sys
      /md5stop
      %windir%\system32\drivers\*.sys /lockedfiles
      %windir%\*.* /mp
      %windir%\*.* /rp
      %windir%\*.* /sl
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
    Last edited: Apr 25, 2012
  35. Deans

    Deans Private E-2

    logs below
     

    Attached Files:

  36. thisisu

    thisisu Malware Consultant

    I think I found the culprit but let me know how the system runs after you run this fix.

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:processes[/COLOR]
    killallprocesses
    [COLOR="DarkRed"]:otl[/COLOR]
    IE - HKU\S-1-5-21-2631899679-1180466060-1752027397-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=AU&ver=5
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} https://www.select2perform.com.au/cabs/QOLCheck.ocx (QOLCheck Control)
    [2012/04/08 10:38:52 | 000,000,000 | ---D | C] -- C:\ProgramData\DriverGenius
    [2012/04/08 10:30:11 | 001,667,264 | ---- | C] (W3i, LLC) -- C:\Program Files (x86)\FreeFileViewer2011Setup.exe
    @Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:090FB735
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:5C6EBC69
    @Alternate Data Stream - 156 bytes -> C:\ProgramData\Temp:3790BACD
    @Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:DF01DCBC
    @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:C82210DD
    @Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:274516E7
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A4BF246C
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:6B86037F
    @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:89C2A42C
    @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:D2A5A561
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B36361EE
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:98DFF516
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:3A6BC948
    @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:A11AE118
    [COLOR="DarkRed"]:commands[/COLOR]
    [resethosts]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)
     
  37. Deans

    Deans Private E-2

    Wow yay finally the google redirects are gone, but my computer is running slower and same with the internet, would that just be because it needs a general clean out?
    I have attached the log below.

    Thank you so much for helping, but will it come back again like it has happened before? Is there anything I can do before posting a new thread if it does come back?

    THANK YOU :-D
     

    Attached Files:

  38. thisisu

    thisisu Malware Consultant

    I'm glad to hear that.
    It could be slow due to other reasons. See: Slow Computer/browser? Check Here First; It May Not Be Malware

    You're welcome.
    It shouldn't come back but the problem was never taken care of in your previous thread.

    Just go through the Fixing Google Redirection/hijacking and other redirection problems thread.

    My pleasure :)

    __

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds