Google Redirect Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by bmw330ci2004, Oct 14, 2010.

  1. bmw330ci2004

    bmw330ci2004 Private E-2

    Hey folks,

    I am another person who had the AntiVirus Studio 2010 virus. I seemed to have gotten it cleaned up for the most part using Malwarebyte's Ant-Malware software but still have a lingering issue. I no longer have the fake antivirus software popping up but still have a browser hijacker that redirects my browser to other webpages. One of the most common being Infomash. I have the problem in Explorer and Firefox. As per the "READ & RUN ME FIRST. Malware Removal Guide" thread, I have attached the required log files. I performed all the steps but now my McAfee virus scanner quarantined explorer.exe and my computer no longer starts up properly. All I get is a blue screen but can open up task manager to run any applications.

    Could someone please help as I am completely unsure as to how to fix this problem?

    Any help is very much appreciated!
     

    Attached Files:

  2. bmw330ci2004

    bmw330ci2004 Private E-2

    .... and here is the final log file.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, bmw330ci2004.

    You have an active thread here: http://www.bleepingcomputer.com/forums/topic352537.html

     
    Last edited: Oct 14, 2010
  4. bmw330ci2004

    bmw330ci2004 Private E-2

    Hi dr.moriarty,

    I have requested that the thread at bleepingcomputer (which I posted a week ago) be closed which is the only other place I have posted. Please refer to:

    http://www.bleepingcomputer.com/forums/index.php?showtopic=352537&st=0&gopid=1975582&#entry1975582

    I apologize for the inconvenience but am desperate to try and get this issue fixed. I humbly ask to have my request put back in the queue.
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, bmw330ci2004

    Let's begin by removing malware, then we need to use the Recovery Console.

    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the "Input script here:" part of the window.
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    You will need your Windows Boot disk so you can get to the Recovery Console to do the below:
    • Set the bios to boot to the cd-rom first. Then boot to the xp cd and get into the recovery console.
      The following steps will assume that your CD drive is D so change this to the appropriate drive letter if yours is different.
    • Once you are back to the C:\Windows> prompt of the Recovery Console, input the below brown bold font commands one at a time each followed by the enter key. Read the notes further down which comment on these commands.

    cd system32
    copy D:\i386\winlogon.ex_ winlogon.exe
    exit


    Notes:
    • the first command should cause the prompt to change to C:\windows\system32>
    • the second command should copy the compressed winlogon.ex_ file ( yes the underscore is the correct file name ) from the i386 folder of your CD into the system32 folder and rename it to winlogon.exe, the file will automatically be uncompressed. Notice the space after the copy and after the ex_.

    Re-boot AGAIN into Recovery Console:
    • Once you are back to the C:\Windows> prompt of the Recovery Console, input the below brown bold font commands one at a time each followed by the enter key.

    copy D:\i386\explorer.ex_ explorer.exe
    exit
    • Remove your CD and reboot normally.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  6. bmw330ci2004

    bmw330ci2004 Private E-2

    Hi dr.moriarty

    Thank you so much for the help! It is very much appreciated. Here is an update of how things have gone.

    I attempted to complete the steps as described below. I might add it is a little tough having to do it with out Explorer running. After Explorer was quarantined by my Anti-Virus software, when I boot up all I get is my screen background with no icons or any menu or tools bars. It is basically blank except for the screen background. I have had to use the task manager, and launch applications that way. I have completed the first few steps (Avenger (see attached log), CCleaner). The problem is that when I boot from the Windows CD, things start well but I end up getting a blue screen with the following error:

    =======================================================
    A problem has been detected and Windows has been shut down to prevent damage to your computer.

    If this is the first time you've seen this Stop error screen restart your computer. If this screen appears again, follow these steps:

    Check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated. Run CHKDSK /F to check for hard drive corruption, and then restart your computer.

    Technical information:

    *** STOP 0x00000078 (0xF78D2524, 0xc0000034, 0x00000000, 0x00000000)
    ========================================================

    Please advise how I can rectify this situation. Could I not just boot the machine normally (with he blank screen), go to the command prompt to make the copy without booting from the CD first?
     

    Attached Files:

  7. bmw330ci2004

    bmw330ci2004 Private E-2

    UPDATE!!!!!

    Hi dr. m.,

    I have an update! I was able to complete the rest of the steps. I got around the blue screen problem my booting from a USB CD. The Stop code seemed to have something to do with the ATA CD driver. Everything went as planned this time.

    I have attached the MGtools.zip file as requested.

    Things seem to be running well right now but I just completed the tasks 15 minutes ago.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :highfive

    Good work, bmw330ci2004!

    I think we're almost done.

    Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\Devin\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Please run this:
    Using ESET's Online Scanner

    *EDITING for additional step:

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the eSetlog.txt and the new C:\MGlogs.zip to your next reply.

    How's your machine running?

    dr.m
     
    Last edited: Oct 19, 2010
  9. bmw330ci2004

    bmw330ci2004 Private E-2

    Hi dr. moriatry!

    I have completed the steps as documented and have attached the logs.

    My machine seems to be running normally as I do not notice any of the problems that I had before.

    dv
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool

    The last vestiges of the infection should be gone when you flush your restore points with the instructions included below:

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to Add/Remove programs (Programs and Features if using Vista or Windows 7) and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  11. bmw330ci2004

    bmw330ci2004 Private E-2

    Hi dr. moriarty,

    I have completed the finals steps!... YAH!!!

    I would sincerely like to thank you for taking the time out of your day to help me out. I cannot tell you how much I appreciated it!

    You folks at Majorgeeks.com provide a fabulous service to the internet community!
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're very welcome!

    Your note of "Thanks!" is much appreciated by us all.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds