Google Redirect Virus Gooredfix log

Discussion in 'Malware Help (A Specialist Will Reply)' started by HalpMeh, May 9, 2009.

  1. HalpMeh

    HalpMeh Private E-2

    Hi, Can you help??
    Firefox running on Windows XP, Google redirects maddeningly at seemingly random times, poiskin.ru shows up in the lower bar when this happens. I ran Gooredfix option 1. Here's the log:

    GooredFix v1.92 by jpshortstuff
    Log created at 10:34 on 09/05/2009 running Option #1 (Tatia)
    Firefox version 2.0.0.20 (en-US)

    =====Suspect Goored Entries=====

    C:\Program Files\Mozilla Firefox\extensions\{C194EAD5-04C4-494A-B4EB-E29C6CF8DC44}

    C:\Program Files\Mozilla Firefox\extensions\{BF42F590-AA06-4F3C-A367-418CB8B5A548}

    C:\Program Files\Mozilla Firefox\extensions\{BC32A55F-C305-4503-90DA-AECEA1D3C99F}

    C:\Program Files\Mozilla Firefox\extensions\{78876033-37C9-4692-A8C5-214F00A6454B}

    C:\Program Files\Mozilla Firefox\extensions\{54ACD14B-2245-42FB-A140-6339718F32D2}

    C:\Program Files\Mozilla Firefox\extensions\{47092E82-5493-40B6-B1E8-8326DBFA8DCB}

    C:\Program Files\Mozilla Firefox\extensions\{45F754D5-C5AD-4D14-9639-2AFCD3661139}

    C:\Program Files\Mozilla Firefox\extensions\{335C6DDB-25B7-4155-9C96-F030F6F9C2D6}

    =====Dumping Registry Values=====

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.20\extensions]
    "Plugins"="C:\Program Files\Mozilla Firefox\plugins"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.20\extensions]
    "Components"="C:\Program Files\Mozilla Firefox\components"



    ADMIN EDIT: May wish to read and follow the following READ & RUN ME FIRST. Malware Removal Guide and HOW TO: Attach Items To Your Post, many thanks, added it as edit to your post as not to bump it.
     
    Last edited by a moderator: May 9, 2009
  2. HalpMeh

    HalpMeh Private E-2

    OK.. I'm sorry to keep cutting and pasting these things, I can't find where the folders are to attach the files. Here's my Malwarebytes log:

    Malwarebytes' Anti-Malware 1.36
    Database version: 2102
    Windows 5.1.2600 Service Pack 2

    05/09/2009 8:00:48 PM
    mbam-log-2009-05-09 (20-00-48).txt

    Scan type: Quick Scan
    Objects scanned: 98047
    Time elapsed: 17 minute(s), 48 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 1
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Documents and Settings\Tatia\Application Data\Twain (Trojan.Matcash) -> Quarantined and deleted successfully.

    Files Infected:
    (No malicious items detected)
     
  3. HalpMeh

    HalpMeh Private E-2

    Last logs, Combofix and MGTools:
     

    Attached Files:

  4. HalpMeh

    HalpMeh Private E-2

    Sorry - one more log:
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I strongly advise you to immediately cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Now on to your malware cleaning.

    First you need to run MSconfig and put your PC into Normal Startup mode as we requested in step 1 of the READ & RUN ME. You need to remain in Normal Startup mode which is why it is called Normal Startup.

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Spybot - Search & Destroy 1.4
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the new SUPERAntiSpyware log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. HalpMeh

    HalpMeh Private E-2

    New SuperAntiSpyware log:
     

    Attached Files:

  7. HalpMeh

    HalpMeh Private E-2

    Combofix and MGTools logs:
     

    Attached Files:

  8. HalpMeh

    HalpMeh Private E-2

    I also followed all your other instructions. For the past few minutes at least, there has been no redirecting on Google and my computer seems to be running faster... preliminarily, it seems better.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. HalpMeh

    HalpMeh Private E-2

    OK... Everything's good... except, I have been trying to work thru the "How to protect yourself from malware" stuff and trying to download Windows XP Service Pack 3, I encountered an "access denied" error message. Tried looking at permissions as suggested and all was as it should have been. Any suggestions on this? ( I'm going back to the Windows troubleshooting website tomorrow)
     
  11. HalpMeh

    HalpMeh Private E-2

    One other thing I've noticed - starting yesterday, a black box headed WINDOWS\SYSTEM32\cmd.exe pops up around the time of boot-up. I've closed these boxes immediately and not let them do whatever they're doing, because I've never seen them before. Any thoughts on what this is?

    I will keep you posted on working through the final step; still attempting to update Windows XP To Service Pack 3.
     
  12. HalpMeh

    HalpMeh Private E-2

    Hi, Thanks for all your help so far - no more Google redirecting...It's awesome!!! :D

    I have not been able to install Windows XP Service Pack 3, Access Denied. Could something have happened to permissions or the registry keys during the cleanup procedures I followed, to stop allowing downloads of updates? I'm still trying the Windows troubleshooting suggestions to no avail. Three attempts at downloading the update have now failed. Any suggestions are welcome... :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not from the cleanup procedures themselves. Perhaps malware that you had caused a change. I suggest that you work thru the below link from Microsoft which discusses this update issue. You will probably need to do what is in the Advanced Troubleshooting section.

    http://support.microsoft.com/kb/949377

    Any additional problems on this should be worked in the Software Forum.
     
  14. HalpMeh

    HalpMeh Private E-2

    All rightie. Thank you so much for all your help... computer is virus free...Thanks so much!!! :):)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds