Google redirect virus HELP!

Discussion in 'Malware Help (A Specialist Will Reply)' started by monthehuang, Oct 25, 2010.

  1. monthehuang

    monthehuang Private E-2

    Tried all the cleaning procedures specified in the READ ME FIRST thread, didn't work, below is my hijack this log, please help! thks!

    Logfile of Trend Micro HijackThis v2.0.4
     
    Last edited by a moderator: Oct 25, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    If you have done the Read and Run First instructions you would know to attach the requested logs:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip
     
  3. monthehuang

    monthehuang Private E-2

    ok i will post them tonight, thks!:cool
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After you have done those, then I want you to run this:
    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  5. monthehuang

    monthehuang Private E-2

    Here's the logs from my laptop, actually my desktop is the one that got infected pretty bad but this morning when I was using my laptop the samething happened, google results got redirected. Therefore, since I'm at school with my laptop I'm gonna post the logs for my laptop first and later my desktop if that's okay. ps. RootRepeal could not be ran, asks me to contact the author.
     

    Attached Files:

  6. monthehuang

    monthehuang Private E-2

    Ran TDSSkiller on my laptop, nothing found.
     
  7. monthehuang

    monthehuang Private E-2

    Hi there, here's my logs for my desktop.
    Once again Rootrepeal failed and combofix freezes.
     

    Attached Files:

  8. monthehuang

    monthehuang Private E-2

    Ran tdsskiller on desktop, nothing found, virus still on both laptop and desktop...
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should have started a separate thread for the desktop computer, otherwise things could get confusing.

    If you hard wire your computers to the modem, bypassing the router, are you still redirected?

    It is possible that your router is infected, so you need to reset it to factory settings. (Find the little red recessed button on the bottom and hold it in for 3 seconds.) You will have to change the configuration if you had anything previously configured in the router.

    In the meantime, on the desktop, do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. monthehuang

    monthehuang Private E-2

    The reg file was successful, do I have to leave it on my desktop or can I delete it? the mgtool zip is attached. I'm renting the room so the router is really not mine..also both my desktop and laptop uses wireless, too far away from the router. Also, any solutions for the laptop? Btw I just tested both and both are still redirecting!!

    Thank you so much!!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can just right click and delete the reg. fix.

    Have you checked to see if other users that are on this router are having the same issues as you? I am not seeing any malware in your desktop logs and your laptop logs where clean. So the only thing that could be the cause is the router.

    It would be very easy for you to plug the laptop directly into the modem and see if you are still being redirected.
     
  12. monthehuang

    monthehuang Private E-2

    I will check with them when I can..so the only way to get rid of it is to change my router to default settings? I don't see any buttons on it..how do I do it then? Plus I don't have a cable...
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do check to see if anyone else is having this issue. It is more than likely the router, but I can't be sure unless you can test it by bypassing it. Perhaps you know someone who you can borrow an ethernet cable from.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds