Google Redirect virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by chiepler, Jan 26, 2011.

  1. chiepler

    chiepler Private First Class

    I've got a computer that has a Google redirect virus. About a week ago, it had the Security Tool 2011 virus, but the normal procedure seemed to have cleaned everything up (or so I thought). I tried the recommended procedure again to remove the current virus, but it didn't fix it. I looked around a bit and found TDSSkiller seemed to work for some, but that didn't detect it either this time. TDSSkiller didn't produce a log for me to attach. Here's the logs from the READ THIS scans. It's a Windows 7 64 bit OS, so no RootRepeal log.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. chiepler

    chiepler Private First Class

    No, not all browsers. I just downloaded Google Chrome & that seems to work fine no matter which search engine I used. While in IE, I tried using Bing, Yahoo, and Ask and get redirected to random sites. However, Altavista and Excite seem to work fine. It looks like it targets some of the more popular search engines while in IE - are there viruses that discriminate like that? I also notice that the searches will sometimes take me to the desired site - the redirects seem to happen when they feel like, but it is often. It's really hard to reproduce the problem. I tried narrowing my search requests to "food network" and "lvrj" & selected the first or second items in the result list. Sometimes it took me to the correct site but most of the time it didn't. Here's a sample list of some of the sites I get redirected to:

    hxxp://dailycontestwinner.com/Usa/Winner/
    hxxp://www.ononeworld.com/?mkt=us&k...network&lpid=10727-2778&veri=thenightrain.com
    hxxp://scour.com/search/web/Lvrj/a10/ordian-10538_2778/v3/
    hxxp://www.gimmeanswers.org/search/vhq/searchabc.php?search=Food+Network&affiliate=ordian-10538_2778

    Hope this helps. This problem sure has my head spinning!:confused
     
    Last edited by a moderator: Feb 1, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you done the procedures that I linked you to? What version of IE are you using? Is IE the only browser that is redirecting you?
     
  5. chiepler

    chiepler Private First Class

    Yes, I tried the ATF cleaner, flushed the DNS cache, and reset my router. I am using IE8. Do you think installing IE9beta would help fix things or does that just import all the settings from IE8 automatically when installing?

    I didn't have Firefox installed, so I went and did that. After a bit of testing on Google & Bing searches, it also started to redirect me. I tried the Firefox cleaning procedure but still get the same problem. I had Chrome already installed, and like I previously mentioned, it seems to work OK - it hasn't redirected me yet. Safari seems OK so far as well. Here's a couple more samples of where it's taking me:

    IE8 -
    hxxp://gamesweaseltv.mevio.com/?utm...686_18119&utm_source=df250c&utm_medium=df250c
    hxxp://www.tazinga.com/bf/results/Food Network?_session_id=8710fb65d33615b615cdb0f4666be266
    hxxp://yellowpages.lycos.com/search...um=roc&utm_term=restaurants&utm_campaign=lyc8

    Firefox -
    hxxp://www.ononeweb.com/?mkt=us&key...network&lpid=10727-2778&veri=thenightrain.com
    hxxp://www.subscriptionagent.com/food-network-magazine.html
    hxxp://www.magazineline.com/magazineline/foodnetwork.htm

    Since the beginning of this thread I've been limiting my searches to Food Network and LVRJ, just to show how repeating the same searches produces different redirects. Also, it still doesn't ALWAYS happen for every search attempt and typing the 2 website addresses directly into the address bar doesn't redirect me either. Even though the problem seems minor, I should mention that I was redirected to a porn site at least once (not listed in any redirect samples here). That has me concerned.

    I attached my log for the Goored scan. I also found the TDSSkiller log.
     

    Attached Files:

    Last edited by a moderator: Feb 1, 2011
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am a little bit at a loss as to what is causing this. Go to start / run / and type:
    %temp%
    Delete all it finds.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  7. chiepler

    chiepler Private First Class

    These 2 files couldn't be deleted because they were 'in use':

    {E9C1E0AC-C9B2-4c85-94DE-9C1518918D02}.tlb - used by dell support center
    FXSAPIDebugLogFile - used by windows explorer

    I attached the updated logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Power down your PC and your cable/DSL modem. Then please remove your router from between your PC and your cable/DSL modem so that your PC is directly connected to your cable/DSL modem. Now power up your cable/DSL modem and wait a few minutes for it to become fully ready. Then power up your PC.

    Is there any change to your redirection problem now?
     
  9. chiepler

    chiepler Private First Class

    My comptuer is connected directly to the modem - there is no external router, it's all combined into 1 box. I rebooted both as directed, however, and I still have the same issue. I even took the tower to a friend's house yesterday & had the same problem. He was able to use the search engines just fine while I was still getting redirected.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this is good information. What is confusing though is that you say the below:
    • Internet Explorer has the problem
    • Firefox has the problem
    • Chrome does not have the problem
    Are you absolutely certain that the problem does not occur with Chrome?

    Also try the below, reboot your PC and only open up 1 browser session with Internet Explorer without allowing it to run any addons ( see below ) and do not run any other programs or browsers.

    To run IE without addons, just right click on the IE icon and select Start Without Add-Ons

    Is there any change when running with no addons?

    Also bring up Device Manager by right clicking My Computer and selecting Properties. Then click the Hardware tab and then select Device Manager.

    Look under System Devices section, do you see something like [cmz vmkd] or [cmz vmkd] Virtual Bus

    If you find a match to what I said to look for then right click on it and select Disable ( not select Delete at this time )

    Then reboot your PC. After reboot, continue witht the below.


    Download and save the current version of combofix.exe to your Desktop and run a new scan.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
     
    Last edited: Jan 31, 2011
  11. chiepler

    chiepler Private First Class

    Disabling the add-ons didn't make a difference. I tried several more searches in Chrome with no redirection happening. I didn't find anything relating to cmz vmkd in device manager, so I didn't run the scans again. Would you like me to post new scans anyway?

    I found something about clearing the LMHOSTS file while researching this problem. I opened it up, but there really wasn't anything in it - just a bunch of commented lines (lines preceded with a # sign).

    Also, would removing, rebooting, then reinstalling IE8 fix it? Maybe a fresh downloaded copy of it direct from MS? Do you know if Firefox runs off of anything IE8 has where reinstalling IE8 would also fix Firefox? Or maybe just stick with Chrome until something happens to my PC where I have to reinstall the OS.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This has nothing to do with your problem.

    Your problem is related to the [cmz vmkd] I have you looking for. Check other areas in Device Manager. For example, under the View menu selection, enable Show Hidden Devices. Then select Non-Plug and Play Drivers and see if it appears there.

    I can see other signs from this infection in the procdll.txt file which is part of MGtools. In it you will see the below hooked into many processes.

    \\.\globalroot\systemroot\syswow64\mswsock.dll

    Yours may be the first PC running x64 where I have seen this. And due to it being x64 ( which really is harder to infect than previous systems ), it is also more difficult to fix. Reinstall may be the only option. Also do note that this infection is also considered a backdoor infection which is a high security risk and in many cases really means you need to reinstall from scratch anyway inorder to ensure security of your PC.

    No!
     
  13. chiepler

    chiepler Private First Class

    I can't see any instance of [cmz vmkd] in device manager. I included some screenshots for you to see if there might be anything else that stands out.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. chiepler

    chiepler Private First Class

    I ended up reinstalling the OS yesterday before I saw your latest post. Everything seems to be working OK now. Thank you for all your efforts to help me over the last few days. I really appreciate it!!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds