Google Redirect virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by mikej62, Jul 17, 2012.

  1. mikej62

    mikej62 Private E-2

    I got the google redirect virus on my computer again. I ran TDSSKiller and it found nothing. I ran a goored and it gave me this log:

    ========== GooredScan ==========


    ========== GooredLog ==========

    C:\Program Files\Mozilla Firefox\extensions\
    {972ce4c6-7e08-4474-a285-3208198ce6fd} [01:06 08/10/2009]

    C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\extensions\
    {20a82645-c095-46ed-80e3-08825760534b} [22:38 28/04/2010]
    {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [20:56 16/12/2011]
    {E2883E8F-472F-4fb0-9522-AC9BF37916A7} [23:43 04/11/2009]

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
    "jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [20:25 13/01/2010]
    "fbphotozoom@installdaddy.com"="C:\Program Files\fbphotozoom\fbphotozoom15.xpi" [04:21 25/03/2012]

    -=E.O.F=-



    btw, it seems like this is a problem only on firefox. On my IE, I don't seem to get google redirect
     
  2. mikej62

    mikej62 Private E-2

    scratch that, i do have google redirect on my IE too.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now follow ALL of these instructions too please!! :)

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. mikej62

    mikej62 Private E-2

    Here is the log. Now whats next
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue on with the other tools and attach the other logs as well.
     
  6. mikej62

    mikej62 Private E-2

    From RogueKiller
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rather than attaching singally, attach logs as a group. ;)
     
  8. mikej62

    mikej62 Private E-2

    I ran HItmanpro 3.6 and it found 5 traces but I can't remove them because my trial license expired. This is what it got:

    Desktop.ini ................................................Trojan.win32.sirefef!IK
    C:\Windows\assembly\GAC


    n
    C:\Windows\INstaller\{142ef8fc1-cdeb-2027-af6c-9d8d24fdebc2}\


    n
    C:\documents and settings\Nashih\Local Settings\Application data\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\



    @
    C:\Windows\INstaller\{142ef8fc1-cdeb-2027-af6c-9d8d24fdebc2}\


    U\
    C:\Windows\INstaller\{142ef8fc1-cdeb-2027-af6c-9d8d24fdebc2}\


    The first 3 are trojans and the last 2 are Zero Access.


    I also ran Malwarebytes but it found nothing
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You must attach not post inline!! You need to take a look at this.

    HOW TO: Attach Items To Your Post

    Also I had said:
    The emboldened words were clickable (post #3) there are other tools to run and you should always attach them no matter what you say they found or didn't find. :) It helps me to help you. Thanks.
     
  10. mikej62

    mikej62 Private E-2

    I couldn't post a log or quarantine items from hitmanpro because the license ran out. I attached the TDSSKiller log from earlier. How do I post a MGtools log. I found something called MGlogs.zip. I extracted it and got a folder.
     
  11. mikej62

    mikej62 Private E-2

    Whoops here is the TDSSKiller log and here is the Malwarebytes log from just now. Both found nothing
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member



    You do not need to attach the MGTools folder, just attach the MGlogs.zip itself the same way you attached before when you did!
     
  13. mikej62

    mikej62 Private E-2

    here it is
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening.

    Re run RogueKiller and attach the log.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  15. mikej62

    mikej62 Private E-2

    Here is the roguekiller log. For some reason when I try to run OTL, I double click it and the prompt is up for like a nanosecond then disappears, what do I do?
     

    Attached Files:

  16. mikej62

    mikej62 Private E-2

    Ok I got OTL to scan but in the middle of the scan it pauses and won't continue because I got a popup that says:

    c:\WINDOWS\Microsoft.net\Framework\v2.0.50727\shfusion.dll is not a valid windows image. Please check this against your installation diskette.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:
    • [ZeroAccess][FILE] n : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\n --> FOUND
    • [ZeroAccess][FILE] @ : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\@ --> FOUND
    • [ZeroAccess][FOLDER] U : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\U --> FOUND
    • [ZeroAccess][FILE] n : c:\documents and settings\nashih\local settings\application data\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\n --> FOUND
    • [ZeroAccess][FILE] Desktop.ini : c:\windows\assembly\gac\desktop.ini --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Reboot and rerun RogueKiller again, attach that log also.
     
  18. mikej62

    mikej62 Private E-2

    I ran RogueKiller, but for some reason I don't see those files under the registry tab. It is blank. In the files tab, I do see those 5 files you listed but there is no checkmark or anything. I attached the log
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So you are not able to have RogueKiller fix the items that remain?

    • [ZeroAccess][FILE] n : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\n --> FOUND
    • [ZeroAccess][FILE] @ : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\@ --> FOUND
    • [ZeroAccess][FOLDER] U : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\U --> FOUND
    • [ZeroAccess][FILE] n : c:\documents and settings\nashih\local settings\application data\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\n --> FOUND
    • [ZeroAccess][FILE] Desktop.ini : c:\windows\assembly\gac\desktop.ini --> FOUND
     
  20. mikej62

    mikej62 Private E-2

    I ran RK again it does the same thing. Nothing on the registry tab, but under the files tab I see those 5 listings. Am I supposed to highlight them then click on the delete button on the side? Does this mean Im fixed from the google redirect?
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, and then rerun RogueKiller again so I can see the changes. And attach that log too. :)
     
  22. mikej62

    mikej62 Private E-2

    Now what? Is the google redirect gone?
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run Combofix as per the instructions here. Attach the log once done.
     
  24. mikej62

    mikej62 Private E-2

    combofix log
     

    Attached Files:

    • log.txt
      File size:
      11.7 KB
      Views:
      1
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    52780469
    
    File::
    c:\windows\system32\drivers\38951778.sys 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    ------------------------------------------------

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      *slserv*
      *notepad*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    ------------------------------

    Run RogueKiller again and attach the log.
     
  26. mikej62

    mikej62 Private E-2

    So am I fixed now?
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\ServicePackFiles\i386\slserv.exe | C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\$NtServicePackUninstall$\notepad.exe | C:\WINDOWS\notepad.exe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    _________________________________________

    Run RogueKiller and attach the log.
     
  28. mikej62

    mikej62 Private E-2

    Combofix and Roguekiller log
     

    Attached Files:

  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files/Folders tab and locate these 3 detections:
    • [ZeroAccess][FILE] n : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\n --> FOUND
    • [ZeroAccess][FILE] @ : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\@ --> FOUND
    • [ZeroAccess][FOLDER] U : c:\windows\installer\{142e8fc1-cdeb-2027-af6c-9d8d24fdebc2}\U --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[10].txt please attach it.

    Now run RogueKiller again normally with no fix, attach that log too! :)
     
  30. mikej62

    mikej62 Private E-2

    I couldn't find a checkmark on the files tab so I just highlighted all 3 of them and deleted them. Here are the logs
     

    Attached Files:

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now describe to me how everything is running at this point please? :)
     
  32. mikej62

    mikej62 Private E-2

    Well I haven't had a redirect in days so far so I think it works, but I will be checking back in if there is anymore problems.
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds