Google redirect!

Discussion in 'Malware Help (A Specialist Will Reply)' started by starbiker99, Dec 6, 2010.

  1. starbiker99

    starbiker99 Private E-2

    I am getting a google redirect on about 25% of my searches it even says redirect in when I click recent searches. I have done the read me guide and here are the logs. W7 64bit home premium and Firefox 3.6.12 Avast. Thanks!!
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, startbiker99

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    *Our queue is working the oldest threads first.

    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, starbiker99

    Delete this, as it's no longer needed and not saved where you were instructed:
    C:\Users\Shawn\Downloads\MGtools.exe

    Please attach the below logs to your next post.
    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.


    Step 2:
    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Files
    C:\Program Files (x86)\Ask.com
    
    :Reg  
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64FB5234-2EAF-56BE-62B2-95E8AC15ED9E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98DEEAC0-2BDC-1C9C-500D-7C2F43EBFAA7}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CD8467DA-6642-6323-6A6D-CB6C86B36D6C}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EACA7D27-91A5-5125-485F-D81F65B7024D}]
    
    :Commands
    [EmptyTemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt%21.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Step 3:
    Now open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!


    Step 4:Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy these file paths in the below Code box:
      Code:
      C:\ProgramData\1112668759
      C:\ProgramData\1652281723
      C:\ProgramData\3D9455B309DB748BEA47C645369FB2C6
      C:\ProgramData\62ab862c
    • At the upload site, click the browse button.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scans are finished, Copy and then Paste the links in the address bar into your next reply.

    Step 5:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right-click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFileslog
    • C:\MGlogs.zip
    • Links from Jotti scans results
    • requested MBAM logs

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited by a moderator: Dec 10, 2010
  4. starbiker99

    starbiker99 Private E-2

    OK thanks for the reply. I performed the tasks in the previous post and am attaching the said logs. I am still having google redirects after completing them and am including a few of those.
    googled filter maf1
    results below
    clicked amazon.com it was ok
    clicked iallergy.com it went to findstuff
    clicked nextag.com it went to 64.111.212.0
    clicked filtersolutions.com it went to infomash
    clicked bizrate.com it went to 64.111.212.118
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Then you need to complete Dr M's instructions including letting him know the results from Jotti.
     
  6. starbiker99

    starbiker99 Private E-2

  7. starbiker99

    starbiker99 Private E-2

    Logs attached.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *Delete this from your desktop:
    C:\Users\Shawn\Desktop\MGtools.exe

    Questions:
    What browsers are being hijacked? Try more than one.
    Does it happen in safe boot mode?
    Have you tried running IE with all addons disabled?

    Let's do this -

    If you are using a router then follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    Using OTM previously downloaded:
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [EmptyTemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt%21.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.


    To flush FireFox cache

    1. From the "Tools/Options/Advanced/Network/Offline Storage" menu

    2. Click on the "Clear" button.

    3. Click on "OK" to close the window. ​

    To flush Java cache
    http://www.java.com/en/download/help/plugin_cache.xml

    Lastly - Run this and attach the results.

    Using ESET's Online Scanner

    Any improvement?
     
  9. starbiker99

    starbiker99 Private E-2

    OK update. It appears that only Firefox on my C: drive is messed up. I have have tried IE and Opera as well as a mobile version of FF on a USB stick and they all go the the proper Google links only the C: version of FF redirects. I also notice when I start FF a red screen appears for a second before my home page loads I don't remember that from before. I'm guessing an uninstall of FF and reinstall won't fix this.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Back up your bookmarks > uninstall Firefox > then reboot and re-install. Problematic still? Or not?
     
  11. starbiker99

    starbiker99 Private E-2

    After uninstall and reinstall I have googled around 30 things and all are going to the correct links. I think it might be OK now. Damn! Thanks for the help!!!

    Shawn
     
  12. starbiker99

    starbiker99 Private E-2

    I believe the trouble came from a facebook link to some quiz that I got.

    Shawn
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, it's for the best to stay away from that kind of facebook crap.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds