google redirect

Discussion in 'Malware Help (A Specialist Will Reply)' started by pip2011, Jan 31, 2011.

  1. pip2011

    pip2011 Private E-2

    Hi All

    I hope you can help with a google redirect virus I am struggling with.

    I tried all the housekeeping fixes you suggest without sucess. Malwarebytes does not see it (although when I scanned earlier it picked up ZbotR which could be the cause of all this). TSS Killer does not see it either.

    I attach the Combofix log, mbam log and HijackThis log

    I appreciate the help

    Thanks pip2011
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this if you have not done so already.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    In order to help you I need to see ALL of the logs from running our malware removal procedures.

    • SUPERantispyware
    • Malware Bytes
    • RootRepeal (If it ran)
    • MGTools
     
  3. pip2011

    pip2011 Private E-2

    Attached are the Root repeal and MGlogs (contains the TDSSKiller I think).

    I ran the SuperAntiSpyware but it did not seem to create a log

    Thanks again

    Pip2011
     

    Attached Files:

    Last edited: Jan 31, 2011
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below outdated java.

    • J2SE Runtime Environment 5.0 Update 6
    • Java(TM) 6 Update 5

    Then you should have attached the log reflecting this! :)

    You have a DNS infection, which is causing the redirects.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\documents and settings\jon.richardson\Application Data\Ahhayr
    RegLock::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"="213.109.66.235 213.109.76.49"
    [HKEY_LOCAL_MACHINE\system\controlset003\services\tcpip\parameters]
    "DhcpNameServe"="213.109.66.235 213.109.76.49"
    Registry::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"=""
    [HKEY_LOCAL_MACHINE\system\controlset003\services\tcpip\parameters]
    "DhcpNameServer"=""
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    What are you currently using for antivirus?
     
  5. pip2011

    pip2011 Private E-2

    Hi

    Thanks again for the help.

    I don't think it worked. - Should I try the CFscript.txt again?
    logs are attached

    Sorry about the malwarebytes log - I had deleted that one.

    For AV Software
    I was using eTrust, but just unistalled it to run Combofix (as I couldn't disable it). Planning to use AVG once this is sorted
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No it did not work. :( You need to re run my entire fix from post 4 from combofix step down.
     
  7. pip2011

    pip2011 Private E-2

    Hi Kestrel

    I've tried again but still no luck. :confused

    Am I doing something wrong?
    Combofix reboots the computer at the end of its scan - once it gets to 50. When rebooted SuperAntispyware automatically starts. Would this effect it?

    Thanks

    Pip2011
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, I did say to disable ALL anti virus/antispyware software. Try again after disabling SAS. :) Don't forget this part after running Combofix:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. pip2011

    pip2011 Private E-2

    :cry

    Still the same.

    ....appreciating the help though.

    Pip2011
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. pip2011

    pip2011 Private E-2

    Received the sucess message

    MGlog attached

    Thanks
    PIP2011
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now let's flush the DNS cache
    • Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Tell Kes if you are still having redirect issues.
     
  13. pip2011

    pip2011 Private E-2

    Hi TimW
    I flushed the DNS but still seems to be some problem.
    When you open the main google page in firefox;
    http://www.google.co.uk/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
    it tells me the page isn't redirecting properly. Anything I search for in google will open in a new tab even though it is not set in the preferences to do so.
    However, it is not redirecting (I think as it did not so it every time in the past)

    Thanks
    pip2011
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How do you have the preferences set? Your choice in FF is either a new window or a new tab.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    That way I can re-check that your DNS settings are correct.
     
  15. pip2011

    pip2011 Private E-2

    Hi TimW
    The MGLog file is attached

    It does the same in both firefox and internet explorer.
    In Search settings on Google the box for open search results in a new window is not ticked.

    Thanks

    pip2011
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still have the DNS infection.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now let's flush the DNS cache
    • Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Not right click you internet connection and under TCP/IP click on properties. Remove any settings under DNS and make sure that you check Obtain DNS settings automatically.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  17. pip2011

    pip2011 Private E-2

    Hi TimW

    Okay -I've done that

    File is attached

    Thanks

    PIP2011
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your runkeys log indicates it is fixed, but your network log still shows the bad DNS settings. Go into your internet settings and make sure that it is set to Obtain DNS automatically and remove any settings that may be there.

    Tell me if you are still being redirected.
     
  19. pip2011

    pip2011 Private E-2

    Hi TimW

    The wireless on this Laptop is definately set to dynamic DNS

    I logged into the router and they seem to be fixed (primary 213.109......secondary similar but the end is different)

    I changed these to dynamic, but it does not seem to help.

    Thanks
    pip2011
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try resetting your router to factory settings. Then tell me if you are still redirected.
     
  21. pip2011

    pip2011 Private E-2

    Hi TimW
    I think you've cracked it.
    I connected up my spare router (I don't know how to reset the other one!) and everything works as it should.
    Do you need me to run any logs to check?
    Thanks
    pip2011
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There should be a small red recessed button on the back or bottom that you hold down for a few seconds to reset it to factory settings.

    If you are no longer being redirected, then you should be good to go!! ;)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  23. pip2011

    pip2011 Private E-2

    All done and Thanks

    pip2011
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds