Google Redirect.

Discussion in 'Malware Help (A Specialist Will Reply)' started by mcaa51, Jul 21, 2012.

  1. mcaa51

    mcaa51 Private E-2

    When I click on a link in the Google search results I am redirected to other websites. I also have multiple instances of rundll32.exe.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, mcaa5 :)

    http://img805.imageshack.us/img805/9659/rktigzy.gif Delete items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Once the scan is complete, go to the Registry tab and checkmark everything except the below items:
    • [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0)
    • [HJ] HKLM\[...]\System : EnableLUA (0)
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[3].txt
    Attach RKreport[3].txt to your next message. (How to attach)

    __

    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif - Rescan with HitmanPro

    This time if the below detections are found, choose the action I've listed below:
    • services.exe - Trojan ==> Replace
    • Desktop.ini - Trojan ==> Delete
    • torrent.exe - Malware ==> Delete
    Ignore any other detections and click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    __

    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif Once you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log. (How to attach)

    __

    Completely delete these two folders manually using Windows Explorer:

    • c:\windows\installer\{2a1961d1-83ae-8605-691a-8cf06c5701e7}
    • c:\users\clay\appdata\local\{2a1961d1-83ae-8605-691a-8cf06c5701e7}

    Let me know if you were successful or not.
     
  3. mcaa51

    mcaa51 Private E-2

    Hi thisisu,

    Thank you for your assistance, much appreciated. I have followed your instructions, however, I was not able to locate the two folders that you told me to delete manually. I have attached the two logs that you mentioned.

    Thanks.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    http://img205.imageshack.us/img205/1894/otl.gif Please download OTL by OldTimer.

    • Save it to your desktop.
    • Right mouse click on the OTL icon on your desktop and select Run as Administrator
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      %systemdrive%\services.exe /s /md5
      c:\windows\installer\{2a1961d1-83ae-8605-691a-8cf06c570*.
      c:\users\clay\appdata\local\{2a1961d1-83ae-8605-691a-8cf06c570*.
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  5. mcaa51

    mcaa51 Private E-2

    Attached.
     

    Attached Files:

    • OTL.Txt
      File size:
      252.7 KB
      Views:
      4
  6. thisisu

    thisisu Malware Consultant

  7. mcaa51

    mcaa51 Private E-2

    Attached.
     

    Attached Files:

    • Log.txt
      File size:
      24.9 KB
      Views:
      1
  8. thisisu

    thisisu Malware Consultant

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Ask Toolbar
    • BitTorrent
    • Java(TM) 6 Update 26
    • Uniblue RegistryBooster

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:otl[/COLOR]
    DRV - [2009/06/10 17:29:09 | 000,001,900 | ---- | M] () [Unknown (-1) | Unknown (-1) | Unknown] -- C:\Windows\SysWOW64\wbem\mpssvc.mof -- (MpsSvc)
    IE - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.ask.com?o=15438&l=dis
    IE - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    IE - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\..\URLSearchHook: {90eee664-34b1-422a-a782-779af65cdf6d} - No CLSID value found
    IE - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files (x86)\Search Toolbar\tbhelper.dll ()
    IE - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=BT5&o=15435&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=GG&apn_dtid=YYYYYYB8US&apn_uid=48D12D53-C706-4915-B5B5-9D1D8E0B077C&apn_sauid=1737AB4F-BF0F-4EAD-91A7-7D655CDBBD27
    CHR - homepage: http://search.babylon.com/?affID=109935&tt=060612_5_&babsrc=HP_ss&mntrId=f09eef15000000000000944452039e54
    CHR - Extension: General Crawler = C:\Users\Clay\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel\2.5_0\
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\Search Toolbar\tbcore3.dll ()
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files (x86)\Search Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
    O3 - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\..\Toolbar\WebBrowser: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files (x86)\Search Toolbar\tbcore3.dll ()
    O3 - HKU\S-1-5-21-4040686905-2316279519-2759804258-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    [COLOR="DarkRed"]:files[/COLOR]
    c:\windows\system32\zz-services.tmp
    C:\Users\Clay\Desktop\9.0.0.912sdasetup-regnow_201_Trial.exe /d
    c:\windows\installer\{2a1961d1-83ae-8605-691a-8cf06c5701e7}
    c:\users\clay\appdata\local\{2a1961d1-83ae-8605-691a-8cf06c5701e7}
    dir c:\windows\system32\services.exe /c
    c:\windows\SysWow64\%APPDATA% /d
    c:\program files (x86)\Ask.com /d
    C:\Program Files (x86)\Uniblue /d
    [COLOR="DarkRed"]:reg[/COLOR]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [COLOR="DarkRed"]:commands[/COLOR]
    [emptytemp]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    __

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Reset Registry Permissions
      • Repair Windows Firewall
      • Repair Windows Updates
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    __
    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  9. mcaa51

    mcaa51 Private E-2

    I have uninstalled the below programs, attached are the two logs.
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    Your latest logs are clean.
    What malware related problems are you still experiencing, if any?
     
  11. mcaa51

    mcaa51 Private E-2

    None, so far as I can tell. The only things that seem odd to me are that I still have four instances of rundll32.exe and explorer.exe is always running, whether or not I have Explorer open. I do not know if this is normal.
     
  12. thisisu

    thisisu Malware Consultant

    I think you may be confusing explorer.exe (Windows Explorer) with iexplore.exe (Internet Explorer)

    Code:
    Running processes:
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    P.S. - You should close all instances Internet Explorer before and during running MGtools ;)

    __

    There's also no high rundll32.exe usage present in your logs.

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  13. mcaa51

    mcaa51 Private E-2

    Good point, ha.

    Thanks again for all of your help.
     
  14. thisisu

    thisisu Malware Consultant

    You're welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds