Google Redirect

Discussion in 'Malware Help (A Specialist Will Reply)' started by davidadein, Oct 13, 2012.

  1. davidadein

    davidadein Private E-2

    I've been fighting a Google Redirect Virus for about a month now. I've noticed that the Java Dump and the DNS Dump seem to temporarly fix the problem, but it always comes back.

    I've uploaded the various reports you suggested. Any help would be appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You neglected to attach these logs:
    HitmanPro
    C:\MGLogs.zip

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [TASK][SUSP PATH] IHSelfDeleteTASK : CMD /C DEL C:\Users\DAVIDA~1\AppData\Local\Temp\IHU19D7.tmp.exe -> FOUND
      [TASK][SUSP PATH] IHUninstallTrackingTASK : CMD /C DEL C:\Users\DAVIDA~1\AppData\Local\Temp\IHU17F2.tmp.exe -> FOUND
      [HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
      [HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
      [HJPOL] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
      [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
      [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJPOL] HKLM\[...]\Wow6432Node\System : DisableTaskMgr (0) -> FOUND
      [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
      [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Now also attach the missing logs.
     
  3. davidadein

    davidadein Private E-2

    Thank you for your help so far. Pardon my ignorance, but I can't figure out how to post the Hitman logs. I did post the other two documents you suggested, though.
     

    Attached Files:

  4. davidadein

    davidadein Private E-2

    Thank you for the help! I have added all the reports you requested.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MGLogs was incomplete. Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Wait for it to tell you it is finished.

    Then attach the new C:\MGLogs.zip
     
  6. davidadein

    davidadein Private E-2

    Here is the completed MSG Logs! Sorry about that!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browsers are the redirecting coming from? FF? IE? Chrome?
     
  8. davidadein

    davidadein Private E-2

    All of them! I mostly use firefox - but it happens in IE and I tried Chrome and it happened there too.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  10. davidadein

    davidadein Private E-2

    Here you go!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I did not find any malware in that log. Let me ask one of my colleagues to have a look and see if I am missing something.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds