Google redirecting and opening new IE

Discussion in 'Malware Help (A Specialist Will Reply)' started by KiteRider, Oct 5, 2010.

  1. KiteRider

    KiteRider Private E-2

    Hi! I've been getting google redirects for a while, mainly shopping sites,new IE's opening at random and today a porn pop-up. The address bar is sometimes called "cheklacation" or "cheklactalon".
    I'm running Windows ME, using Avast free edition and Windows firewall (also I think there's a firewall in the router?)
    I've run through all the READ AND RUN ME FIRST;
    nothing found withMalwarebytes or Superantispyware.

    Combofix seemed to run ok but it stopped at step 33 for a while with the message
    Windows - No Disk
    Exception Processing Message c0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c
    Then it ran to 50 but a log didn't appear and then just a message about internet failing to connect, which started up ok after re-booting.

    I couldn't find the log. I have added what I could find , please let me know if these are the wrong things!
     

    Attached Files:

    Last edited: Oct 5, 2010
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    No you are not running Windows ME. You are running Windows XP. The tools you mentioned would not run on Windows ME.

    You need to attach the requested log from MGtools. Then click the link below and run TDSSkiller and then attach the log. If it detects any problems, make sure that you immediately reboot ( even before coming here to attach any log ).

    TDSSkiller - How to run

    Why did you attach that last log? It is not something we requested not do we need it.
     
  3. KiteRider

    KiteRider Private E-2

    Hi,
    Sorry for ME mistake:-o
    I posted what I thought was one of the logs you needed. Will try again.
    TDSSKiller found something and for last hour have had no issues on IE!!!!
    Am I in the clear now?

    Thanks for help so far.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need additional logs from a couple tools including a new MGtools like that have been obtained after TDSSkiller was run so let's do the below.

    First you must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    You also have Symantec leftovers which need to be removed. Please run the below then reboot.

    Norton Removal Tool (SymNRT)

    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - S-1-5-18 Startup: edyl.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: edyl.exe (User 'Default user')
    O4 - .DEFAULT User Startup: edyl.exe (User 'Default user')
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. KiteRider

    KiteRider Private E-2

    Hi,
    IE still seems to be running OK.

    I ran the Norton removal Tool, had to run it twice as the first time was unsuccessful.

    The MG Tools analyse.exe found and deletd these items
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - S-1-5-18 Startup: edyl.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: edyl.exe (User 'Default user')
    O4 - .DEFAULT User Startup: edyl.exe (User 'Default user')
    The following was not present:
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    I copied everything from the quote into the Avenger *input script here*, it didn't seem to be acceptin the input even when I used enter to space the text exactly as in your post. Log attached.

    Was I to run MGTools again? The attach files message I am getting says I have already posted this log in a previous post.


    Many thanks.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See my previous instructions which said:
    That is how you get the new log.
     
  7. KiteRider

    KiteRider Private E-2

    Thanks you're a star
    log attached
     

    Attached Files:

  8. KiteRider

    KiteRider Private E-2

    And a happy birthday to you
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thank you.:)


    You did not disable Teatimer as requested and it may have blocked the fixing of the below:

    O4 - S-1-5-18 Startup: edyl.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: edyl.exe (User 'Default user')
    O4 - .DEFAULT User Startup: edyl.exe (User 'Default user')

    Disable Teatimer and try again and then attach a new log after running GetLogs.bat
     
  10. KiteRider

    KiteRider Private E-2

    Hi, thanks again for your patience with an idiot:-o
    Log attached
    IE still working great!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those items are still not getting fixed. Please download the current version of combofix.exe to your Desktop and try running it now as per original instructions in the READ & RUN ME. Attach the log if it runs. Make sure you shut down protection software before trying to run it.


    Also, please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      edyl.exe 
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  12. KiteRider

    KiteRider Private E-2

    Hi
    Have run combofix again,
    at stage 4 I got the following
    Windows Application Error
    "The instruction at 0x006f0063 referenced memory at 0x003el95c. The memory could not be written."
    At Stage 33 I go the following
    Windows - no disk
    exception processing message
    c0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c.
    The process did run to the 50th stage, where I didn't get a log but machine rebooted itself. Can't find a log from C:\ComboFix.txt
    We are still running IE well. Your time much appreciated.

    KiteRider
     

    Attached Files:

  13. KiteRider

    KiteRider Private E-2

    I hadn't intended to look angry...?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well since things are running good, it would seem we should quit, but I just want to be sure that the edyl.exe file does not exist. Let's try 2 more things.

    First run SystemLook again with the below instructions:

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      edyl.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.

    Now reboot your PC into safe mode and see if you can complete a ComboFix scan in safe mode. Make sure protection software is shutdown before running ComboFix.

    The reboot into normal mode and attach the new SystemLook log and the log from ComboFix if it worked.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds