Google Redirection Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by chrisvought, Jul 11, 2012.

  1. chrisvought

    chrisvought Private E-2

    For the past two days I've been having trouble removing the Google Redirection Virus/Malware, I wasn't having any luck so I figured I'd come here. I uploaded RKreport[2].txt because after the scan completed it told me to select and remove anything the program saw as a threat and I did it only to find the instruction thread on here didn't tell me to. Just thought I'd let you guys know.
     

    Attached Files:

  2. chrisvought

    chrisvought Private E-2

    Oh and my PC didn't have any problems running and completing the tdsskiller scan, in case that helps.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:
    • [BLACKLIST DLL] HKCU\[...]\Run : Adobe (rundll32.exe "C:\Users\Chris Vought\AppData\Local\Ahead\Adobe\nlloicge.dll",CreateInstance) -> FOUND
    • [BLACKLIST DLL] HKUS\.DEFAULT[...]\Run : Adobe (rundll32.exe "C:\Users\Chris Vought\AppData\Local\Ahead\Adobe\nlloicge.dll",CreateInstance) -> FOUND
    • [BLACKLIST DLL] HKUS\S-1-5-21-212308926-3669759131-2721750471-1001[...]\Run : Adobe (rundll32.exe "C:\Users\Chris Vought\AppData\Local\Ahead\Adobe\nlloicge.dll",CreateInstance) -> FOUND
    • [BLACKLIST DLL] HKUS\S-1-5-18[...]\Run : Adobe (rundll32.exe "C:\Users\Chris Vought\AppData\Local\Ahead\Adobe\nlloicge.dll",CreateInstance) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Reboot, run RogueKiller again and attach the log for me to see.
     
  4. chrisvought

    chrisvought Private E-2

    As I said before I accidentally deleted all of the threats RogueKiller detected the first time I used it, so I'm guessing that that is why the detections you have told me to delete didn't come up this time. I've attached the RKreport[2].txt file that I uploaded in my first post in this topic so you can see the log of when I deleted the threats that were detected the first time around. I also attached a log of a scan I just ran as you instructed, RKreport[2]2.txt. Hopefully that helps. Thanks for the help.

    -The Forums not letting me reupload RKreport[2].txt in this post, so if you look back on my first post you can find it there.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running?
     
  6. chrisvought

    chrisvought Private E-2

    Well I wanted to wait awhile to see how everything was running and at first the problem seemed as though it went away but yesterday it started again. The problem being, me getting redirected to weird sites through Google links.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  8. chrisvought

    chrisvought Private E-2

    Here the log you asked for.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this file:
    C:\ProgramData\bqeojehc.wbx

    Delete this folder:
    C:\Program Files\Enigma Software Group

    Please download and run Combofix as per the instructions. Attach the log once done. (Read the instructions first!!)
     
  10. chrisvought

    chrisvought Private E-2

    I deleted the file and folder like you said, but while I was running combofix my pc blue screened before it could finish. I couldn't find the C:\Combofix.txt log afterwards but i did find another Combofix.txt log that was inside C:\Combofix folder, I'm not sure if it will help but ill attach it to this post anyway. I also got an error message after my pc restarted after I got blue screened.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------

    Run FRST without a fix, just let it scan and attach the log.

    Are things in better shape now?
     

    Attached Files:

  12. chrisvought

    chrisvought Private E-2

    Your instructions said to run FRST64, but I have a 32 bit system so i figured you made an error and ran the FRST.exe. Sorry if I wasn't supposed to it just confused me since you previously said Frst64 was for 64bit systems. As of now Firefox can't connect to Google when i try and search through the Firefox Google search bar/tool bar, however if i type Google.com in the bar to the left (I'm not sure what its called), then Google shows up fine and I can search through Google that way.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget I had typed:
     
  14. chrisvought

    chrisvought Private E-2

    Sorry here it is.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks: (Except at the point where you are instructed to uninstall it, please use revo uninstaller.

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.)

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    --------------------

    Any better now?
     
  16. chrisvought

    chrisvought Private E-2

    Nope still can't search google through the tool bar, it says Firefox can't establish a connection to the server at www.google.com. Plus I'm still getting redirected.
     
  17. chrisvought

    chrisvought Private E-2

    Also I thought I should let you know that I am experiencing this problem with the Firefox Bing search engine( the redirect problem) and when i try to search google in internet explorer. Overall my system is running slower than usual.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue ANY further I would like for you to use MSConfig to put this machine back into normal start up mode

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Explain or show me with screenshots what sites you are being redirected to.
     
  19. chrisvought

    chrisvought Private E-2

    I did receive a success message when I added fixME.reg to the registry. But when I ran C:\MGtools\GetLogs.bat I recieved an error message half way through, but ignored it like the program said to do, I've attached a screenshot of the message in case it helps. Also before C:\MGtools\GetLogs.bat could finish scanning I got a blue screen that said something along the lines of "Windows has shut itself down to prevent further damage", I'm not sure exactly what it said. I've also attached 2 screenshots of 2 different sites I have been redirected to. Also I thought you should know that I can't turn on real time protection for Microsoft security essentials anymore.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I apologise that this has not been a simple case of easy fix and done, but I'm having trouble finding the source of the redirects....

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  21. chrisvought

    chrisvought Private E-2

    Its alright I really appreciate the help. Here are those 2 logs you asked for.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK OTL is showing something that the other logs did not, so now I see the cause of your redirects. Unfortunately I am just about to head out the door and can't give you a fix for a while, just wanted to let you know progress is occurring ;) I see remnants of the ZA infection.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    [2012/07/27 22:35:49 | 000,232,960 | ---- | C] () -- C:\Windows\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\U\00000008.@
    [2012/07/27 22:35:48 | 000,013,312 | ---- | C] () -- C:\Windows\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\U\80000000.@
    [2012/07/27 22:35:48 | 000,002,048 | ---- | C] () -- C:\Windows\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\U\00000004.@
    [2012/07/27 22:35:48 | 000,000,804 | ---- | C] () -- C:\Windows\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\L\00000004.@
    [2012/07/27 22:35:47 | 000,001,632 | ---- | C] () -- C:\Windows\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\U\000000cb.@
    [2012/07/27 22:35:43 | 000,092,160 | ---- | C] () -- C:\Windows\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\U\80000032.@
    [2012/01/11 08:58:36 | 000,002,048 | -HS- | C] () -- C:\Windows\System32\config\systemprofile\AppData\Local\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\@
    [2012/01/11 08:58:36 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\@
    @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    • Now run OTL like you did the first time and attach the log please.
    • Tell me how things are running as well.
     
  24. chrisvought

    chrisvought Private E-2

    I haven't seen any change in the way my pc is running.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, because the files are being stubborn about being deleted. Naturally.


    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run OTL again, no fix just a scan and attach the log.
     
  26. chrisvought

    chrisvought Private E-2

    I'm going away till Thursday so I wont be able to get back to you till then. I really appreciate the help, thanks. Here are those logs you wanted.
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you get back, let me know how things are running.
     
  28. chrisvought

    chrisvought Private E-2

    Back early, PC is still running slower than usual and I'm still getting redirected.
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Damn. Are the redirects still in ALL browsers? The screenshots are from Firefox.


    Run this and attach the results.

    Using ESET's Online Scanner
     
  30. chrisvought

    chrisvought Private E-2

    Well in Firefox when i search for anything whether it be in the Google search bar or on Google.com, I get the error message "Firefox can't establish a connection to the server at www.google.com". However with internet explorer When i search from www.google.com the search goes through, but I don't get any results. Google shows me how many pages there are but no results. I attached an image so you can see what I'm talking about. I've also attached the results you asked for.
     

    Attached Files:

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run FRST again please. No fix just a scan. ESET removed a good bunch of bad stuff. Attach the log from FRST.
     
  32. chrisvought

    chrisvought Private E-2

    Sounds good, I attached that log you asked for.
     

    Attached Files:

  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    • Now re-run RogueKiller - no fix just a scan and attach the log.
    • Re-run FRST - no fix, just a scan and attach the log.
    • Let me know how things are running at this point.
     

    Attached Files:

  34. chrisvought

    chrisvought Private E-2

    I haven't noticed any change in how my PC is running.
     

    Attached Files:

  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Damn! This is frustrating.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 2 detections:
    • [ZeroAccess] HKCR\[...]\InprocServer32 : (\\.\globalroot\systemroot\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\n.) -> FOUND
    • [ZeroAccess] HKLM\[...]\InprocServer32 : (\\.\globalroot\systemroot\Installer\{bee50ca4-3fd9-1b32-a8f9-47a0dca0d60b}\n.) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Re run RogueKiller. Just a scan. Attach log.
    Still no change? If not I'll have to yell for Thisisu or Chaslang. :(
     
  36. chrisvought

    chrisvought Private E-2

    I ran Roguekiller like you said and deleted the items you told me to delete. But after i restarted my pc and tried to run the roguekiller scan my pc blue screened on me during the scan and gave me a message that said something like, "Windows has detected a threat and shut itself down to prevent further damage". I'm not sure which of these logs i have attached is from when I deleted the detections you told me to delete or a log from the failed Roguekiller scan. The logs are numbered 5 and 6 because i already have 1,2,3 and 4 on my desktop. Still no change in my pc :cry, I really appreciate the help though.
     

    Attached Files:

  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You ran it about a month ago though, yes?

    Run it again, fresh!

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  38. chrisvought

    chrisvought Private E-2

    Ok here are the logs from TDSSKILLER and MBRCheck.
     

    Attached Files:

  39. chrisvought

    chrisvought Private E-2

    Just thought I'd let you know that in Firefox and internet explorer, Google seems to be working properly as is the tool bar, as of now I'm not getting redirected but I'm pretty sure there's still something wrong because I still can't turn on Real Time Protection in Microsoft security essentials.
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I should have had you run TDSSKiller a long time ago! I see you ran it once, but it was about a month ago.

    rerun it, have it fix this that you skipped:

    Re run again, show me the new log and please tell me everything is really ok again :-D
     
  41. chrisvought

    chrisvought Private E-2

    Everything seems fine besides the fact that I can't turn on real time protection in windows security essentials. I've attached a screenshot of the error message I'm getting.
     

    Attached Files:

  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Chris. I think you ought to uninstall and reinstall MSSE. Do it using Revo.

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    After you are done, come back here and post and let me know all is sweet, ay? :)
     
  43. chrisvought

    chrisvought Private E-2

    Everything is running fine now thanks!
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Takes a sigh of relief. Glad to hear it!! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  45. chrisvought

    chrisvought Private E-2

    I do have one more problem, that I believe was caused by the malware problem I had. I can't download any updates from windows update. I receive the error code 80246008 when I try to download updates.
     
  46. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can ask about that one in the software forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds