Google redirects and Windows 7 won't allow update of Mal-Ware programs??

Discussion in 'Malware Help (A Specialist Will Reply)' started by mountbrierfarms, May 13, 2010.

  1. mountbrierfarms

    mountbrierfarms Private E-2

    Hi,

    Every time I use google, if I click the link, it takes me to a totally different page. I did the gooredfix and this is the report:



    Also, I am running windows 7, and it will NOT allow me to update Mal-Ware Bytes - when I try to update it says "An error occurred. Please report the following error code to Malware Bytes Antimalware support team error 732 (12007,0). When I try to update SuperAnti Spyware it just sits there saying Downloading and installing SASKUTL.SYS... and never does anything.

    I scanned with Superantispyware (without update of course). Found nothing...

    "Scanning is complete. No harmful software was detected."

    Here is a report from Malware Bytes (not updated because I can't update period):

    I also had Kaspersky on here, but Windows 7 would not allow that to update either....... WTF!!!! So now I have a computer running Windows 7 with no antivirus that works, that also won't update malware/spyware programs and I keep getting redirected all over the place when I google things and click the links. :confused
     

    Attached Files:

    Last edited by a moderator: May 13, 2010
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    For Malware Bytes
    If you have a problem automatically installing the update due to no internet connection or other reason, you can manually download and install the update from here: Malwarebytes' Anti-Malware Database


    For SUPERantispyware
    If you encounter any problems while downloading the updates, manually download and unzip them from here.


    Why did you not run Combofix (if you have 64 bit windows then do not run combofix) or MGTools? These needs to be run after aquiring updates for MBAM/SAS, and scanning with both if successful.

    Attach all of the requested logs when ready.
     
  3. mountbrierfarms

    mountbrierfarms Private E-2

    I manually successfully installed the updates for both programs however I am still getting "error 732" for MalWare Bytes and can't run it. Not even when I click run as administrator. When I clicked on super antispyware it says in the right corner of my screen that a new update is available but I just manually install that so I don't get it???? :confused It won't start the program it seems. The only log I could give you right now would be a HijackThis log, it's the only one that works at the moment :(

    I did all of the steps for "READ & RUN ME FIRST. Malware Removal Guide" so everything else is ready to go I think. With Avast antivirus (downloaded this since I can't use Kaspersky-just won't work or update), and it found a JS:pdfka-gen [Expl] and I finally was able to delete that with Avast.

    Windows is still saying it is unable to update.

    I am running a 64 bit processing system. Just checked that under system type.

    So since I have 64 bit I need to avoid doing combofix, right?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, can you at least get C:\MGTools.exe to run? If so then please attach the C:\Mglogs.zip that it creates into your next reply. Without that I am not able to help you so let's see if that works at least. :)

    avoid running combofix.
     
  5. mountbrierfarms

    mountbrierfarms Private E-2

    OK, so here we go - it finally worked. Superantispyware did a scan, and it found absolutely nothing. However, I did as you said with downloading and installing the update manually and it all looked fine but still when I click to run the program it pops up in the right corner that an update is available. Malwarebytes absolutely just won't go.....still says "error 732".

    Sorry if this is dumb, but I searched for C:\MGTools.exe by going to start and search and also for just MGTools.exe and can't find anything???
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You probably never downloaded it because you didn't complete every step of the R&R. go to this MGTools and download MGtools.exe.

    Download it to your C Drive, double click to run, and once complete, attach the C:\Mglogs.zip into your next reply.

    Using MGTools
     
  7. mountbrierfarms

    mountbrierfarms Private E-2

    I downloaded MGtools and tried to run it. It says I am running a 64 bit OS and that access is denied???? I get dozens of this error:

    "Do you want the following program to make changes to your computer?

    Program Name-Registry Editor
    Verified Publisher-Microsoft Windows."

    If I click No, it says ACCESS DENIED in the black box for MGTools. If I click yes, it just pops up again and again but does nothing else.....
     
  8. mountbrierfarms

    mountbrierfarms Private E-2

    OK, now it worked, here is the log file....
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    and did you disable UAC before running MGTools.exe?

    Please refer to our procedures and ensure you read everything, I realise some steps aren't working for now so just check everything out so that you know how to follow steps correctly.

    READ & RUN ME FIRST. Malware Removal Guide

     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, I see that you have posted the log now, I have not looked at it yet, I finished work late and still haven't eaten, so give me some time and I will make a response as soon as I can. :)
     
  11. mountbrierfarms

    mountbrierfarms Private E-2

    Thanks so much, I really appreciate the help. Been trying to do internet research for my vet assisting class in college and it's such a pain with all this going wrong :(
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable utorrent from start up whilst I am working with you to remove malware.

    2. Disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.


    3. Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Windows Restore\Builder.exe
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    4. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    5. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    6. Now something was missing from your last mglogs.zip so let's see if we can get a complete one this time:

    7. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from OTM.

    8. Tell me how the machine is behaving now.
     
  13. mountbrierfarms

    mountbrierfarms Private E-2

    Did steps 1-3 and here is the file for OTC:

    All processes killed
    ========== FILES ==========
    C:\Windows Restore\Builder.exe moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Amanda
    ->Temp folder emptied: 3021567 bytes
    ->Temporary Internet Files folder emptied: 2339620 bytes
    ->Java cache emptied: 14469403 bytes
    ->FireFox cache emptied: 37283133 bytes
    ->Flash cache emptied: 50900 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 41620 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 865691 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67630 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 55.00 mb


    OTM by OldTimer - Version 3.1.12.0 log created on 05152010_144805

    Files moved on Reboot...
    C:\Users\Amanda\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Amanda\AppData\Local\Mozilla\Firefox\Profiles\1f72pqgs.default\Cache\_CACHE_001_ moved successfully.
    C:\Users\Amanda\AppData\Local\Mozilla\Firefox\Profiles\1f72pqgs.default\Cache\_CACHE_002_ moved successfully.
    C:\Users\Amanda\AppData\Local\Mozilla\Firefox\Profiles\1f72pqgs.default\Cache\_CACHE_003_ moved successfully.
    C:\Users\Amanda\AppData\Local\Mozilla\Firefox\Profiles\1f72pqgs.default\Cache\_CACHE_MAP_ moved successfully.
    C:\Users\Amanda\AppData\Local\Mozilla\Firefox\Profiles\1f72pqgs.default\urlclassifier3.sqlite moved successfully.
    C:\Users\Amanda\AppData\Local\Mozilla\Firefox\Profiles\1f72pqgs.default\XPC.mfl moved successfully.
    C:\Users\Amanda\AppData\Local\Mozilla\Firefox\Profiles\1f72pqgs.default\XUL.mfl moved successfully.
    File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

    Registry entries deleted on Reboot...



    ___________________________________

    Then I did step 4 and was not able to to step 5 because it says "utility doesn't support x64 operating systems!".

    I attached the new MGtools log for you to look at.
     

    Attached Files:

  14. mountbrierfarms

    mountbrierfarms Private E-2

    I did all steps except I can't run TDSSKiller because it says utility can't run with 64 bit system????
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please right click this file and run as administrator, then attach that log:

    C:\MGtools\GetRunKey.bat
     
  16. mountbrierfarms

    mountbrierfarms Private E-2

    I right clicked it and ran as administrator and it gives me this error:

    "The program or feature "\??\C:\MGTools\ltime.exe" cannot start or run due to incompatibility with 64-but versions of windows. Please contact the software vendor to ask if a 64 bit Windows compatible version is available."
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The correct version to run for x64 is GRK64.bat so try right clicking on that, and Run As Administrator ;)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just in case GRK64.bat does not run, try GRK.bat.
     
  19. mountbrierfarms

    mountbrierfarms Private E-2

    THANKS!!! I got it to run!! :)

    Here is the report attached...
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Still getting redirects?
     
  21. mountbrierfarms

    mountbrierfarms Private E-2

    So far so good, no more google redirects. Do I need to post you any other logs to make sure I am clean?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't think there's any need unless the computer is behaving oddly. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds