Google search redirects

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nickman87, Apr 29, 2012.

  1. Nickman87

    Nickman87 Private E-2

    Since a couple of weeks I'm having a problem when searching the web, every now and then I get redirected to strange pages, not related to the link I clicked on. when I go back and press the link again, I often get the correct page.

    I've followed several threads on the forum already with no success. I also ran spyware scans and fixes like super anti-spyware and malware bytes before I came to the forum.

    I'm using Microsoft security essentials as anti spy-mal-ware tool, but since the problem started I cannot open up the main window. When I launch it trough the start menu I only get a short glimpse of the main window. So I don't think it is actively scanning/protecting the system at the moment.

    I re-ran all the scans posted in the READ ME because I did not have the old logs anymore. I hope you guys can help me out here as I am out of options for the moment...

    I attached all the logs in this post.

    Thanks allot in advance!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing any blatant malware, so let's dig a little deeper:

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. Nickman87

    Nickman87 Private E-2

    Hey TimW,

    Thanks alot for the quick response!
    I just got home to my parents to run the additional scans.

    See the attached logs.

    TDSS only gave me suspicious files, but at first glance they don't seem to harmfull to me.

    MBRCheck gave me no warnings.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those logs are clean. What browser does it happen it? Does it happen in all browsers?
     
  5. Nickman87

    Nickman87 Private E-2

    Hey TimW,

    Another quick response :).

    The problem occurs in Firefox (11.0) and in Internet Explorer 9. We usually use Firefox for browsing.
    I also checked the connection settings for both, and I do not see any strange settings like a proxy or anything.

    I just captured one of the IP addresses that I am redirected to instead of the actual search result: 109.206.185.153
    Don't know if that is any help?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. Nickman87

    Nickman87 Private E-2

    Hey TimW,

    The log files are attached.

    Thanks!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    C:\Windows\tasks\thafaaqvz.job
    C:\Windows\SysWow64\kbdgeoeri.dll
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  9. Nickman87

    Nickman87 Private E-2

    Hey TimW,

    I ran the fix you suggested and for now everything seems to be working again. We will keep an eye on it.
    The logs you asked for are attached to this post.

    The main window for Microsoft Security Essentials also stays open now, but I cannot restart the service so real-time protection is currently off.
    I also attached a screenshot of the error message I get when enabling it.
    Googling for a solutions always refers to the windows update service not running, but when I check it, the service is running. Do you have any idea what might cause this?

    A huge thanks already for the effort in solving my problem!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any additional malware in your logs. Try using Add/Remove programs to uninstall MSE, run CCLeaner to remove any left overs and then reinstall.

    Tell me what issues are remaining.
     
  11. Nickman87

    Nickman87 Private E-2

    Hey TimW,

    I got Microsoft security essentials working again, thanks!

    I've still got the following problems:

    I cannot turn Windows Firewall back on. Looking in the Event log I found this:
    Code:
    Log Name:      System
    Source:        Service Control Manager
    Date:          12/05/2012 18:33:20
    Event ID:      7024
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      beneden
    Description:
    The Windows Firewall service terminated with service-specific error Access is denied..
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
        <EventID Qualifiers="49152">7024</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2012-05-12T16:33:20.090432700Z" />
        <EventRecordID>116437</EventRecordID>
        <Correlation />
        <Execution ProcessID="628" ThreadID="4160" />
        <Channel>System</Channel>
        <Computer>beneden</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="param1">Windows Firewall</Data>
        <Data Name="param2">%%5</Data>
      </EventData>
    </Event>
    And the Action Center is telling me that the "Windows Security Center Service" is not running. When I try to start it it immediately tells me it cannot be started.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. Nickman87

    Nickman87 Private E-2

    Hey TimW,

    I just checked the registry and that key exists.
    Any other ideas?

    Thanks!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since that fix did not work, you can either post in the software forum to try to get the firewall working or download a firewall to replace the windows version.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds