Google search results being redirected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wayne0h, May 19, 2011.

  1. wayne0h

    wayne0h Private E-2

    Hello,
    hoping someone can help. Problems started a few weeks back when I was downloading free software for video capturing/editing. Google search results in Firefox get redirected frequently to places like: www.find-quick-results.com or search.us.b00kmarks.com. I believe I ran through the forumgeeks malware cleaning procedure OK, BUT with the exception of combofix, which basically stalls out at the screen that says 'scanning for infected files . . .this typically doesn't take more than 10 minutes However, scan times for badly infected machines may easily double', and then never completes (I've tried this 3 times already, and each time I end up having to shut the machine off after letting it run overnight or for several hours). This is on a IBM R52 laptop running windows xp prof'l that was previously infected with malware a few years ago (but which was fixed at that time using this same forumgeeks malware cleaning procedure). I've attached the required logs (with the exception of the combofix, which didn't successfully run).

    I am grateful for any help you can provide.

    Thanks,
    Wayne
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Now:
    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. wayne0h

    wayne0h Private E-2

    I noticed after 5 minutes of testing (and I believe I remember from testing it before previously) that I don't have the same redirection problems using Internet Explorer. Should I have tried the GooredFix program for Firefox first?
     
  4. wayne0h

    wayne0h Private E-2

    Thanks for the quick response!

    I did as you asked, but am still experiencing the same redirect issues in Firefox.

    I noticed that when running C:\MGtools\analyse.exe that the following lines were not present to be deleted:
    O1 - Hosts: 255.255.255.255 hcurltest5
    O1 - Hosts: 255.255.255.255 vnsjs1.1stworks.com
    O1 - Hosts: 74.208.77.54 hcurltest1
    O1 - Hosts: 74.208.223.76 hcurltest2

    Also, I did not get a license agreement for TrendMicro and did not have to click on any Accept button TWICE when running C:\MGtools\GetLogs.bat
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    In situations where redirection is occuring, TDSSKiller needs to be run! :)

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Now tell us how things are running.
     
  6. wayne0h

    wayne0h Private E-2

    Thanks for your response. I did run TDSSKiller, but it didn't find anything. Log attached. Any other ideas?
     

    Attached Files:

  7. wayne0h

    wayne0h Private E-2

    I think I just realized something: the redirects only happen when I do the google search through the google 'toolbar' that is in the upper right of my browser. If I go directly to www.google.com and do a search there, then when I click on a search result, no redirect occurs.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the followup logs that Tim requested in is fix given to you in message # 2. Make sure that you have follow all of those instructions and attach the logs from Avenger and the new MGlogs.zip file.
     
  9. wayne0h

    wayne0h Private E-2

    woops, sorry about that. I must not have pressed the upload button the first time around. I've attached them now.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you removed your Google toolbar? I am not seeing any malware in your logs. You do need to clean out these folders:
    C:\WINDOWS\temp\
    C:\Documents and Settings\Wayne.IBM-R52\Local Settings\Temp\

    Tell me what malware issues you are still having, if any.
     
  11. wayne0h

    wayne0h Private E-2

    Once again, thanks for your time to help me.

    Is there a difference between the google toolbar that you have to explicitly install vs. the embedded search box in the upper right corner in Firefox that searches google (and any of several other search engines)? What I was using was the embedded search box, which I think is built into firefox. So I'm not sure how to uninstall it...although I can certainly uncheck and remove google as an option for that box.

    Regardless, it appears that only searches on google through this box are redirected. I can do searches using this box but choosing a different search engine, such as Yahoo, and the searches are not redirected.

    I suppose I could just stop using google in the search box, but still a little curious why I'm still getting redirected if you're not seeing any malware. Do you think it's safe for me to use the computer normally (and just stop using google in the search box)? I haven't been using it to browse any sites that require me to input a password, as I'm still leery of doing so at this point.
     
  12. wayne0h

    wayne0h Private E-2

    Oh, and I did delete all the files in the two directories you mentioned, however there was one file, 'perflib_perfdata_37c.dat' in c:\windows\temp, that couldn't be deleted b/c it was in use or something.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did fine. Tell you what, lets uninstall FF and reinstall it and see if that takes care of your issue:

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:

    C:\Documents and Settings\UserAccount\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?
     
  14. wayne0h

    wayne0h Private E-2

    TimW:
    Hope you're having a great weekend!

    You Rock! Thanks a million! I'm keeping my fingers crossed, but it seems the problems are all gone now. Who would've thought something as simple as uninstalling firefox and reinstalling would fix it? Seems kind of obvious now in hindsight. :-o

    Thanks for all your help...dunno where I'd be without you. Grateful for the service you provide!!!

    (bows down to master JEDI...)

    Sincerely,
    Wayne
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let us know if your issues recur. In the meantime:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds