Noticed Win32/bundledGoogle.D variant

Discussion in 'Malware Help (A Specialist Will Reply)' started by ccn, Dec 27, 2013.

  1. ccn

    ccn Private E-2

    Hi folks, hope everyone had an enjoyable Holiday and Christmas, i noticed the above in a scan i ran with Eset online scanner and upon running Roguekiller i noticed results that i rarely ever see.

    98% of the time when Rogue killer is run i get a total of two HJ DESK results which is nothing to be worried about however, this last one has numerous HJ POL entries and when viewing the text i see a few (node ) entries (whatever that is) so i just want someone to take a look to see if anythings suspicious.

    Can you tell me what HJ POL means, i know what PUM means.

    I have noticed Kaspersky freezes when trying to update as well but not always.

    Thank you


    I always have issues with posting mbam and tdss logs but i can tell you they both found nothing.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal settings.

    Hijacked Policy which should mean that it has been changed from the Windows Default but all those items set to 0 are the defaults other than LUA and ConsentPromptBehaviorAdmin which we had you change to disable UAC.

    Why? What exactly happens?
     
  3. ccn

    ccn Private E-2

    I can never find the logs is the problem, i follow where to put them but i always seem to have major issues finding them. I do know however that they are new and updated versions.

    Here is the screenshot of what Eset finds, but Eset fails to be able to get rid of them , even in safe mode.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The TDSSKiller log is right in your root folder just as the instructions stated. It is always put there. The Malwarebytes logs are always stored in the Malwarebytes logs folders and can always be quickly review directly from the Malwarebytes program or by navigating to the below folder:

    C:\Users\Chris\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs


    Not really helpful at all. That is just a name that Eset makes up. We would need to see the exact filename and location or a proper full log from Eset but my guess is that this is just a program file that has Google Toolbar bundled into it. Like for example Shockwave for one example.
     
  5. ccn

    ccn Private E-2

    Thanks Chaslang, I got rid of Google and decided to see if I still have issues when using another browser and surprisingly with IE 11 they are gone .
    Now when I use IE 11 and click on the Google favorites search bar all the problems re appear . This site called Faraway magic UK pops up and nearly all search results reference it, my Kaspersky URL advisor has them all blacked out as no good.

    Something very strange going on, one thing I did notice with IE 11 is that when you attempt to download anti malware of any kind it says dangerous and this program is not downloaded and should be avoided .

    It actually only shows a (delete) or (do not run ) option and really tries to get you to not run it , didn't realize IE was like that . Chrome never does that
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal. New verisons of IE have added in more protection and smartscreen filter scanning to make sure that you know what you are downloading. If you know you downloaded something you want then just close that little box at the bottem of IE with the warning.

    See >> http://windows.microsoft.com/en-us/windows7/smartscreen-filter-frequently-asked-questions-ie9
     
  7. ccn

    ccn Private E-2

    I installed CCleaner and saw the option to install Chrome since i like it better than IE but only when it's not messing up my search results .

    I unchecked the install google toolbar for IE option and just went with plain old Chrome, after updating i did a search and the same results are coming up as you can see in the screenshot.

    Maybe i need to go into the software forum as this may not be malware but i have never seen so many bad links .

    Anyway's i appreciate your help very much as i always do and i hope your doing well.

    Chris
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure I follow you! You already had Chrome installed per your first logs.

    Also the title of this thread was Noticed Win32/bundledGoogle.D variant Are you now talking about different problems?



    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  9. ccn

    ccn Private E-2

    My apologies, i uninstalled the Chrome i originally had thinking maybe i had a bad link and reinstalled it with the CCleaner. Unfortunately the same issues.

    I did the OTL

    Thanks for your help


    Side note: I noticed when OTL started scanning the netsvs and active x text disappeared but the drives text remained for the entire scan.
     

    Attached Files:

    • OTL.Txt
      File size:
      292.8 KB
      Views:
      4
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which issues? Search hijacking? Does this only happen with Chrome? Test Firefox and Internet Explorer too but only run one browser at any given time.
     
  11. ccn

    ccn Private E-2

    The issues of redirects which I never had before with Chrome. I do not have the same issues with other browsers so it's Chrome only.

    Did my OTL look OK ?


    I want to ask you another question, off topic.


    When I run a sfc/scannow I always get a message saying there is a system repair pending but I have no idea what it is.

    This has been going on forever and I have to always run chkdsk/r to fix . Is there something that could get the system repair pending message deleted permanently like a code I could use in Command prompt?

    The last thing is when I run Secunia PSI it will say your 29 programs are up to date , i'll run it again and it will say your 33 programs are up to date then it will say your 29 programs are up to date again.

    I ran all three under user account but need to type in admin password each time.

    Here is a screenshot ( that thing circled concerns me because I don't play games and it's not showing in programs ).
     

    Attached Files:

    Last edited: Dec 30, 2013
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then try the below because the reinstall does not cleanup the garbage. Run the below

    Reset Chrome to Defaults

    Then see how Chrome works. You will have to exit and restart Chrome ( possibly reboot ). If this does not help then there is a strong possibility that the link file ( the .lnk ) or quicklaunch button you are using to run Chrome is the cause and you would have to remove this and create new ones.

    All clean.


    I'm sorry but both of your questions need to be posted in the Software Forum. We are very busy in here just dealing with malware issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds