Please Help. Browwer Redirect Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by 3Series, Nov 8, 2012.

  1. 3Series

    3Series Private E-2

    Hi all,
    I think I have a browser redirect infection. When I'm on google and I click a link it takes me to something else.

    I've read all the stickys and performed the tasks. Attached are my logs to help out.

    I would appreciate any help.

    FYI, if you a bunch of x's I did a find replace on my name in the logs.

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from running Hitman.

    In the meantime:

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files/folders tab and locate these detections:

    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> FOUND
      [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> FOUND
      [ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\n --> FOUND
      [ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-21-1260549892-2075942151-2575213225-1001\$ff24043d55f85ce9a20a8337d9b4b888\n --> FOUND
      [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\@ --> FOUND
      [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-1260549892-2075942151-2575213225-1001\$ff24043d55f85ce9a20a8337d9b4b888\@ --> FOUND
      [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\U --> FOUND
      [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-1260549892-2075942151-2575213225-1001\$ff24043d55f85ce9a20a8337d9b4b888\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\L --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-1260549892-2075942151-2575213225-1001\$ff24043d55f85ce9a20a8337d9b4b888\L --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Now rescan with both Hitman and RogueKiller and attach those logs as well.
     
  3. 3Series

    3Series Private E-2

    Attached are the logs from RK and Hitman.

    1.) When I restarted my computer, Malware bytes started up and it quarantined some files. Is that good?

    2.) I ran Rouguekiller and accidently had it delete some files/processes that it thought was suspect. One of those was part of Dropbox. You can see it from the logs. Did I mess somehting up?

    -Thanks for the help
     

    Attached Files:

  4. 3Series

    3Series Private E-2

    One more thing.

    1.) The redirect seems to have been solved. Google links do not redirect me.
    2.) I'm unable to change the homepage default. I can change in in IE9 but it won't save.
    3.) I'm unable to turn on the Windows Firewall. I get an error, 0x80070424
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run RogueKiller and attach the new log. Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ). Then attach the below logs: * C:\MGlogs.zip
     
  6. 3Series

    3Series Private E-2

    Attacehd are the logs.

    FYI, I don't recall seeing the Trendmicro prompt.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run RogueKiller and under the registry tab, make sure these are removed:
    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-1260549892-2075942151-2575213225-1001\$ff24043d55f85ce9a20a8337d9b4b888\n.) -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\n.) -> FOUND
      [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$ff24043d55f85ce9a20a8337d9b4b888\n.) -> FOUND'
    If they are gone, just attach the new log. If you have to remove them, do so and then re-run it again and show me the clean log.

    Tell me what issues you may still have, if any.
     
  8. 3Series

    3Series Private E-2

    The browser looks good. I was able to change the homepage and it saved and I don't see any redirects anymore.

    My latest log from Rogue Killer is attached.

    The only problem that I see is that I'm unable to turn on Windows Firewall. I get an error, the same error code in my previous post.

    BTW, thanks for all the help.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attached is bfe.zip
    Inside is:
    Extract bfe.reg to your desktop.
    Double-click bfe.reg and allow it to merge into the registry. If you get a "successfully merged into registry" type of message, reboot your PC and see if you can turn on BFE, or if it is already turned on.
    You can run these commands from the command prompt.
    • net start bfe
    • sc qc bfe

    If you go to run / services.msc and find it is still not running, do the following:

    Run regedit:
    1. Browse to the location for the BFE service in the registry (HKLM\System\CurrentControlSet\Services\BFE\Parameters\Policy), right click and select permissions. (note: HKLM is short for HKEY_LOCAL_MACHINE_
    2. In the “Permissions for Policy” window, click advanced | Add.
    3. Once the “Select Users, Computers or Group” box appears, change the “From this location:” to point to the local machine name.
    4. After changing the search location, enter “NT Service\BFE” in the “Enter the object name to select” box and click “Check names” – this will allow you to add the BFE account.
    5. Give the following privileges to the BFE account:
    Query Value
    Set Value
    Create Subkey
    Enumerate Subkeys
    Notify
    Read Control
    After adding the BFE account to the registry key, please try to start the Base Filtering Engine service.
     
  10. 3Series

    3Series Private E-2

    1.) I saved BFE, unzipped and ran it. I received a succesful merger message.

    2.) I restarted my computer and I'm noticing two things.
    a.) My homepage in my browser won't let me save google as the default home page anymore.
    b.) I'm still unable to start the Windows Firewall.

    3.) So, I proceded with the additonal steps. I opened the command prompt and ran:
    C:\Users\My Name>net start bfe

    My result:
    System error 5 has occured.
    Access is denied

    4.) Then I ran:
    C:\Users\My Name>sc qc bfe

    My result:
    [SC] QueryServiceCOnfig SUCCESS

    5.) I don't understand this part:
    "If you go to run / services.msc and find it is still not running, do the following"

    Anyway, I checked the registry and BFE is now a "Group or user name" and the permissions you said to check have been checked.
    I dont understand when you say to start the Baser Filteirng Engine service. Is it now running?


    I've attached my latest log from Rogue Killer if it helps with the homepage issue.
     

    Attached Files:

    Last edited: Nov 12, 2012
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).
    Then attach the below logs:
    * C:\MGlogs.zip
     
  12. 3Series

    3Series Private E-2

    Attached are the mglogs.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. What issues remain? ( Do note that you have TeaTimer running!! ).
     
  14. 3Series

    3Series Private E-2

    Oh I see. I killed Sypbot and that stopped Teatimer.exe. With that stopped I was able to change my IE 9 homepage back to google.

    I'm still unable to turn on the Windows Firewall and I just tried to update Windows and it says the service is not running. Is this is Windows issue I'm having as result of a virus or just a settings issue?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
  16. 3Series

    3Series Private E-2

    I ran the program, it looked like it was gfixing things and I let it complete and it rebooted my computer with no issues.

    However, it did not resolve my issues.

    1.) I am still unable to turn on windows firewall. I get the same error that I stated in a previous post.

    2.) I was able to run Windows update but it won't let me install the updates (13 of them) THis is the error code I get:

    "WindowsUpdate_80246008" "WindowsUpdate_dt000"
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot your PC if the above was successful.
    After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. 3Series

    3Series Private E-2

    I ran the text attached to the previous post and it was successful.
    I rebooted my machine and tested it again, however I am still having the same issues.

    I am unable to install the latest Windows Update. I get the following error:

    "WindowsUpdate_80246008" "WindowsUpdate_dt000"

    I ran MGLOGS and attached is my MGLOGS.zip.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but now your firewall is working which is what that last fix was for. This issue with Windows Update is something different and we will have to check your logs in more detail to see if there is anything else we can do. Quite often this is not related to remaining malware. It is just damage to Windows itself which may or may not have been caused by malware. Possibly there is an issue with the BITS service.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I was right, BITS is not running because it does not even exist. And neither does your Windows Security Center Service. In addition, your system restore service (aka Windows Backup and Restore Service ) is not running. We will try another but longer registry patch.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your PC if the above was successful.

    After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. 3Series

    3Series Private E-2

    Thank you. Everything seems to be working fine.

    Attached are my latest logs.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds