Please help me. I got Google redirects and my sound drivers crash.

Discussion in 'Malware Help (A Specialist Will Reply)' started by kewlboy_24, May 3, 2011.

  1. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hello all,

    I am new to this forum. I got a computer problem here at work that is driving me nuts. I think the problem started out as a Google redirect infection which escalated from the stupid things I've done. Any help from you guys to get me back on track would be much appreciated.

    Here is a quick backgrounder on my problem:

    Two weeks ago, I was browsing some forum, and before I realized it, every website I visit triggers the MicroTrend Client on my computer to pop up with a message that it has caught a virus from adserve or something with a long name made up of a long string of letters and numbers.

    Here are the steps I have tried to solve the problem:

    1) I went to MicroTrend Online and ran all their scanners and rootkit removers, all of which did not catch any infection.
    2) I did more searching and found a thread on the forum.techguy.org with the same problem and followed one of the suggested solution to run SDFix.
    3) The next day, the MicroTrend Client on my computer was still doing the same thing, so I called in one of the techies in the office. First, she said my MicroTrend Client was not updated for a long time because she forgot to re-activate it with a new registration key. She then tried to do a couple of system restores, both of which completely crapped out. Eventhough the system restores failed, she continued to un-install and re-install MicroTrend Client on my computer.
    4) I run a quick scan on MicroTrend Client and it did not catch any infection.
    But when I visit a website, I do not get any MicroTrend Client pop-ups anymore, so I though everything is fine and I was happy.

    However, on the days following I realized that something was wrong. Here are the problems I am encountering:

    1) All my Google searches are now redirecting me to the wrong websites (usually advertisement sites). I have to try 3 or 4 times before getting to the right website.
    2) After being logged on for a while, my taskbar would go all grey/white on me. (I have WinXP so my taskbar is usually blue). The grey/white taskbar would usually go away and sometimes it would stay on. I would then have to do a right-click/Properties on my desktop to restore my desktop settings through Display Properties.
    3) After my taskbar goes wonky, I would usually get a pop-up message from the system tray that Outlook got disconnected, and then another message that my Outlook connection has been restored.
    4) After 2 and 3 above happens, I will get a couple of pop-ups from the Visual Studio Just-In-Time Debugger with the error message "An unhandled win32 exception occurred in svchost.exe [nnnn]"
    5) After 4 above happens, all my sound device drivers become non-existent to the system. So I cannot play any sound/music through Windows Media Player. I cannot hear any sound from Youtube clips. My Accessories/Volume Control is also unaccessible.
    6) If I am logged on for a while, and then shutdown the computer, the computer cannot update my roaming profile or save my profile settings.
    7) For a little while, when I log on to my computer in the morning, it would stop at a blue screen and I don't get a login box. But this one got resolved when I run a few more spyware utilities. The other problems remained the same.

    I ran a few more spyware utilities mentioned in other forums. I am at the end of my wits by this point, I was just running whatever utilities I read from other forums:
    1) STOPzilla, but it did not catch any infection.
    2) TDSSkiller, but it keeps stopping at 80% initialization.
    3) Malwarebyte's Anti-Malware. It caught and quarantined 5 viruses.
    4) Dr. Web CureIt. It caught and quarantined a TDSS infection.

    All the problems (except the 7th) I stated above are still there. In spite of these problems, I am still able to do the core duties of my job as a database analyst/programmer, meaning that the essential software that I need to function at work seem unaffected: Visual FoxPro 6.0, MS Office, MSDN. I can still use the Internet Explorer (I just have to endure 3-5 redirects though). But it is really irritating when the sound drivers suddenly bomb or when the taskbar goes all grey/white. I would really like to resolve my computer problems.

    This has led me your forum. Hopefully you will be able to help me. I have already gone through the READ and RUN ME Malware Removal Guide. The necessary logs are attached. If you have the time, please guys, I need your assistance. Thank you in advance.

    Troy

    ~~~
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    You need to use your Windows XP CD to boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command then boot back to normal mode Windows and try running TDSSkiller now. Then attach the log. Also explain if you are still having any malware problems.
     
    Last edited: May 3, 2011
  3. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hello again,

    Here are the rest of the log files from the READ ME and RUN ME guidelines.
    Please note that I attached two log files from Malwarebyte (mbam-log) one of them is the log I got the very first time I ran it, and the second log is the one I got when I ran the utilities/tools as mentioned in the guide.

    Thank you in advance for your assistance and patience.

    Troy

    ~~~
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please see my post # 2 :)
     
  5. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hi Kestrel13, thank you so much for looking into this problem for me. I have attached the MGlogs.zip. I going into a meeting at work right now. I will do your instructions as soon as I get out from the meeting (1 hour). Please don't think I'm ignoring your instructions.

    Troy

    ~~~
     
  6. kewlboy_24

    kewlboy_24 Private E-2


    Hello Kestrel13,

    I am back again again. I did as per your instructions:
    1) I ran the Recovery Console that got downloaded and installed when I ran ComboFix (per the malware guideline).
    2) I ran FixMBR. I got a couple of warning messages about my partitions getting wiped out if I continued etc. but I continued to run FixMBR anyway.
    3) I ran TDSSKiller. The latest update apparently is 2.5.0.0. I ran with both checkboxes selected (Services and Drivers, and Bootsectors). I am attaching the log.

    So far, I haven't got a redirect or a crash, but it is too soon to tell. I've only been logged on for 30 minutes. The problems usually start after an hour. So I will report back to you after an hour.

    In the meantime, here are other info that you might need or interested to know. The TrendMicro Client that I have been referring to is actually named TrendMicro OfficeScan client which is the standard anti-virus software we use here at work.

    Yesterday, I caught the "MS Removal Toolkit" virus. This was probably from one of those ad-sites I get redirected to. This prompted me to run Malwarebyte and Trojan Remover in safe mode. Malwarebytes caught and quarantined two infections. But ever since then, TrendMicro OfficeScan would no longer load when I log on or at least, it does not seem to load because I don't see it on the system tray. And, when I am newly logged in my system tries to automatically install TrendMicro Officescan which then stops in the middle of the install saying that TrendMicro is already installed.

    I also remembered, that in my original post under Dr. Web CureIt, you can add CCleaner.

    Troy

    ~~~
     

    Attached Files:

  7. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hi Kestrel13,

    I have been logged on for 1.5 hours, and I still haven't experienced any redirects or sound driver crashes. It seems too good to be true. And for a procedure that is just too easy, it almost feels like I do not deserve it. Can we please keep this thread alive until tomorrow afternoon, at least? It would give me some time to observe the system.

    In the meantime, I am wondering if I should re-install TrendMicro Officescan? I've tried to uninstall it from the Start menu and it cannot find the EXE for uninstalling it. I've looked in Add/Remove Programs of the Control Panel, and it is not even listed there. But when I log on, it tries to install but stops mid-way because it detects that it already install (just like I've explained in my earlier post.)

    Anyway, I'll wait till tomorrow before I do anything.

    Troy

    ~~~
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It was an easy fix because we know how to deal with the infection. :) I understand you wanting to wait another day or so before we wrap up, and anyway, there is a bit more to do yet.

    Uninstall outdated Java:
    • Java 2 Runtime Environment, SE v1.4.2_18
    • Java(TM) 6 Update 20

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\documents and settings\All Users\Application Data\oN31004HdPdJ31004
    c:\documents and settings\troy\Application Data\sdojltzwufvd3ykiov3icdegtgupfbs2
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot
    your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  9. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hi Kestrel13,

    I just logged into the forum today, and so far, so good. I haven't had a redirect or crash. I just read your latest instructions, so I'll get back to you with the results, as soon as I can.

    Troy

    ~~~
     
  10. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hi Kestrel13,

    I am back with the results. The log files are attached.

    The ComboFix of your instruction was done in Safe Mode. Even then, ComboFix detected that TrendMicro Officescan was active. I tried to de-activate it but like I said in my earlier posts, its uninstall link from the Start menu does not work, it is not listed under Control Panel/Add or Remove Programs, and I do not know which process to kill in the Task Manager to de-activate it. So I just let ComboFix run its course even though it detected TM Officescan.

    When the machine was rebooted, TM Officescan tried to install and then stopped (like I explained from my earlier posts). This could probably fixed later. Other than this the system seems to be working normally.

    I've installed the Java Runtime 6 from the link provided. I've run C:\MGTools\GetLogs.bat in Safe Mode.

    Troy

    ~~~
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    tmcfw
    TmFilter
    TmPreFilter
    TmProxy
    TmPfw
    SecCenter::
    {2832D46E-3476-453A-A794-9401F69C54A5}
    {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
    Folder::
    c:\program files\Trend Micro
    c:\documents and settings\troy\Application Data\sdojltzwufvd3ykiov3icdegtgupfbs2
    File::
    c:\windows\system32\drivers\TM_CFW.sys
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Install some antivirus!!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  12. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hi Kestrel13,

    I just gone through your latest instructions... The log files are attached.

    A couple of things:
    1) After running ComboFix in Safe Mode and rebooting, my machine failed to retrieve my roaming profile.
    2) I've run the CCleaner and tried to install TrendMicro Officescan but can't. So I got our main techie here to take a look. She has to log on my computer as Admin, disconnect my machine from our network, and then reconnect. Afterward, she went into Network Properties and delete TrendMicro firewall. When I reboot and log in as myself, it went along fine, and TrendMicro Officescan automatically installed by itself.
    3) I ran C:\MGtools\GetLogs.bat in Normal Mode.

    One more thing, I would like to know your thoughts on using a virtualization software such as Sandboxie or iCore or ZoneBufferPro when browsing with IE or Firefox. Do you think I would not have caught the Google redirect virus if I had been using one of these virtualization software? I mean, is it advisable to use these software? Do they really add an extra layer of protection?

    Thanks.

    Troy

    ~~~
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run this fix in normal mode please not safe mode. There is one folder that remains I want gone.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    c:\documents and settings\troy\Application Data\sdojltzwufvd3ykiov3icdegtgupfbs2
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  14. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hi Kestrel13,

    I have just performed your latest instructions. The logs are attached.

    Two things:
    1) I ran them all in Normal mode using "Run as Administrator".
    2) When OTM finished rebooting the machine, it automatically opened the log in Notepad, not in the OTM Results window.

    Troy

    ~~~
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. kewlboy_24

    kewlboy_24 Private E-2

    ~~~

    Hi Kestrel,

    It has been two days and I have not had any problems with my computer. So much so that I almost forgot to return to the MajorGeeks forum to check our thread.

    I'll do your latest (final?) instructions at the end of the day.

    Thank you so much. You guys are awesome. I told our tech support here at the office that if they ever encountered any malware problems to check out the MajorGeeks forum. You guys are the greatest.

    Troy

    ~~~
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds