Redirected searches.

Discussion in 'Malware Help (A Specialist Will Reply)' started by appreciate, Jul 29, 2010.

  1. appreciate

    appreciate Private E-2

    Searching with Firefox / Google, Internet Explorer / Bing, or any combination of the above, I continue to receive maybe one or two good searches but then I'm redirected to another web site.
    The redirected searches will sometimes open a new tab but not always. For example, I made a search to CNN news, after 30 seconds I was then was redirected. The search history looked like this: CNN News > 2 search.php > blue gills Prices. The search history always looks similar to this after a redirected search. The commonality of most redirected searches is "they all sell things" somewhat related to my original search or to a previous search I had made. There have been some redirected searches made to blank websites. The redirected searches continue to happen after going through the "Malware Removal Guide".
    I was able to generate logs except from the ComboFix program. ComboFix would run up to the blue window which stated "scan time for badly damaged machines may easily double", the screen showed a yellow blinking "under-bar", I left it for 60 minutes, the screen never changed and the computer was frozen. I tried this several times with the same results.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You really need to run CCleaner and clean out your temp files.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop

    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. appreciate

    appreciate Private E-2

    I re-ran CCleaner.
    I ran TDS SKIller, attached is it's log file.

    Thanks
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you running through a router? Are there other computers also sharing this router connection? Do they also have re-direct issues? If the answer is yes, then please find the reset button on the router and reset it to factory settings. Tell me if that helps.
     
  5. appreciate

    appreciate Private E-2

    Yes, I'm running through a router, sharing the router with a Mac which has no re-direct issues.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you try resetting the router?
     
  7. appreciate

    appreciate Private E-2

    Yes I have reset the router, but I still have the re-direct problem.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you cleaned out your browser cache? Are you having re-directs if you type in the address or is this happening just by clicking search results? Have you run CCleaner? Also try running:
    ATF Cleaner by Atribune.

    Let's try an online scan:

    Using BitDefender Online Scan.
     
  9. appreciate

    appreciate Private E-2

    1) I have cleaned out the browser cache since your last note.
    2) When I type in an web site address I don't receive a redirect initially, I can get to the correct web site. But after a minute or two a second browser tab will open and takes me to an redirected web site.
    3) With a word search in Google I continue to get redirected. What happens is if I simply mouse click select one of the selections from the word search I'll get redirected. But if I cut and past the address of one of the selections it works OK but may open a second browser tab (same thing that happens with number 2 above).
    4) I ran CCleaner 3 times since your last message. I'll run it before any scans.
    5) I ran ATF, 1st time it cleaned 15.4MBs, 2nd time it cleaned 2,868 KBs, and the 3rd time it cleaned 1,096 bytes.
    6) I ran BitDefender On-Line. The 1st time I ran it, after a hour a power interruption canceled the scan. Up to that point it had found 6 viruses and had deleted them. The second time I ran it, it found no viruses. The txt file ID was not available when I tried to save the log. The only option was html, that's what I used, see attachment. (I could not attach a html file, I renamed it as a txt file, not sure it will do any good.)

    Current Status: searches still being redirected, see number 2 & 3 above.

    Thanks
     

    Attached Files:

    Last edited: Aug 2, 2010
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  11. appreciate

    appreciate Private E-2

    Ran MBR Check, log attached.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.


    Now if you wish to continue and fix the malware - please do the following:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  13. appreciate

    appreciate Private E-2

    I ran my last backup 3 weeks back, I disconnected the external drive when I first noticed problems about 2 weeks back. I have not done anything important since my last backup.
    I just ran MBRCheck, and C:\MGtools\GetLogs.bat. Here are the attachments:

    The computer is still redirecting from the search block.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MBRfix.txt indicates you had it fix it, but your subsequent MBRCheck log shows it is not fixed. Plus your MGLogs.zip also indicates it is not fixed. What did you do?
     
  15. appreciate

    appreciate Private E-2

    Not sure, the first time I ran the MBR Check file yesterday at the point after I did a save all text, I tried to open the Notebook application to paste the data but the computer froze. I had to boot the computer. After it restarted I started the process all over again. I'll go through the process from your "yesterday 16:25" message again. Before I do I'll place all previous logs and .txt files in a folder and isolate them, possibly old and new are getting mixed together.
     
  16. appreciate

    appreciate Private E-2

    Re ran MBRCheck.exe and C:\MGtools\GetLogs.bat see attachments.
    Having a problem attaching the MRBfix.txt file, error message keeps warning file has already been attached to this thread. I'll try to attach it in the next message.
    Still experiencing redirected searches.

    Thanks
     

    Attached Files:

  17. appreciate

    appreciate Private E-2

    I can't get the MRBfix.txt file to attach, I even tried to rename it, still no luck.
    I decided to paste it's contents here:

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x00000074

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    Size Device Name MBR Status
    --------------------------------------------
    74 GB \\.\PhysicalDrive0 MBR Code Faked!
    SHA1: 3DD27C7EE9B2D8B2CB511843C79460E5DB3CA995


    Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit: y

    Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.

    Enter your choice: 2

    Enter the physical disk number to fix (0-99, -1 to cancel): 0
    Available MBR codes:
    [ 0] Default (Windows XP)
    [ 1] Windows XP
    [ 2] Windows Server 2003
    [ 3] Windows Vista
    [ 4] Windows 2008
    [ 5] Windows 7
    [-1] Cancel

    Please select the MBR code to write to this drive: 0
    Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes
    Successfully wrote new MBR code!
    Please reboot your computer to complete the fix.


    Done!
    Press ENTER to exit...
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will need to see a new MGRCheck.log as well as a new MGLog.zip. Did you reboot after doing the fix?
     
  19. appreciate

    appreciate Private E-2

    Tim
    I have decided to stop trying to clean out the virus, I will be doing a clean install. I had said in a previous message that the change in files from my last back-up were very small. Thank You for your time and effort and I did learn a few things.
    Thanks.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Let me know if you have any issues after doing it. I assume you have your personal data and files backed up and have not backed up any .exe files.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds