Redirected using Google

Discussion in 'Malware Help (A Specialist Will Reply)' started by Paul E, Feb 15, 2006.

  1. Paul E

    Paul E Private E-2

    :rolleyes: After completing a Google search I click on the desired website but am redirected to another site, usually abcsearch, on-line betting, porn or other search engines. I click back to Google and again click on the desired site but am redirected again. I click back to Google and after the 3rd attempt I get to the correct website. I've scanned with Adaware SE, Spybot, Ewido, Tojan Hunter, Norton and MS Spyware. (I've also scanned in Safe Mode). The only scan to indicate a problem is Ewido which shows "Trojan Pakes" but there is an error during the cleaning process so the trojan is not removed.
    This problem is really annoying, any removal solutions would be greatly appreciated. Below is a HJT log.
    Regards
    Paul

    Edit by chaslang: Inline HJT log from very outdated HJT removed.
     
    Last edited by a moderator: Feb 15, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. The version of HJT that you are using has not been used for two years. Best guess is you have a WareOut infection that will need some special steps in addition to the below to remove.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support


    Make sure you check version numbers and get all updates. PLEASE make sure you do this. If your HJT version is two years old, who knows about the rest of the tools you have.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. Paul E

    Paul E Private E-2

    Hi,
    I have followed the instructions in "read and run me first". Unforunately, the problem has not been resolved.
    Below are the requested logs: (I had trouble attaching the documents):

    Edit by chaslang: Inline logs attached
     

    Attached Files:

    Last edited by a moderator: Feb 19, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What problems are you having attaching files?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O4 - HKLM\..\Run: [dmnsv.exe] C:\WINDOWS\system32\dmnsv.exe


    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\WINDOWS\system32\dmnsv.exe
    C:\Program Files\UnSpyPC <--- delete the whole folder if found

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  6. Paul E

    Paul E Private E-2

    Chaslang,
    Many thanks for your continued patience and assistance.
    The file did not appear in HJT log, furthermore, the file and folder was not found in the Windows Explorer search.
    I thought I solved the problem re attachments, here are the report.txt and latest hjt log.

    I'm not sure the attachments are properly attached, so I'll copy and paste anyway.

    Regards
    Paul
     

    Attached Files:

    Last edited by a moderator: Feb 19, 2006
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post logs inline and do not use the paper clip to change attachments to inline links. They are annoying to use and require additional logins to read. Just attach them like I did in your previous message. You are still infected. You must avoid rebooting your PC inbetween posts because the problem seems to be mutating. You also must make sure that you have viewing of hidden and system files enabled per the READ & RUN ME or you will not be able to locate the files.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O4 - HKLM\..\Run: [dmmxf.exe] C:\WINDOWS\system32\dmmxf.exe

    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\WINDOWS\system32\dmmxf.exe
    C:\WINDOWS\SYSTEM32\DMNSV.EXE

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  8. Paul E

    Paul E Private E-2

    Hi Chaslang,

    Very sorry, I don't know how you attached the file, hence I've again had to use the paperclip. The Windows Explorer search did not find the file or folder you mentioned. I shall not reboot between posts. See latest report and pog.

    Regards
    Paul
     

    Attached Files:

    Last edited by a moderator: Feb 19, 2006
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just do not use the Paper Clip to attach files. Below your message window, use the Manage Attachments button to attach files. Using the Paper clicp makes them inline links and more difficult to read.

    You are still infected. There must be some hidden files that are respawinging the problems. Please perform the below scans and attach both the Ewido and Spy Sweeper logs

    Running Spy Sweeper

    Running Ewido Anti-Malware

    Then also attach a new HJT log! Again do not reboot or power down afterwards.
     
  10. Paul E

    Paul E Private E-2

    Hi Chaslang,

    Done as requested BUT things have suddenly gone very bad. PC is running extremely slowly. Can't use functions such us Search. I now can't attach the logs. Help!!

    Thank you
    Paul
     
  11. Paul E

    Paul E Private E-2

    Chaslang,
    I've just noticed that the Google searches are now working properly!! BUT as just mentioned the PC is generally very slow. The Search function and possibly others do not work. I apologise and appreciate this is against your wishes but this is the only way I can deliver the HJT log (attachment function will not work). Would you like me to send SpySweeper by this method? I won't reboot until I hear from you again.

    Many thanks
    Paul

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Feb 20, 2006
  12. Paul E

    Paul E Private E-2

    Chaslang,
    Sorry to trouble you again but I've just closed down Spysweeper and everything is working properly (the original problem is currently fixed) BUT what do I do now? Disable System Restore and reboot? Below are the attachments I await further news. Again thank you for your continued assistance.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now you are clean. You should uninstall bot SpySweeper and Ewido. That will help speed things up.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  14. Paul E

    Paul E Private E-2

    Chaslang,
    Done as instructed, all appears to be working OK. Many thanks indeed for your patience, understanding and highly professional assistance.
    Cheers once again,
    Paul
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds