redirecting on searchs and more

Discussion in 'Malware Help (A Specialist Will Reply)' started by kailuacoach, Oct 1, 2010.

  1. kailuacoach

    kailuacoach Private E-2

    Hi Guys,

    This is a real bugger... Symptoms are pretty similar to this post by Thymexxx

    "Hi! I am still haveing redirect issues after following all the cleaning steps in your sticky. My computer seems to be talking to the internet all the time, even when it is idle, which seems to be keeping the screensaver from coming on. Also, when doing a search on Bing, and I click on a relavent result, I am taken somewhere else. The only way to get where I really want to go is to copy and paste the address into the address bar. This started happening 2 or 3 days ago, while my husband was using the computer. Hope you can help..."

    In addition to her symptoms - once is a while a a Tab will just pop up. Also, there is a "Breaking News" tab that will not shut down. When I try to shut it - it redirects to "Kevin's Road to Riches and pretty much locks up the browser - need to shut down with task manager.

    This is happening in IE and Firefox.

    Attaching the logs I ran...

    Thanks!
     

    Attached Files:

  2. kailuacoach

    kailuacoach Private E-2

    combo fix log...
     

    Attached Files:

  3. kailuacoach

    kailuacoach Private E-2

    Here is mglogs
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\Vjecodamuju.dat
    c:\windows\Afoxalazahixu.bin
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  5. kailuacoach

    kailuacoach Private E-2

    Guys - Thanks SO MUCH in advance.

    I ran everything - logs are attached. FYI, After running Tdsskiller, Windows did not properly shutdown it was left at Desktop background, When rebooting first time - same it froze on desktop background. Rebooted again and it came up. When IE was first opened up - it was immediately redirected to the same "consumer news" site.

    I closed that an ran mgtools.

    Thanks

    KailuaCoach
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay as I was out of town yesterday. TDSSKiller says it fixed your MBR infection but the other logs are indicating it is not fixed.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  7. kailuacoach

    kailuacoach Private E-2

    Here is the log - thanks!
     

    Attached Files:

  8. kailuacoach

    kailuacoach Private E-2

    I definitely still have issues. I am still getting redirected pressing any search link in IE. Is there a threat if I log into my bank account with this going on?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your xp cd? We need to have you set the bios to boot to the cd-rom first. Then boot to the xp cd and get into the recovery console. Once there, simply type:
    fixbmr

    Reboot and tell me if you still are getting redirected.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds