Redirecting webpages

Discussion in 'Malware Help (A Specialist Will Reply)' started by BranchS, Nov 23, 2010.

  1. BranchS

    BranchS Private E-2

    Hi there, wondering if anyone can help. I mainly use firefox to access the internet. However recently, maybe for a week or so, websites have been redirecting themselves to other sites. Occasionally I can get through to the page I request. When I do a google search and click on a link, it takes a while (which is unusual) and while waiting for the page to load I notice that the status bar displays "Click2Mix.info". Immediately after that appears the website is redirected to some "**.cc.co" site(it seems different each time). Before the page can load they are blocked giving me the option to shut down the page. I tried to a number of tools to clear it out however it still remains. I have been successful in the past in removing problems that have inadvertently appeared using your website. Thank you for your effort and support.

    I eventually decided to use the READ ME FIRST thread to clean the computer and now attached the logs requested when seeking help.

    I could run MGTools. When I tried to run the program, it did create a folder called MGTools and there was a cmd window that appeared for less than a second then disappeared.

    Any help would be appreciated.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )



    All of the below are infected as you may have noticed:

    • c:\windows\regedit.exe
    • c:\windows\system32\winlogon.exe
    • c:\windows\explorer.exe

    We will need to get MGTools to run because I need adequate information in order to be able to replace those infected files with clean copies.

    Rename C:\MGTools.exe to C:\5678.com. Reboot into safe mode now and again try running it. If successful please attach the C:\MGlogs.zip.
     
  3. BranchS

    BranchS Private E-2

    The change of name worked, thanks. As a result the MGlogs.zip is attached. I also ran TDSSKiller. It didn't find anything but the log is also attached as requested.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp3bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. BranchS

    BranchS Private E-2

    Followed instructions carefully. I did notice an extremely quick flash of something so assumed it ran successfully. Also ran C:\MGtools\GetLogs.bat.
    New MGlogs.zip is attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you got your Windows XP disk handy?
     
  7. BranchS

    BranchS Private E-2

    Yes I should have it. I will look for it.
     
  8. BranchS

    BranchS Private E-2

    I don't have it. Are there any alternatives?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There maybe yes, I will have to look into it. Can you not get hold of a disk anywhere else to borrow?
    Let's do this for now:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\MGtools\temp\explorer.exemg | c:\windows\explorer.exe
    C:\MGtools\temp\winlogon.exemg | c:\windows\system32\winlogon.exe 
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. BranchS

    BranchS Private E-2

    I will look again. It should be here somewhere.
    In the mean time, I ran combofix again as instructed and have attached logs.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Tell me what the below files are for?
    1. Go to Microsoft Windows Update and install all important updates.
    2. Then after a reboot, run sfc /scannow
    3. Now run an online scan with Kaspersky and get me the log.
    4. Download current version of ComboFix and then reboot into safe mode and run ComboFix
    5. Reboot into normal mode
    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited: Nov 27, 2010
  12. BranchS

    BranchS Private E-2

    I'm not sure what those files are. I don't recognize them.
    I followed through the steps you outlined (got the XP CD) but when I came to run the online scan with Kaspersky it gave the following message:

    "Update has failed The program could not be started. Please close the window of Kaspersky Online Scanner 7.0 and start the program again from the web site of Kaspersky Lab. Successful updating of Kaspersky Online Scanner 7.0 and scanning of your computer requires uninterrupted Internet connection. Please make sure that the Internet connection is established. [ERROR: License has expired]"

    The internet connection is fine. It is always connected. I tried it a couple of times even with IE but received the same message.

    Should I continue without it and run combofix?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, continue on if you cannot get Kaspersky to scan using either browser.
     
  14. BranchS

    BranchS Private E-2

    Had some trouble running combofix in safe mode. I couldn't disable internet and virus protection software. I don't know if that caused the problem but at the end it of the run it froze. In the end I had to boot from CD and reinstall/repair windows to get it working again.
    Anyway I managed to run combixfix again this time successfully and have attached the logs including the new MGlogs.zip file.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Combofix is not showing those three infected files now.

    Please go to virustotal and upload the following files for analysis, and let me know the results.
    Disable TeaTimer as shown in case we have to run a fix later:

    How to disable Spybot's TeaTimer

    Delete the following using Windows Explorer
    • c:\windows\SETD2.tmp
    • c:\windows\SETC6.tmp
    • c:\windows\SETC5.tmp

    Could you please get this: ¹ÙÅÁÈ*~1 into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip

    Are you still experiencing redirects?
     
  16. BranchS

    BranchS Private E-2

    I did some testing and I don't seem to be experiencing any redirects. I clicked on a number of google search results and it works well. Thank you very much for your help with this. I haven't had a virus in a long time sometimes they have creeped in over the years but I have managed to get rid of them with a couple of free tools from the net. But never like this.

    Anyway here is the result of the Virus Total scan of btscan. It seems to have found something. Not sure what exactly. I also tried to zip the file you requested but couldn't find the resulting collect.zip file in c:

    0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
    File name:
    btscan.exe
    Submission date:
    2010-11-30 23:09:25 (UTC)
    Current status:
    queued (#1) queued (#1) analysing finished
    Result:
    1/ 43 (2.3%)

    VT Community

    not reviewed
    Safety score: -
    Compact
    Print results
    Antivirus Version Last Update Result
    AhnLab-V3 2010.12.01.01 2010.11.30 -
    AntiVir 7.10.14.155 2010.11.30 -
    Antiy-AVL 2.0.3.7 2010.11.30 -
    Avast 4.8.1351.0 2010.11.30 -
    Avast5 5.0.677.0 2010.11.30 -
    AVG 9.0.0.851 2010.11.30 -
    BitDefender 7.2 2010.11.30 -
    CAT-QuickHeal 11.00 2010.11.30 -
    ClamAV 0.96.4.0 2010.11.30 PUA.Packed.ASPack
    Command 5.2.11.5 2010.11.30 -
    Comodo 6906 2010.11.30 -
    DrWeb 5.0.2.03300 2010.11.30 -
    Emsisoft 5.0.0.50 2010.11.30 -
    eSafe 7.0.17.0 2010.11.29 -
    eTrust-Vet 36.1.8010 2010.11.30 -
    F-Prot 4.6.2.117 2010.11.30 -
    F-Secure 9.0.16160.0 2010.11.30 -
    Fortinet 4.2.254.0 2010.11.30 -
    GData 21 2010.11.30 -
    Ikarus T3.1.1.90.0 2010.11.30 -
    Jiangmin 13.0.900 2010.11.30 -
    K7AntiVirus 9.69.3126 2010.11.30 -
    Kaspersky 7.0.0.125 2010.11.30 -
    McAfee 5.400.0.1158 2010.11.30 -
    McAfee-GW-Edition 2010.1C 2010.11.30 -
    Microsoft 1.6402 2010.11.30 -
    NOD32 5662 2010.11.30 -
    Norman 6.06.10 2010.11.30 -
    nProtect 2010-11-30.01 2010.11.30 -
    Panda 10.0.2.7 2010.11.30 -
    PCTools 7.0.3.5 2010.11.30 -
    Prevx 3.0 2010.12.01 -
    Rising 22.76.01.04 2010.11.30 -
    Sophos 4.60.0 2010.11.30 -
    SUPERAntiSpyware 4.40.0.1006 2010.11.30 -
    Symantec 20101.2.0.161 2010.11.30 -
    TheHacker 6.7.0.1.093 2010.11.30 -
    TrendMicro 9.120.0.1004 2010.11.30 -
    TrendMicro-HouseCall 9.120.0.1004 2010.11.30 -
    VBA32 3.12.14.2 2010.11.30 -
    VIPRE 7457 2010.11.30 -
    ViRobot 2010.11.30.4177 2010.11.30 -
    VirusBuster 13.6.67.6 2010.11.30 -
    Additional information
    Show all
    MD5 : 58def6c5d9fa3b3d6894e1ad1d1cd8c0
    SHA1 : cd97aa2809011f6811a74fdeee67acf59bd549e7
    SHA256: 10c45f78b5d5ab5a1a900f44fe2723fccdac065e9da340e46abca4a0cb38ca93
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, I am sure it relates to bluetooth.

    Did you manage to get the C:\collect.zip?

    Good that you are no longer having redirects.
     
  18. BranchS

    BranchS Private E-2

    I copied and pasted the link you specified but I couldn't find the collect.zip file in c:. I looked for the file in the directory C:\Documents and Settings\user\¹ÙÅÁÈ*~1 but it looks like it doesn't exist.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry about that. What problems remain now? Is all running smoothly? Perform another reboot and let me know after using the computer a while.
     
  20. BranchS

    BranchS Private E-2

    After a reboot everything seems ok. I will continue to monitor it, hopefully all is well. Once again thank you for your help.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. :) Safe surfing.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds