Requesting help for browser redirect virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by kwill, Apr 3, 2009.

  1. kwill

    kwill Private E-2

    Hi -- First, hello to everyone as I'm brand new to this site. I registered because I’ve got a very nasty browser redirect virus – Google and Yahoo redirect all search result links to various sites, from Firefox and IE (the only two I use). Also, Firefox (latest version) keeps crashing, and I’m suddenly getting a lot of svchost.exe App error messages. Norton AV found nothing, and I’ve also tried:

    Super Antispyware
    Malwarebytes Anti-Malware
    Spybot
    Spyware Doctor
    Ad-Aware

    and some others. Tried downloading and running a couple of other AV programs, but they interfered with Norton AV and I’m not experienced enough at this to figure out how to disable Norton so the others could run. I’m not sure if I’m even a sophisticated enough user to be on your site, but I wanted to at least try before turning to Symantec or the GeekSquad for help.

    I’ve followed most of your READ AND RUN ME directions, though my computer won’t go to the ComboFix site at bleepingcomputer, and I’m nervous to run MGTools for some reason. After reading through some of the posts, then searching for/finding wdmaud.sys on my computer, I’m wondering if that’s the problem. I did download Hijack This and could post that log. Anyway, whatever help or suggestions anyone has to offer, I’d be incredibly grateful as I've been trying to solve this for about a month now. Many thanks…
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the logs from SUPERAntiSpyware and Malwarebytes.

    Try downloading it from here: ComboFix

    You need to run it and attach the log. A HijackThis log is of no use to us.
     
  3. kwill

    kwill Private E-2

    Many many thanks for responding. More trouble this morning, however, as I now can't get online at all. Writing this from bberry. Re-ran SuperAntyspyware and though it showed clean before, and I hadn't updated parameters, it now caught redirect.clickshield. On restart, went to blue screen, I booted in safe mode, then later regular, then no Internet connection. Now I'm really at wit's end. Any ideas re what might have happened?? Again, thank you so much for your very kind help. I'm grateful.
     
  4. kwill

    kwill Private E-2

    Ok, kept rebooting, maybe 10 times, and suddenly Internet connection came back. Computer running very slowly but I downloaded and ran MGTools, and I'm posting it and Malwarebytes and SuperAntispyware logs. Cannot get to your ComboFix page either, it just goes to the main Malware Removal page (on bleepingcomputer, I still get a white screen). Did not rerun CCleaner as afraid of more problems before posting. Hope this is sufficient for you to help me. And again, I am incredibly grateful for your help!!! All my very best...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not convert text logs into word documents. The text log files are what you should be attaching. They are 20 times smaller.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\kw\Local Settings\Temp

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. kwill

    kwill Private E-2

    You're incredible! Attached are my logs, as requested (note: I couldn't delete vtclrg41, got a message saying access denied. Also, do I empty recycle bin?) and, as far as I can figure out, all is well again. Truly, you're a genius and I offer a gazillion thank yous. I hope nothing else finds its way to my computer - what do you recommend running to prevent/find malware, etc., going forward? And how do I repay your kindness? All my very best...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    This is most likely a file related to your IBM PC.

    It was emptied when you ran CCleaner.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds