Search Redirect Issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by amaasing, Jun 6, 2010.

Thread Status:
Not open for further replies.
  1. amaasing

    amaasing Private E-2

    I have used both IE and Google and get same results. My son's PC is infected as well (home networked) and he uses Firefox. Get taken to ad pages when clicking on links. It's intermittent but enough to be annoying. I have 64 bit so did not run a couple of the programs per the instructions provided. Logs are attached. Thanks in advance.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, amaasing.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. amaasing

    amaasing Private E-2

    thanks for the update. Just let me know what other information you need. This is a new experience for me.....I have always been able to fix whatever ailed my PC before now. :)
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, amaasing

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 4:
    Now install the latest Sun Java Runtime Environment

    Step 5:
    Now download Sophos Anti-Rootkit 1.5 and save to a location you will be able to find such as your desktop

    Run sar_15_sfx by double clicking on it.

    Click Accept to agree to the EULA

    Click Install (if you wish to change the default installation location do so here but remember where you install to, the default is C:\SOPHTEMP)

    Once it finishes copying files, exit the installer​
    Running the scan
    Navigate to the location that you installed the software to (Default: C:\SOPHTEMP)

    Run the sargui Application by double clicking on it. (Note: if using Vista or Windows 7, use right click and select Run As Administrator).


    Ensure that all three of the options are checked

    Click Start Scan

    * Be aware that the scan will take at least 30 minutes, once it is complete, close Sophos Anti-Rootkit by closing the scan window and clicking Exit in the main window

    DO NOT CLICK 'CLEAN UP CHECKED ITEMS' OR ATTEMPT TO HAVE SOPHOS ANTI-ROOTKIT FIX ANYTHING UNLESS SPECIFICALLY INSTRUCTED TO IN THE THREAD YOU ARE WORKING ON
    Finding the logs
    Click on Start --> Run

    Type in %TEMP%\sarscan.log and press enter

    The log file will open in the default editor (probably Notepad)

    Click File --> Save As and save the file to your desktop or other location for easy retrieval.​
    Step 6:
    Please download OTL by OldTimer, saving it to your desktop:
    • Close all open windows on the Task Bar. Double-click the OTL icon to start the program and let it run uninterrupted.
    • When the windows appears, underneath Output at the top - change it to Minimal Output.
    • Under the Standard Registry box, change it to All.
    • Check the boxes beside LOP Check and Purity Check.
    • Now click the Run Scan button at Top left and let the program run - the scan may take 5-10 minutes.
    • Do not TOUCH your keyboard until the scan completes!
      • It will produce two (2) logs on your desktop, one will pop up called OTL.txt and the other - Extras.txt. These logs are saved normally directly under your C:/ directory.
      • Now exit Notepad.
      • Exit OTL by clicking the [X] at top right.

    Please attach the below logs to your next reply:
    • OTListIt.txt
    • Extras.txt
    • sarscan.log

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited: Jun 9, 2010
  5. amaasing

    amaasing Private E-2

    Step 1 - Complete
    Step 2 - Complete
    Step 3 - Complete
    Step 4 - Complete
    Step 5 - Complete - however even running as Administrator, the 'Running Processes' box was grayed out so I was unable to check all three options
    Step 6 - Complete

    All 3 logs are attached.

    Still experiencing re-directs. Using Chrome I searched on "Malware" and clicked on the link for PCTools.com and was sent to http://www.lowpriceshopper.com/malware/shop?rf=abl

    gg
     

    Attached Files:

  6. amaasing

    amaasing Private E-2

    Did I send you everything you needed? Just let me know the next steps. Thanks.
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, amaasing

    Can you tell me what this is? C:\Users\Grace\Desktop\umcflngb.exe
    If not - please right-click the file > select "Properties" > post what's listed under both the "General" and the "Details" tabs.

    Step 1:
    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:8CE646EE
      
      :commands
      [EMPTYTEMP]
      [REBOOT]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Open OTL again and click the Quick Scan button. Attach the new OTL.txt log it produces in your next reply.

    Step 2:
    See this link for re-setting your Hosts File
    How do I reset the hosts file back to the default?

    Step 3:
    Please go to start > Run and paste in the following:
    Step 4:
    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated OTL.txt log
    • C:\collect.zip

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited: Jun 13, 2010
  8. amaasing

    amaasing Private E-2

    umcflngb.exe is the alternative name for GMER that you guys had me download and run the other day.

    Step 1 - complete (log attached)
    Step 2 - complete
    Step 3 - complete
    Step 4 - complete (log attached) received a message from HiJack This that writing to the hosts file was denied.

    No Change in Behaviour. Searched on 'Malware' as before, clicked on the PCTools link and was sent off to some other site.

    Replied earlier but it doesn't seem to have saved. Hope I didn't save it somewhere else.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    amaasing

    You have ignored two of our forum rules:

    1)
    The following only appears in your most recent logs -
    TFC.exe/Alwil Software/pcpitstopAntiVirus.dll/HijackThis 1.99.1/Java(TM) 6 Update 13 (64-bit)

    2)
    You have opened a thread topic at another forum-
    http://forums.pcpitstop.com/index.php?showtopic=186505

    To avoid further confusion and wasting valuable resources on duplicate work, this thread is now closed.

    dr.m
     
  10. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    This guy is an IT admin, or so he claims in an email to me, so let him use his knowledge that he is getting paid for at his job. As you know, we don't assist so called pofessionals, a eal professional can remoe any infection or offer his custome a fomat when they cant get it done. We are volunteers here, helping idividuals, not so called pofessionals.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds