Still getting random redirects after removal attempt

Discussion in 'Malware Help (A Specialist Will Reply)' started by whoopski, Apr 14, 2010.

  1. whoopski

    whoopski Private E-2

    Hi there,

    Thanks so much for your malware removal guide. It's been very helpful, but there is still something causing redirects on my PC and I'd be so grateful if you could help me remove it completely.

    I noticed yesterday that my PC had the following symptoms:
    Google Chrome can't connect to any sites (eventually any tab I open crashes)
    Firefox works, but redirects to attack sites when clicking on some links (seems like about a third of the time when clicking on a Google search result)
    The Windows firewall was disabled (I wasn't running a third-party one, stupidly), and I couldn't access Windows Update

    I think this started after I clicked a search result and got directed to an attack site that opened a new tab, tried to open Acrobat Reader, and seemed to start Java. Because I was running Windows Defender, I thought I was safe (duh!).

    I used Malwarebytes Anti-Malware and Spybot S&D (which I already had installed). They detected Zbot infection, but still detected problems every time I rebooted.

    I worked through your removal guide - all steps worked and here are my logs. I used the existing versions of MAM and Spybot, because they seemed work OK. At the end of the process, for some reason an old version of Sun Java was starting on boot, so I uninstalled it.

    After doing that, the Windows firewall is back on, and automatic Windows updates seem to be working, although I still can't go to Windows update. I am still getting random redirects to attack sites in Firefox.

    Any help would be much appreciated!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We are going to need some additional info. Please follow the instructions in the below link and attach the requested log from GMER:

    GMER - running with a random name
     
  3. whoopski

    whoopski Private E-2

    Also, it seems like every so often, a new tab opens in Firefox with 'search results' for something like "zbot removal" - except it's clearly a list of attack sites.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested log from GMER. We don't need to know anything else. We need this log to continue. Once I get this log, I will have another tool for you to run to check for backup files on your system so that we can replace an infected file from a backup.
     
  5. whoopski

    whoopski Private E-2

    Sorry, I posted my previous reply before I saw your request for the additional scan. Please find the GMER log attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you have several different infections including a new form of TDSS and also a several Conficker infections.

    Now I need you to run the below to locate backups of a file we will need to replace.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1

    Download Mirror #2
    • Double-click SystemLook.exe to run it. (If you are using Vista, please right-click and select run as administartor)
    • A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff".
    • Copy and Paste the content of the following codebox into the main textfield under "File":
    Code:
    :filefind
    pciide.sys
    
    
    • Please Confirm everything is copied and Pasted as I have provided above
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can close this notepad window as the log will already be saved as SystemLook.txt on your Desktop ( if you downloaded and ran SystemLook to your Desktop as requested ).
    • Please attach this log in your next reply.
    Note: The scan may take a while from several seconds to a minute or more depending on the number of files you have and how fast your computer can perform the task.
     
  7. whoopski

    whoopski Private E-2

    OK, that scan seemed to work - here is the log!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay with this new file I can start working up a fix for your TDSS infection. However below is another part of the fixes you need that you can start on right now while I work up the next fix.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 12

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10566&gct=&gc=1&q=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10566&gct=&gc=1&q=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8118
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. whoopski

    whoopski Private E-2

    Thanks so much for this help.

    I had already uninstalled that old version of Java.

    ComboFix did not produce a log at C:\ComboFix.txt. After it rebooted the machine, Outpost firewall (which I had disabled while I ran ComboFix) started and maybe interfered with generating the log? I have uninstalled it to prevent that happening again.

    There was a ComboFix_error.dat which I have attached (I had to rename it to a txt file so that the forum would let me upload it). There was also a ComboFix.txt file in the C:\ComboFix folder, which has a timestamp which matches when I ran the program, which I have attached.

    There are still some symptoms happening. I am still seeing redirects to dodgy sites from random search results, and closing the laptop lid doesn't make the system hibernate, even though it should do according to the power options.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fix did not work due to the error with ComboFix. You need to try the same fix again now that you have Outpost uninstalled. Download the current version of ComboFix first.


    We have not started on the fix for the redirects yet. We need to cleanup the other problems first.
     
  11. whoopski

    whoopski Private E-2

    OK, ComboFix seemed to work this time! Please see the attached log.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better. Let's try one more fix wirh ComboFix and another scan with GMER before we have to resort to a more complex procedure.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, re-run GMER like previously run.


    Then attach the new logs from ComboFix and GMER.
     
  13. whoopski

    whoopski Private E-2

    OK, the first time I ran ComboFix, it said it had detected rootkit activity and needed to reboot the machine. After the reboot, Windows just showed the desktop wallpaper and a mouse pointer - no taskbar or icons - and stuck like that. I turned off the laptop and turned it back on - this time ComboFix completed all the scans.

    GNER worked as normal.

    Logs attached - thanks again for looking at all this!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that appears to have solved the redirection problem and we can avoid having to use the Recovery Console.

    How are things working?
     
  15. whoopski

    whoopski Private E-2

    Well, Chrome is working again, and so is hibernation, and so far I'm not seeing any redirects!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. whoopski

    whoopski Private E-2

    Thanks so much for all your help. Everything seems to be behaving normally now. Antivir and spyware scanners aren't finding anything!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds