What could this be?

Discussion in 'Malware Help (A Specialist Will Reply)' started by joroll, Oct 1, 2010.

  1. joroll

    joroll Private E-2

    This infection, or whatever it is, has me beat. It has been a total frustration for the last 3 weeks or so. I have some of the same issues as in other threads such as brower redirects ( both IE and Firefox) I also have the problem where holding down the left mouse button causes the brower to open a new and undesired window, also cannot use search engines because I am redirected with every click.
    So I have done all the recommended actions in the stickys and whatever else i could find that might help in the threads. Mbam, combofix, TDSS, have all come out okay. Actually have tried many tools referred to in forums over the past couple of weeks and nothing has worked. So last night I bit the bullet and decided the only way to fix it was a re-format and fresh install. So I did that and sat through 4 hours of windows updates patiently, knowing that at least the bug would be gone. Well after all the updates I went to search google for my video card drivers and my first click on the ATI site link got redirected to some bogus page yet again, Urrrrgh. So I have spent this morning getting and running MBAM, CCleaner, Combofix, etc, and none of them show any problem.
    Dang, all I can figure at this point is that the infection must be in the BIOS or somehow hidden on the HD that is undetectable. I don't know of anything that could stay in memory but at this point I am willing to consider anything. In the past I always figured that if worse came to worst I could at least re-format and get clean. Now I don't know. I am stumped if anyone could offer an suggestions I would be most grateful. Thank you.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs from doing the Read and Run First instructions:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip

    and your TDSSKiller log.
     
  3. joroll

    joroll Private E-2

    Here you go. thanks!
     

    Attached Files:

  4. joroll

    joroll Private E-2

    this too.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Are you still being redirected? If so, does it happen with all browsers? Does it happen in safe mode with networking?
     
  6. joroll

    joroll Private E-2

    Yes it is still happening, even in safe mode and with both IE and firefox.
    It's bizarre I know. Also when I am on a page I can see multiple addresses flashing past in the lower left of the browser, then it just seems to pick one and off I go.
    Thanks.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What version of IE do you have? I suggest that we remove it, after doing the below:

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:

    C:\Documents and Settings\Diane\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?

    If Firefox is now working, uninstall IE, run CCleaner and then install IE8.
     
  8. joroll

    joroll Private E-2

    IE 8. Thanks, I followed intructions and tried firefox again, redirected first click urggh.
    Man, maybe I need a new comp.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    May not help but...something to try:
     
  10. joroll

    joroll Private E-2

    Thanks I will try that. Actually I am thinking it must be hardware of some sort after the re-format. Let you know.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let us know how that goes.
     
  12. joroll

    joroll Private E-2

    I believe you got it Kestrel13!

    Just got a chance to try it and so far so good!

    Thanks so much.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds