win32 - Olmarik and google redirect virus, etc

Discussion in 'Malware Help (A Specialist Will Reply)' started by sevens906, Dec 22, 2010.

  1. sevens906

    sevens906 Private E-2

    hi, sorry for barging in here i been looking through the web on possible related scenarios that might be consistent to my inconsistent attempt to remove virus or malware. My antivirus program (eset smart security 4) caught certain infiltrations but ended up getting blocked by it because it attached itself to operating memory. so i tried, avira, avast, avg, malwarebytes anti-malware, and spybot all to be a dead end. i am the type of person who has been using a pc since he was 9, at the age of 24 now, who has never gotten a virus or malware this bad, not to sure if my siblings, the current users of the pc where just stumbling into them or what but now it's my problem, so without being able to run combofix, or spybot or malwarebytes anti-malware (assuming it was the virus/malware) i came across a thread about this on your forum, ran MGTools and well here is my zip file. hope this helps you help me, thank you.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running now?
     
  3. sevens906

    sevens906 Private E-2

    i been surfing through the forums and combofix didn't work for me it froze at stage 4, and rootrepeal gave me an error
    "rootrepeal error:
    FOPS - DeviceIoControl Error! Error Code = 0xc000000d
    Extended Info (0x000001a4)" i was able to get a log for SAS and Malwarebytes' Anti-Malware. ill try what you posted now.
     

    Attached Files:

  4. sevens906

    sevens906 Private E-2

    ok did what you told me and got these files. i hope the mgtools.zip is the new one.

    ps. as far as the quarantine file goes what action do i take.
     

    Attached Files:

  5. sevens906

    sevens906 Private E-2

    was wondering is eset smart security 4 a good firewall/antivirus combo, and which malware software should i keep from the ones i downloaded that work. Super Anti-Spyware, Malwarebytes' Anti-Malware, etc. I never had an issue until now with ESET, so let it be free or paid for doesn't matter to me unless it gets the job done. thank you.

    ps. i have a router and use that firewall as well.
    thank you for your help, just wondering about those logs to see if i am still infected.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I apologise! I was just checking through older threads and came across yours. I have been busy what with the Christmas period and it just slipped by me. I am reviewing those logs right now.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    TDSSKiller did the trick for part of the malware however you still have a DNS infection in place that needs to be dealt with.

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Java(TM) 6 Update 14 <--- Uninstall outdated Java

    You can dequarantine the Deamon Tools driver.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running for you now, and again, I offer my apologies for losing track of your thread.
     
  8. sevens906

    sevens906 Private E-2

    np about the late reply i been busy with chistmas and now new years ... so i been using it and its run ok, i uninstalled smart security 4 by eset and installed avir anti virus, and pc tools firewall, spwareblaster and spybot, and revo uninstaller to help with my pc, but i did what you asked and here are the logs.
    thanks for the reply,
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "NameServer"=""
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "NameServer"=""
    [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
    "NameServer"=""
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Also:

    Do you use a router? There is a little button on the bottom ( on most models ) to reset it to factory settings. Do that. You may then need to go back into it to set any special setting that you may have set up originally.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. sevens906

    sevens906 Private E-2

    ok here they are

    question though, it booted a log, it didn't show results alongside it, the log was in notepad, ...anyways, a lot of my services are not loading up, i tried msconfig, running startup and normal mode, switching among them, services and startup programs etc, and still some of my programs won't start up, nothing serious, but my system is running bare for the most part. i dunno how to turn them on.

    thanks
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Tell me which ones exactly?
    You mean you tried normal start up mode and selective? You are in normal start up now according to your logs, which is how you should always run.

    Again, state which services, which start up programs and which programs are either faulting or not running services that should be run.

    Are you being redirected any more??
     
    Last edited: Dec 29, 2010
  12. sevens906

    sevens906 Private E-2

    no not getting redirected anymore, thanks for the help, but something is happening when i reboot to admin nothing loads up (startup programs) and the windows explorer freezes on me and i have to to force restart i believe it's got to be the services.
    let me name the startup programs

    wmdc.exe - windows mobile device center
    TPwrMain.EXE - Toshiba Power Saver
    TosWaitSrv.exe
    TosSENotify
    Teco.exe - Toshiba Eco Utility
    SynTPEnh - Synaptics TouchPad Enchancements
    StartCCC - Catalyst Control Center Launcher
    amd_dc_opt - AMD Dual-Core Optimizer

    some services might have to do with the startup programs of Toshiba
    diskeeper *
    FlexNet licensing service
    nprotect gameguard service
    adobe switchboard (doesn't have to be on)
    TMachinfo - toshiba *
    tpch service - toshiba *

    *most interested in


    now through msconfig the startup programs above are checked which i suppose mean they should be running but are not, when i run revo uninstaller to check on my my startup programs it shows them all and shows not running alongside them

    not to sure about the crash that happens sometimes when my pc loads up, it seems like my drivers turn off and the only thing working might be avira anti-virus but even then it wont let me click or use it.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What exactly do you mean by reboot to admin?
    All of the below are running as a service, so I am not quite sure what you mean.

     
  14. sevens906

    sevens906 Private E-2

    let me try my hardest to write somewhat o.k i been known to run-on and create creative sentences that might confuse people.

    the crash on admin happens when, for the most part, i let users use a restricted account, but when i see an update to this post i tend to log off and re-login with admin. when i do this it starts up but gives me something like most services and drivers are not working. when i try to click on start it crashes and i have to hard reboot. after that windows starts with safety menu and let it load normally and the admin account works.

    now the services you mention and start up programs associated with them show themselves working through msconfig and maybe task manager but are not running, within revo i can tell which are not running, and well they are not in my start up little bar at the bottom.
    thanks
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is not a malware issue. You will have to make a post in software. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. sevens906

    sevens906 Private E-2

    don't super antispware and malwarebytes anti-malware do the same thing i read in one guide that it's best to have one installed, i have spybot, should i keep all 3 or should i remove spybot?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If I were you I would uninstall SpyBot Seacrch and Destroy, and keep both the free versions of Malware BYtes and SUPERantispyware.
     
  18. sevens906

    sevens906 Private E-2

    thanks really for the help, the windows crashes and the services not loading which forum section should i ask for help?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. :)

    You can post in the software section
     
  20. sevens906

    sevens906 Private E-2

    dude i am getting redirected in google again....i think some fraudulent websites got to my brothers trying to buy a cheap guitar, can it be fixed with super anti-spware and malwarebyes antimalware
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh dear. :(
    Doubtful that those two programs alone will solve your problem, but you will need to run them as part of the rest of the malware removal procedures, which, after running, you will need to attach logs into a completely NEW thread. It will cause confusion to piggy back off this thread, and you were clean when I finished up with you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds