Yahoo redirect problem!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by alexmndz, Mar 2, 2010.

  1. alexmndz

    alexmndz Private E-2

    Hello,

    I keep getting redirected in yahoo searches and I have followed the removal guide as well the XP cleaning instructions. I did not however ran Combofix or MGlogs until I get instructed to do so. Please let me know ASAP. Thanks for all your help with this. Your guys are a godsend.
     
  2. alexmndz

    alexmndz Private E-2

    Forgot to include attachments.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run both MGTools.exe and ComboFix.exe. Then attach those logs.
     
  4. alexmndz

    alexmndz Private E-2

    Hello,

    Thanks for getting back to me. I have run both MGTools and Combofix and have attached logs. FYI im still getting popups. Also I got an error while running MGTools which was Error Msg Type 4 on guide about process Dll.exe application error. Thanks again.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this computer on a domain ( sanchezog.com )? If so, do not check the 017 line boxes in the HJT fix.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    c:\documents and settings\All Users\Application Data\SAHERGIDUV
    c:\documents and settings\All Users\Application Data\2b6fbf8

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. alexmndz

    alexmndz Private E-2

    Thanks Tim!!!

    This is done. And yes this pc is on a domain but logged in as Admin. I have attached MGlogs.zip for you to view. Unfortunately I am still getting redirected and some popups. Let me know what to do next. I really appreciate your help. Thanks again!
     

    Attached Files:

    Last edited: Mar 4, 2010
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't have HJT fix anything!

    Reset Host File


    • Open Notepad.
    • Copy and Paste everything from the Code Box below into Notepad: (Do not include the word Code:)
      Code:
      @Echo off
      pushd\windows\system32\drivers\etc
      attrib -h -s -r hosts
      echo 127.0.0.1 localhost>HOSTS
      attrib +r +h +s hosts
      popd
      del %0
    • Go to File >> Save As
    • Save File name as FixHosts.bat
    • Change Save as Type to All Files and save the file to your Desktop.

    Now double click on the desktop FixHosts.bat to run the batch file. It will self-delete when completed.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. alexmndz

    alexmndz Private E-2

    Thanks Tim for getting back to me. BTW I did what you asked and dont know why HJT didnt fix anything. I did the reset host file and and ran getlogs.bat as well and have attached MGlogs.zip and two pics where I received erros. Also, I ran a HJT again and fixed check those hosts and they are still there. And Im still getting redirected. Let me know. Thanks.
     

    Attached Files:

    Last edited: Mar 5, 2010
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do it the old fashioned way:

    Click Start > Run and type in cmd

    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window


    Now:
    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    EDIT; You are doing this on an account with Admin. privileges?? Yes??
     
  10. alexmndz

    alexmndz Private E-2

    Tim,

    I flush dns and then I get msg when I double click on hostsexpert.exe I clicked ok and then clicked on restore MHF and get another error msg. And it kicks me out. I have attached both screens.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then have you tried to manually remove all the items in your hosts file that were listed in the HJT fix I gave you?
     
  12. alexmndz

    alexmndz Private E-2

    Tim,

    Yes I am doing this on Admins account and have followed all steps you have instructed me to do so. When you say to manually remove those hosts file do you mean in HJT cause I have tried doing that countless times and they still reappear?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I mean you need to go to:
    windows\system32\drivers\etc\hosts and open it with notepad and delete all but the first two files which should be:
    Code:
    127.0.0.1       localhost
    ::1             localhost
    Possibly only the first will be there....but delete all the rest in the list and when done, click File/Save.
     
  14. alexmndz

    alexmndz Private E-2

    Tim,

    Deleted hosts but when I do File/Save it doesnt want to save? And gives me this msg.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You aren't hitting Save As are you?
     
  16. alexmndz

    alexmndz Private E-2

    Tim,

    I got the same msg with HJT and followed the instructions and rebooted but did not take the changes. It looks like the host system file has read/access denied look at the properties and it has Authenticated Users and I cannot add the Administrator it has the ADD greyed out. Could this file be corrupted?
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not sure what you are doing, but make sure it is this:

    When editing the HOSTS file remember to File > Save (only)
    • Do not File > Save As
    • Do not "associate" the HOSTS file with Notepad, this occurs when you select the option to "Always Open" the HOSTS file in Notepad. This will convert the HOSTS (no 3-letter extension) file to a "text file"
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read this Host's Editor
    Scroll down to Safely Rename the HOSTS file and follow those instructions. Tell me how that goes.
     
  19. alexmndz

    alexmndz Private E-2

    Tim,

    I understand and thats exactly what I did. I am not doing a file save as rather a save but it gives me this window saying cannot create the c:\windows\system32\drivers\etc\hosts file make sure the path and filename are correct and then gives you option to save as.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may have missed my second post to you regarding using the Hosts editor site.
     
  21. alexmndz

    alexmndz Private E-2

    Tim,

    Followed Host editor instructions on renaming hosts file and when I run renhosts.bat it tells me the system cannot find the file specified?
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you press a key to continue? Can you now manually edit the file?
     
  23. alexmndz

    alexmndz Private E-2

    Yes I did Tim and then I go into notepad c:\windows\system32\drivers\etc\hosts delete hosts and I still can't save.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have disabled all your AV and AS as well as firewall programs?
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  27. alexmndz

    alexmndz Private E-2

    Attached Files:

  28. alexmndz

    alexmndz Private E-2

    Tim,

    Went to double check if hosts file is there and I don't see it anymore I see a hosts.new but in txt format. Let me know what you think. Thanks again for all your help.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open notepad and copy and paste this into it:
    Code:
          # Copyright (c) 1993-1999 Microsoft Corp.
          #
          # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
          #
          # This file contains the mappings of IP addresses to host names. Each
          # entry should be kept on an individual line. The IP address should
          # be placed in the first column followed by the corresponding host name.
          # The IP address and the host name should be separated by at least one
          # space.
          #
          # Additionally, comments (such as these) may be inserted on individual
          # lines or following the machine name denoted by a '#' symbol.
          #
          # For example:
          #
          # 102.54.94.97 rhino.acme.com # source server
          # 38.25.63.10 x.acme.com # x client host
    
             127.0.0.1 localhost
    Save as c:\windows\system32\drivers\etc\hosts


    Tell me if that goes ok.
     
  30. alexmndz

    alexmndz Private E-2

    Tim,

    Done. But it saves as a .txt file. I clicked all files in save as type. Anyways whats next.
     

    Attached Files:

    Last edited: Mar 9, 2010
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Give me a screen shot of the contents of the hosts.new file.
     
  32. alexmndz

    alexmndz Private E-2

    Here you go Tim.
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Perfect....right click it and rename it....just take out the .new extension. Then just hit save.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  34. alexmndz

    alexmndz Private E-2

    Tim,

    Thanks for everything!!! You are a Godsend...keep up the awesome work. Laters.
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds