also @ TechSpot: Updated Microsoft EULA prohibits class action lawsuits

TechSpot

[Solved] Google redirect nothing works

Discussion in 'Virus and Malware Removal' started by misiorto, Nov 30, 2010.

Thread Status:
Not open for further replies.
  1. misiorto Newcomer, in training

    There has been no redirection since I replaced the files: winlogon and explorer. However, in the last scan ESET found something.
    Moreover I believe after running TFC my computer rebooted and when it started again my antivir Avira found and moved to quarantine ADWARE/Zwangi.dhd. (I'll put the Avira log at the very end of the post)
    I'll post the logs below starting with the ESET, laterOTL and Security check:

    ESET
    C:\Documents and Settings\All Users\Dokumenty\Server\hlp.dat Win32/Bamital.DZ trojan

    All processes killed
    ========== OTL ==========
    Starting removal of ActiveX control {33564D57-0000-0010-8000-00AA00389B71}
    C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-0000-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\WINDOWS\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 32902 bytes

    User: michał
    ->Temp folder emptied: 10426036 bytes
    ->Temporary Internet Files folder emptied: 112100256 bytes
    ->Java cache emptied: 1385885 bytes
    ->FireFox cache emptied: 76385981 bytes
    ->Google Chrome cache emptied: 315907355 bytes
    ->Flash cache emptied: 1821 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 492,00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService

    User: michał
    ->Flash cache emptied: 0 bytes

    User: NetworkService

    Total Flash Files Cleaned = 0,00 mb

    Error: Unable to interpret <[Reboot]Then click the Run Fix button at the top > in the current context!

    OTL by OldTimer - Version 3.2.17.3 log created on 12132010_193335

    Files\Folders moved on Reboot...
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1QZ2DGJ\CA05E7W5.htm moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1QZ2DGJ\CAU7O5AL.com moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1QZ2DGJ\dot[2].html moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\GDIZO56F\01[1].htc moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\EH0BGLWN\CAEZ8ZJG.com moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\EH0BGLWN\topic157421[1].html moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\EH0BGLWN\zumibox[2].html moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\EBMJSBWL\CAO1UJWH.com moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\2DINMH0X\crosspixel-dest[1].htm moved successfully.
    C:\Documents and Settings\michał\Ustawienia lokalne\Temporary Internet Files\Content.IE5\2DINMH0X\folder_d[2].html moved successfully.

    Registry entries deleted on Reboot...


    Results of screen317's Security Check version 0.99.5
    Windows XP Service Pack 2
    Out of date service pack!!
    Internet Explorer 6 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Avira AntiVir Personal - Free Antivirus
    Antivirus up to date!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    SAS Private JRE (J2SE(tm) Java Runtime Environment 1.4.2_09)
    Java(TM) 6 Update 22
    Out of date Java installed!
    Adobe Flash Player 10.1.53.64
    Adobe Reader 9.4.1
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Avira Antivir avgnt.exe
    Avira Antivir avguard.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````





    Avira AntiVir Personal
    Report file date: 13 grudnia 2010 19:36

    Scanning for 3140431 virus strains and unwanted programs.

    The program is running as an unrestricted full version.
    Online services are available:

    Licensee : Avira AntiVir Personal - FREE Antivirus
    Serial number : 0000149996-ADJIE-0000001
    Platform : Windows XP
    Windows version : (Dodatek Service Pack 2) [5.1.2600]
    Boot mode : Normally booted
    Username : SYSTEM
    Computer name : KOMP

    Version information:
    BUILD.DAT : 10.0.0.607 31826 Bytes 10-11-30 19:17:00
    AVSCAN.EXE : 10.0.3.5 435368 Bytes 10-12-12 20:14:53
    AVSCAN.DLL : 10.0.3.0 46440 Bytes 10-04-01 12:57:06
    LUKE.DLL : 10.0.3.2 104296 Bytes 10-12-12 20:14:53
    LUKERES.DLL : 10.0.0.1 12648 Bytes 10-02-10 23:40:50
    VBASE000.VDF : 7.10.0.0 19875328 Bytes 09-11-06 19:39:24
    VBASE001.VDF : 7.10.1.0 1372672 Bytes 09-11-19 19:39:24
    VBASE002.VDF : 7.10.3.1 3143680 Bytes 10-01-20 23:04:44
    VBASE003.VDF : 7.10.3.75 996864 Bytes 10-01-26 19:04:40
    VBASE004.VDF : 7.10.4.203 1579008 Bytes 10-03-05 16:38:13
    VBASE005.VDF : 7.10.6.82 2494464 Bytes 10-04-15 19:59:05
    VBASE006.VDF : 7.10.7.218 2294784 Bytes 10-06-02 21:50:19
    VBASE007.VDF : 7.10.9.165 4840960 Bytes 10-07-23 07:36:35
    VBASE008.VDF : 7.10.11.133 3454464 Bytes 10-09-13 11:08:25
    VBASE009.VDF : 7.10.13.80 2265600 Bytes 10-11-02 11:08:26
    VBASE010.VDF : 7.10.13.81 2048 Bytes 10-11-02 11:08:27
    VBASE011.VDF : 7.10.13.82 2048 Bytes 10-11-02 11:08:27
    VBASE012.VDF : 7.10.13.83 2048 Bytes 10-11-02 11:08:27
    VBASE013.VDF : 7.10.13.116 147968 Bytes 10-11-04 11:08:27
    VBASE014.VDF : 7.10.13.147 146944 Bytes 10-11-07 11:08:27
    VBASE015.VDF : 7.10.13.180 123904 Bytes 10-11-09 11:08:27
    VBASE016.VDF : 7.10.13.211 122368 Bytes 10-11-11 11:08:27
    VBASE017.VDF : 7.10.13.243 147456 Bytes 10-11-15 11:08:27
    VBASE018.VDF : 7.10.14.15 142848 Bytes 10-11-17 11:08:27
    VBASE019.VDF : 7.10.14.41 134144 Bytes 10-11-19 11:08:27
    VBASE020.VDF : 7.10.14.63 128000 Bytes 10-11-22 11:08:28
    VBASE021.VDF : 7.10.14.87 143872 Bytes 10-11-24 11:03:50
    VBASE022.VDF : 7.10.14.116 140800 Bytes 10-11-26 07:59:53
    VBASE023.VDF : 7.10.14.147 150528 Bytes 10-11-30 17:58:46
    VBASE024.VDF : 7.10.14.175 126464 Bytes 10-12-03 20:51:50
    VBASE025.VDF : 7.10.14.203 120320 Bytes 10-12-07 10:03:22
    VBASE026.VDF : 7.10.14.230 137216 Bytes 10-12-09 20:14:50
    VBASE027.VDF : 7.10.14.231 2048 Bytes 10-12-09 20:14:50
    VBASE028.VDF : 7.10.14.232 2048 Bytes 10-12-09 20:14:50
    VBASE029.VDF : 7.10.14.233 2048 Bytes 10-12-09 20:14:51
    VBASE030.VDF : 7.10.14.234 2048 Bytes 10-12-09 20:14:51
    VBASE031.VDF : 7.10.15.0 100352 Bytes 10-12-12 20:14:51
    Engineversion : 8.2.4.122
    AEVDF.DLL : 8.1.2.1 106868 Bytes 10-07-30 07:57:49
    AESCRIPT.DLL : 8.1.3.48 1286524 Bytes 10-12-03 20:51:58
    AESCN.DLL : 8.1.7.2 127349 Bytes 10-11-24 11:08:32
    AESBX.DLL : 8.1.3.2 254324 Bytes 10-11-24 11:08:32
    AERDL.DLL : 8.1.9.2 635252 Bytes 10-11-24 11:08:31
    AEPACK.DLL : 8.2.4.1 512375 Bytes 10-12-03 20:51:57
    AEOFFICE.DLL : 8.1.1.10 201084 Bytes 10-11-24 11:08:31
    AEHEUR.DLL : 8.1.2.54 3113335 Bytes 10-12-08 10:03:27
    AEHELP.DLL : 8.1.16.0 246136 Bytes 10-12-03 20:51:52
    AEGEN.DLL : 8.1.5.0 397685 Bytes 10-12-03 20:51:52
    AEEMU.DLL : 8.1.3.0 393589 Bytes 10-11-24 11:08:29
    AECORE.DLL : 8.1.19.0 196984 Bytes 10-12-03 20:51:51
    AEBB.DLL : 8.1.1.0 53618 Bytes 10-04-25 16:28:43
    AVWINLL.DLL : 10.0.0.0 19304 Bytes 10-08-02 15:09:58
    AVPREF.DLL : 10.0.0.0 44904 Bytes 10-08-02 15:09:56
    AVREP.DLL : 10.0.0.8 62209 Bytes 10-06-17 14:27:14
    AVREG.DLL : 10.0.3.2 53096 Bytes 10-08-02 15:09:56
    AVSCPLR.DLL : 10.0.3.2 84328 Bytes 10-12-12 20:14:53
    AVARKT.DLL : 10.0.22.6 231784 Bytes 10-12-12 20:14:52
    AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 10-11-24 07:27:29
    SQLITE3.DLL : 3.6.19.0 355688 Bytes 10-06-17 14:27:24
    AVSMTP.DLL : 10.0.0.17 63848 Bytes 10-08-02 15:09:58
    NETNT.DLL : 10.0.0.0 11624 Bytes 10-06-17 14:27:22
    RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 10-01-28 13:10:22
    RCTEXT.DLL : 10.0.58.0 97128 Bytes 10-08-02 15:10:10

    Configuration settings for the scan:
    Jobname.............................: avguard_async_scan
    Configuration file..................: C:\Documents and Settings\All Users\Dane aplikacji\Avira\AntiVir Desktop\TEMP\AVGUARD_4d3de5a4\guard_slideup.avp
    Logging.............................: low
    Primary action......................: repair
    Secondary action....................: quarantine
    Scan master boot sector.............: on
    Scan boot sector....................: off
    Process scan........................: on
    Scan registry.......................: off
    Search for rootkits.................: off
    Integrity checking of system files..: off
    Scan all files......................: All files
    Scan archives.......................: on
    Recursion depth.....................: 20
    Smart extensions....................: on
    Macro heuristic.....................: on
    File heuristic......................: high

    Start of the scan: 13 grudnia 2010 19:36

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
    Scan process 'GlobeTrotter Connect.exe' - '1' Module(s) have been scanned
    Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
    Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
    Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
    Scan process 'Reader_sl.exe' - '1' Module(s) have been scanned
    Scan process 'RUNDLL32.EXE' - '1' Module(s) have been scanned
    Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
    Scan process 'sm56hlpr.exe' - '1' Module(s) have been scanned
    Scan process 'HPWuSchd2.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
    Scan process 'notepad.exe' - '1' Module(s) have been scanned
    Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
    Scan process 'isqlplus' - '1' Module(s) have been scanned
    Scan process 'java.exe' - '1' Module(s) have been scanned
    Scan process 'java.exe' - '1' Module(s) have been scanned
    Scan process 'apache.exe' - '1' Module(s) have been scanned
    Scan process 'hpqwmiex.exe' - '1' Module(s) have been scanned
    Scan process 'dbsnmp.exe' - '1' Module(s) have been scanned
    Scan process 'ORACLE.EXE' - '1' Module(s) have been scanned
    Scan process 'avshadow.exe' - '1' Module(s) have been scanned
    Scan process 'TNSLSNR.exe' - '1' Module(s) have been scanned
    Scan process 'cmd.exe' - '1' Module(s) have been scanned
    Scan process 'apache.exe' - '1' Module(s) have been scanned
    Scan process 'agntsrvc.exe' - '1' Module(s) have been scanned
    Scan process 'omtsreco.exe' - '1' Module(s) have been scanned
    Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
    Scan process 'jqs.exe' - '1' Module(s) have been scanned
    Scan process 'GtDetectSc.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned

    Starting the file scan:

    Begin scan in 'C:\Documents and Settings\michał\Pulpit\prevxcsifree.exe'
    C:\Documents and Settings\michał\Pulpit\prevxcsifree.exe
    [DETECTION] Contains virus patterns of Adware ADWARE/Zwangi.dhd
    [NOTE] The file was moved to the quarantine directory under the name '4fffc955.qua'.


    End of the scan: 13 grudnia 2010 19:36
    Used time: 00:11 Minute(s)

    The scan has been done completely.

    0 Scanned directories
    53 Files were scanned
    1 Viruses and/or unwanted programs were found
    0 Files were classified as suspicious
    0 files were deleted
    0 Viruses and unwanted programs were repaired
    1 Files were moved to quarantine
    0 Files were renamed
    0 Files cannot be scanned
    52 Files not concerned
    0 Archives were scanned
    0 Warnings
    1 Notes


    The scan results will be transferred to the Guard.
  2. Broni Malware Annihilator

    I apologize for the delay.
    Somehow, email notification missed me :)

    You need to update Internet Explorer to at least version 7. Version 6 is obsolete and thus dangerous.

    ======================================================================

    Uninstall SAS Private JRE (J2SE(tm) Java Runtime Environment 1.4.2_09)

    =====================================================================

    You need to install Service Pack 3!

    =====================================================================

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      
      :Services
      
      :Reg
      
      :Files
      C:\Documents and Settings\All Users\Dokumenty\Server\hlp.dat
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    =======================================================================

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current (including Service Pack 3 installation and IE upgrade).

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    12. Please, let me know, how your computer is doing.
  3. misiorto Newcomer, in training

    Let me ask You a couple of questions before I proceed with Your instructions.
    1. Do I need to upgrade IE - I use Mozzila?
    2. What about the threat found by ESET (C:\Documents and Settings\All Users\Dokumenty\Server\hlp.dat Win32/Bamital.DZ trojan)?
    3. Can I change all the passwords using my computer?
  4. misiorto Newcomer, in training

    Hi,
    I moved from step 1 to step 2 without postin the OTL log. I think that sthe second cleaning step deleted the log. Sorry for my mistake. Do You want me to install OTL once again and run a scan.
  5. Broni Malware Annihilator

    The 1st OTL run was supposed to remove C:\Documents and Settings\All Users\Dokumenty\Server\hlp.dat file, so if you ran it, you should be fine.
    You can check manually, the file is gone.

    1. Yes. IE is still on your computer, so it must be updated.
    3. Now, when your computer is clean, yes.
  6. misiorto Newcomer, in training

    The file was removed. Everything wored fine. There has been no rediriction since I replaced the windows' files. I would like to thank You for the help. Otherwise I would have to reinstall the system, which would cause a lot of trouble for me in current situation.
  7. Broni Malware Annihilator

    Yes!! [IMG]
    Good luck and stay safe :)
Thread Status:
Not open for further replies.