Redirect virus and adware serious problems

Status
Not open for further replies.
I am having the toughest time getting rid of this adware and the google redirect problem still exists after completing the 8 steps suggested by your website. I have attached the logs requested. Pleeeeez see if you can help with this serious problem. P.s. when installing malwarebytes I am getting a issue where I must ignore because the setup couldnt find a specific file??? Im not sure what it means but the program started up ok. Please let me know asap...
 

Attachments

  • hijackthis1.txt
    13.3 KB · Views: 1
  • mbam-log-2010-01-15 (20-47-47).txt
    1.1 KB · Views: 2
  • SUPERAntiSpyware Scan Log - 01-15-2010 - 13-23-33.log
    4 KB · Views: 1
Thank you for your patience. I'm not sure if thi will work, but I'd like you to give it a try. you have a process that's running in memory:

Please download OTMovit by Old Timer and save to your desktop.
  • Double-click OTMoveIt3.exe to run it. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Code:
    :Processes	
    
    :Services
    
    :Reg
    
    :Files 
    C:\PROGRAM FILES\INTERNET EXPLORER\WMPSCFGS.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\WMPSCFGS.EXE
    C:\WINDOWS\Prefetch\WMPSCFGS.EXE-2DC2A9E2.pf
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
---------------------------------------
After doing thi, please run this online scan to see if the malware has been moved:
Run Eset NOD32 Online AntiVirus Scanner HERE

Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the Active X control to install
  • Disable your current Antivirus software. You can usually do this with its Notification Tray icon near the clock.
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked
  • Click Scan
  • Wait for the scan to finish
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.

Attach the Eset scan log in your next reply.
Meanwhile I'll be checking the other logs.

EDIT: Please do not use the System Restore feature now. The restore points have malware. I'll have you remove them at the end.
 
both scans completed

Ok both have been tried and here are the logs from otm and eset.
 

Attachments

  • 01202010_193646.log
    4.3 KB · Views: 2
  • log.txt
    1.9 KB · Views: 2
Can you delete the files that Spybot has quarantined?

Please run this:

TFC (Temp File Cleaner)
Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.

TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.

Empty the Recycle Bin

Then run Combofix:
Please download ComboFix HERE:
  • With ComboFix, at the download window, please rename it to Combo-Fix(.exe) before downloading it.

    Important! Save the renamed download to your desktop.
  • Please disable all security programs, such as antiviruses, antispywares, and firewalls. Also disable your internet connection.
  • Double click on the setup file on the desktop to run
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console.
  • When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    (Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.)
  • Query- Recovery Console image
    RcAuto1.gif

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
    whatnext.png

  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a log.Please include the C:\ComboFix.txt in your next reply.
Notes:

  • 1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
    3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
    4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Rescan with HijackThis afterwards.
Attacxh Combofix report and new HJT log to next reply.

I may have to ask someone to write some code for the process in memory- let's see what Combofix does first.
 
Ok when combo fix run it somehow deletes files that dont allow windows to sart correctly. I was able to delete the quarantined files from spybot and tfc seemed to run pretty smooth. Here are the log files for both...
 

Attachments

  • hijackthis.log
    9.5 KB · Views: 1
  • ComboFix.txt
    332 bytes · Views: 1
Did you do the Combofix scan? There is nothing in the report. If you cannot get it to run, please run the following:
Download SDFix HERE and save it to your Desktop.
  • Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Boot into Safe Mode
  • Restart your computer and start pressing the F8 key on your keyboard.
  • Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.

    Run SDFix
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
  • Attach Report.txt back herein next reply.
 
Status
Not open for further replies.
Back