also @ TechSpot: The One Thing Next-Gen Consoles Could Really Learn From The PC

Redirected searches (yeah, again)

Discussion in 'Virus and Malware Removal' started by mikelorus, Feb 6, 2010.

  1. mikelorus Newcomer, in training Posts: 41

    When I try to paste in the text files, it says my connection has been interrupted, so I'm just going to try to attach the files. Hope that's okay, if not I can try to edit them in on another computer.

    Attached Files:

  2. Broni Malware Annihilator Posts: 40,091   +187

    How is redirection issue at the moment?

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab (Reg Error: Key error.)
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Reg Error: Key error.)
      
      
      :Services
      
      :Reg
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
      "DisableMonitoring" =-
       [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
      "DisableMonitoring" =-
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
      "139:TCP" =-
      "445:TCP" =-
      "137:UDP" =-
      "138:UDP" =-
      
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [resethosts]
      [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
  3. mikelorus Newcomer, in training Posts: 41

    Redirection seems to have decreased, but I'm still getting popups, and inconsistent internet connection, that is, it sometimes is always off until I restart my computer. That may or may not be related though.

    Attached Files:

  4. Broni Malware Annihilator Posts: 40,091   +187

    Restart in Safe Mode and try to run rKill, then broni.com
  5. mikelorus Newcomer, in training Posts: 41

    Thanks again for all your help >.>

    Attached Files:

  6. Broni Malware Annihilator Posts: 40,091   +187

    Combofix log looks pretty much clean.

    Any particular site(s), you're getting redirected to?
    What kind of pop-us are you getting?
    What is the browser, you're using?
    Did you try different browser?

    ======================================================================

    Please download OTC to your desktop. It'll remove most tools and logs we used so far. If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    • Double-click OTC.exe to run it. (Vista and 7 users, please right click on OTC and select "Run as an Administrator")
    • Click on the CleanUp! button and follow the prompts.
    • You will be asked to reboot the machine to finish the Cleanup process, choose Yes. If it doesn't ask you to reboot, restart computer manually.
    • After the reboot all the tools we used should be gone.
    • The tool will delete itself once it finishes.

    ========================================================================

    1. Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.


    2. Go to Kaspersky website and perform an online antivirus scan.

    1. Disable your active antivirus program.
    2. Read through the requirements and privacy statement and click on Accept button.
    3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    4. When the downloads have finished, click on Settings.
    5. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

    • Spyware, Adware, Dialers, and other potentially dangerous programs
      [*] Archives
      [*] Mail databases
    6. Click on My Computer under Scan.
    7. Once the scan is complete, it will display the results. Click on View Scan Report.
    8. You will see a list of infected items there. Click on Save Report As....
    9. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

    Post fresh HijackThis log as well.
     
  7. mikelorus Newcomer, in training Posts: 41

    Usually those sites that just have advertising links, pop ups are sometimes bogus google news or "registry defender".
    [IMG]
    They are like the first third and seventh in the pic.
    I'm using firefox, I have tried to do some searches with IE but it's typically on and off for firefox =\

    Attached Files:

  8. Broni Malware Annihilator Posts: 40,091   +187

    Please download OTM

    • Save it to your desktop.
    • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Code:
    :Processes
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\cache\6.0
          
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [Reboot]
    
    • Return to OTM, right click in the Paste Instructions for Items to be Movedwindow (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTM and reboot your PC.

    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
  9. mikelorus Newcomer, in training Posts: 41

  10. Broni Malware Annihilator Posts: 40,091   +187

    How are redirections and pop-ups now?
  11. mikelorus Newcomer, in training Posts: 41

    Still getting pop-ups, haven't gotten any redirections yet.
  12. Broni Malware Annihilator Posts: 40,091   +187

    We may be getting somewhere then :)

    Can you check, if pop-ups happen in IE as well.
    Do pop-ups happen, only, when you actually use Firefox, or even with FF closed?
    Do you pop-up blocker enabled?

    Close Firefox. Go Start>All Programs>Mozilla Firefox, click on Mozilla Firefox (safe mode). Still pop-ups?
  13. mikelorus Newcomer, in training Posts: 41

    Got a popup in IE

    Pop-ups only ocur when firefox is open

    I have a popup blocker enabled, but I don't know if it's doing its job correctly.

    Got a popup in safe mode.

    Is a new tab still considered a popup? They are kind of infrequent but noticeable still.
  14. Broni Malware Annihilator Posts: 40,091   +187

  15. mikelorus Newcomer, in training Posts: 41

    still occasionally getting popups, but I guess it's not really a big deal.
  16. Broni Malware Annihilator Posts: 40,091   +187

    Delete broni.com, download fresh copy of Combofix and give me new log.
  17. mikelorus Newcomer, in training Posts: 41

    Here's a fun new wrinkle, it says it cannot be saved because an unknown error occurred, and that I should try to save it in a different place. I can't save it to my desktop or anywhere.
  18. Broni Malware Annihilator Posts: 40,091   +187

    Rename it to broni.com again BEFORE saving it to your desktop.
    Something is still hiding there.
  19. mikelorus Newcomer, in training Posts: 41

    I had to run it in safe mode to get it to work

    Attached Files:

  20. Broni Malware Annihilator Posts: 40,091   +187

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    
    Folder::
    c:\documents and settings\Michael\Local Settings\Application Data\iohecvqxg
    
    
    Driver::
    
    Registry::
    
    RegLockDel::
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.