also @ TechSpot: Check your bill: AT&T adds new 'administrative fee' to wireless bills

(yet another) google redirect hijack case, foul play suspected

Discussion in 'Virus and Malware Removal' started by rvee, Jun 3, 2011.

  1. Broni Malware Annihilator Posts: 39,437   +177

    Good Night :)
  2. rvee Newcomer, in training Posts: 19

    ESET completed scanning 190k files in around an hour, No threats found, and no log popped up - is there a hidden one somewhere?
  3. Broni Malware Annihilator Posts: 39,437   +177

    It won't produce any log, if nothing found.

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    12. Please, let me know, how your computer is doing.
  4. rvee Newcomer, in training Posts: 19

    Thanks, but I'm still getting redirects in IE and FF (and occasionally chrome), so I'm not sure my PC is clean!

    most often clicking a google result points the browser off to one of these:
    scour.com
    gallantsearch.com
    famousclicks.com
    searchpotluck.com
    clinkingclicks.com
    toppingsearch.com

    Then after a wait it ends up elsewhere on ad sites or fake shopping sites

    RVee
  5. Broni Malware Annihilator Posts: 39,437   +177

    Please download GooredFix from one of the locations below and save it to your Desktop
    Download Mirror #1
    Download Mirror #2
    • Ensure all Firefox windows are closed.
    • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
    • When prompted to run the scan, click Yes.
    • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
  6. rvee Newcomer, in training Posts: 19

    runs OK, a dos box flashes up, then a dialogue box saying its going to scan and fix, when I click yes I get an error dialogue:

    Gooredfix error
    Unable to create logfile.
     
  7. Broni Malware Annihilator Posts: 39,437   +177

    Did you?
  8. rvee Newcomer, in training Posts: 19

    yes ran as admin, also tried running from elevated cmd prompt - same result.
  9. Broni Malware Annihilator Posts: 39,437   +177

    I must admit, it's pretty puzzling...

    Your routers DNS settings my have been hijacked.
    Please, follow this instructions in attempt to fix the issue: https://store.opendns.com/setup/router/
    Once you set your new DNS settings reboot your computer.
    Then go to http://opendns.com/welcome/ to see if it is working. If you see a checkmark then you switched to OpenDNS.
  10. rvee Newcomer, in training Posts: 19

    I checked the DNS settings were correct when I reset the router yesterday and considered switching over to opendns then, I'll give it a go.

    Thanks, as always for your, time.
  11. Broni Malware Annihilator Posts: 39,437   +177

    Let me know...
  12. rvee Newcomer, in training Posts: 19

    swapped to opendns, rebooted to flush cache, successful connected to the opendns welcome page.

    quick try of firefox & chrome... both redirected. :(

    This is so puzzling. I want to find out the cause just to satisfy curiosity, but by the same token this is taking up a lot of time and I tempted to just reformat and reinstall the OS and apps.
  13. Broni Malware Annihilator Posts: 39,437   +177

    There are cases (rare), when sometimes, there is no other option.
    Let me know, what you want to do.
  14. rvee Newcomer, in training Posts: 19

    Well I think we've given it a good shot and tried just about everything, I think I'll use it as excuse to switch to an SSD and get a fresh install going.

    Really big thanks for your time and patience.:wave:
  15. Broni Malware Annihilator Posts: 39,437   +177

    You're very welcome [IMG]

    Good luck!