Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Google redirect
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Google redirect
Hi,
Links from google are being redirected to ad sites and various other sites aren't loading at all. I haven't noticed any other symptoms. I've run SuperAntiSpyware and HiJack this and attached logs, but I can't get MalwareBytes to run (or uninstall for that matter). Any help with this would be hugely appreciated! Edit: Have uninstalled MalwareBytes and reinstalled it but it still won't run Edit: Managed to get MalwareBytes to run - had to rename the exe file for it. I ran a quickscan and I've attached the log for it. Currently running a full scan. Will attach the log when it has finished. I really hope someone can help with this. Last edited by Karina M; 11-24-2008 at 07:29 AM.. |
|
#2
|
||||
|
||||
|
I see some norton entries and some mcafee entries - I would guess you uninstalled Norton and installed Mcafee? If so you need to run the Norton Removal Tool
========================================= Disable the real time monitoring for your antivirus product - this can normally be done by right clicking it in the system tray and checking or unchecking a box. =========================================
Combofix will automatically save the log file to C:\combofix.txt |
|
|
|
#3
|
|||
|
|||
|
That's strange - I uninstalled Norton and used the removal tool about 18 months ago! Ah well, ran it again.
Ran combofix and HJT again, have attached logs, along with completed log for mbam full scan. Google is no longer redirecting either. Hooray! Am I fixed? |
|
#4
|
||||
|
||||
|
There is still quite a bit on there, run this program then we can remove the rest manually.
PrevX CSI: http://www.prevx.com/freescan.asp afterwards - click tools and settings -> save scan results -> attach here |
|
#5
|
|||
|
|||
|
Okay, ran PrevX CSI and it came up clean, didn't find anything. Have attached new combofix log and log for PrevX.
Edit: Have just realised you didn't ask for a new combofix log. Think my brain is scrambled! |
|
#6
|
||||
|
||||
|
Run CFScript
Open notepad and copy/paste the text in the code box below into it: NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it. Also .. Pay particular attention to this :- Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it) Quote:
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log. Last edited by Blind Dragon; 11-27-2008 at 01:52 PM.. |
|
#7
|
|||
|
|||
|
Ok, did as instructed and have attached both logs. Thank you for all of this help by the way - it's really appreciated.
|
|
#8
|
||||
|
||||
|
Upload a File to Virustotal
Please visit Virustotal found HERE
============================================== Run Kaspersky Online AV ScannerIn order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
|
|
#9
|
|||
|
|||
|
I'm running the Kaspersky online scanner. I can't find the other file you specified though - it doesn't seem to be there.
|
|
|
|
#10
|
||||
|
||||
|
We will get to that after kaspersky scan then. We may have to change the files attributes for you to be able to see it
|
|
#11
|
|||
|
|||
|
Finally finished the Kaspersky scan! Have attached the log.
Edit: It's back again! Same symptoms as before. Running mbam again, will post the log when it's done. Edit: Found out that my husband was trying to download somethig he shouldn't have. That's why it's back. Edit: Mbam log attached, PrevX also popped up with a virus warning so I've attached the log for that too. Last edited by Karina M; 11-25-2008 at 02:10 PM.. |
|
#12
|
|||
|
|||
|
Update the scanning tools: MBAM & SAS.
Please observe MBAM log file for the following: "Delete on reboot'. A restart of the computer is necessary. Scan with MBAM twice. First scan in the quick mode. Check the log. Restart the computer. The final MBAB scan specifying complete mode so as to root-out files/folders related to the infection. Scan with other tools that have proven value to you. Note to B.D. - pardon my intrusion. I spotted the need to update MBAM. |
|
#13
|
||||
|
||||
|
Please run Combofix again, it is the exact same files
attach the log here that just set us back a few steps - but once we are all done, you should be asked before the malware is installed. We will get the security to a point where if you are infected again, it will be because you said okay to something. Last edited by Blind Dragon; 11-25-2008 at 05:57 PM.. |
|
#14
|
|||
|
|||
|
Ok, attached combofix log. Nobody will be going near the computer till we've got it sorted now!
Edit: IE Stopped working properly - Images not loading. Ran mbam and combofix again but it hasn't helped. Have attached the logs. Last edited by Karina M; 11-26-2008 at 04:08 AM.. |
|
#15
|
||||
|
||||
|
Please update, and run a full scan with MBAM again attaching the fresh log here.
I would also like to try another free tool from my favorite antivirus company Avira AntiRootkit Tool After the anti-rootkit scan please click View Report - Save that report to attach here I would also like to see a fresh hijackthis log. So in your reply I want: 1) MBAM log 2) Avira AR log 3) fresh hijackthis ran after |
|
#16
|
|||
|
|||
|
Okay, all 3 scans run. I didn't take any action after the rootkit scan except to save the log.
|
|
#17
|
||||
|
||||
|
Good work. It's adding known bad sites to your trusted zone. I suggest you install a free tool called Spyware Blaster when we get you clean to prevent this in the future. You may also consider using an alternative browser to IE, as most malware from surfing is targeted towards the most popular browser.
============================================== Remove bad HijackThis entries
======================================================= Right click on this link DelO15Domains.inf and choose Save As. Save it to your desktop. Right click on that file and choose Install. It will run immediately (you won't be able to see anything happen). You may delete it afterwards. NOTE: This script will delete any sites you may have added to the Trusted Sites. So if you want them back, you have to add them back to the Trusted Sites again. ======================================================== Was Avira Root Kit Detection able to fix the 3 registry entries it found? It doesn't look like it, but was curious. ========================================================= Open Notepad (from accessories) copy (Ctrl +C) and paste (Ctrl +V) the text in the code box below into Notepad. Code:
@echo off ATTRIB -R c:\windows\system32\iwsnec.dll ATTRIB -R c:\windows\system32\kbmccn.dll del unhidedll.cmd and exit Save it to your desktop as File name: unhidedll.cmd Save as type: All Files Once done, double click service.cmd to run it. A command window will open briefly, then close. This is quite normal. ========================================================== Upload a File to Virustotal Please visit Virustotal found HERE
Do the same for c:\windows\system32\kbmccn.dll =========================================================== After you do this, we have just a few more things to remove, then can clean up and secure the system. |
|
#18
|
|||
|
|||
|
Did everything except upload files to virustotal - they still aren't showing up, sorry.
I don't think ARKD did clean anything up. If it did, it certainly didn't tell me about it! |
|
#19
|
||||
|
||||
|
When you scan with the ARKD, after the scan does it give you the option to quarantine, in the left panel?
|
|
#20
|
|||
|
|||
|
Just rescanning now. If it does, I assume I should quarantine them?
|
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Google Redirect | Virus & Malware removal | 1 | 10-17-2008 04:27 AM | |
| Google Redirect Virus? | Virus & Malware removal | 1 | 09-20-2008 07:08 PM | |
| Google search redirect to nothing IP 85.255.120.226 | Virus & Malware removal | 28 | 04-27-2008 03:17 AM | |
| Google redirect | Virus & Malware removal | 10 | 05-15-2007 06:14 PM | |
| Google redirect | Virus & Malware removal | 17 | 03-01-2007 10:06 PM | |
All times are GMT -4. The time now is 06:30 AM.




Run Kaspersky Online AV Scanner