Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Begin your free trial now
Pay-as-you-go options starting at $10/user/month
Pay-as-you-go options starting at $10/user/month
Google search Browser redirects
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Google search Browser redirects
Hello,
Starting this morning I am getting random redirects of my browser google search. I go to the search bar on the top right of my Internet explorer 8 and type a search and it takes me to links that look like googles but then when I click on the link I am interested in it takes me to a random site. If I choose bing as the search engine after this I seem to have no problems. If I choose google after this it works too only the default search provider (ostensibly google) seems to have the problem. I followed the procedures mentioned in the forum here and here are the logs. Please help. |
|
#2
|
||||
|
||||
|
You have some Norton's leftovers.
Please, run Norton Removal Tool: http://service1.symantec.com/Support...05033108162039 Then.... Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
Make sure, you re-enable your security programs, when you're done with Combofix. DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!! |
|
#3
|
|||
|
|||
|
Combofixlog and HJT log
Hello,
Here are the logs. As I was running the combofix it seems that a program ostensibly "Windows Security Center" automatically started up and said it found some 25 threats in my computer and asked me to register to get the computer immunized the popups indicate that it is from XP smart security and seems to not let me turn on my windows built in firewall. I am not sure if this is legit and remembering the warning not to install anything I did not do anything. Awaiting your response. Thanks |
|
#4
|
||||
|
||||
|
"Windows Security Center" is surely a fake, so make sure not to click on anything like that.
Please download Profiles by noahdfear. * Save it to your desktop. * Double-click profiles.exe and post its log when you reply. ========================================================================= Download TDSSKiller and save it to your Desktop. Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop. Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK. "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file. When it is done, a log file should be created on your C: drive called TDSSKiller.txt please copy and paste the contents of that file here. |
|
#5
|
|||
|
|||
|
Here are the logs looks like the tdskiller found something
Hope I can get this nasty out of the system soon. Later when we are done maybe you can shed some light how I may have caught this. I know the answers depend on several parameters and browsing habits but any suggestions may help me in the future.
PS: I noticed that TDSS seems to have indicated that it will cure something on reboot but I have not rebooted as I think you will want me to do something else than what is suggested. Last edited by arunbav; 04-11-2010 at 02:43 PM.. Reason: added info |
|
|
|
#6
|
||||
|
||||
|
Uninstall Combofix:
Go Start > Run [Vista users, go Start>"Start search"] Type in: Combofix /Uninstall Note the space between the "Combofix" and the "/Uninstall" Click OK (Vista users - press Enter). Restart computer. ==================================================================== Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
Make sure, you re-enable your security programs, when you're done with Combofix. DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!! |
|
#7
|
|||
|
|||
|
Latest Logs am I clean?
Here are the latest combofix and HJT logs. Am I clean now? My browser seems to be behaving ok ( google queries do not get redirected as yet). But I'll let the logs inform you better. Thanks
|
|
#8
|
||||
|
||||
|
I'm glad to see, redirection is gone
![]() 1. Please open Notepad
2. Now copy/paste the entire content of the codebox below into the Notepad window: Code:
KillAll:: File:: c:\windows\system32\drivers\lvuvc.hs Folder:: c:\documents and settings\All Users\Application Data\Symantec c:\program files\Common Files\Symantec Shared c:\documents and settings\Arun Bhaskar\Application Data\Symantec Driver:: NeroNET pciinfo Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000000 "FirewallOverride"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000000 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"=dword:00000001 "DisableNotifications"=dword:00000000 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"=- RegLockDel:: MBR:: 3. Save the above as CFScript.txt 4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. ![]() 5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
|
|
#9
|
|||
|
|||
|
New Logs Please let me know if you think I am clean
Please let me know if my pc is clean. Thanks for all the help.
|
|
#10
|
||||
|
||||
|
I surely will let you know, as soon, as it's clean
![]() Uninstall Combofix: Go Start > Run [Vista users, go Start>"Start search"] Type in: Combofix /Uninstall Note the space between the "Combofix" and the "/Uninstall" Click OK (Vista users - press Enter). Restart computer. ====================================================================== 1. Download Temp File Cleaner (TFC) Double click on TFC.exe to run the program. Click on Start button to begin cleaning process. TFC will close all running programs, and it may ask you to restart computer. 2. Go to Kaspersky website and perform an online antivirus scan. 1. Disable your active antivirus program. 2. Read through the requirements and privacy statement and click on Accept button. 3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run. 4. When the downloads have finished, click on Settings. 5. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
7. Once the scan is complete, it will display the results. Click on View Scan Report. 8. You will see a list of infected items there. Click on Save Report As.... 9. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here. Post fresh HijackThis log as well. |
|
#11
|
|||
|
|||
|
I declared victory too soon :-(
Here are the logs from Kaspersky scan (it took a long while to run hence the delay in the post) and the latest HJT log. Kaspersky finds nothing but redirection is still occuring :-(. Please advise.
|
|
#12
|
||||
|
||||
|
Download OTL to your Desktop.
* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. * Under the Custom Scan box paste this in: netsvcs %SYSTEMDRIVE%\*.exe /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys /md5stop %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav CREATERESTOREPOINT * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
|
|
#13
|
|||
|
|||
|
OTL Log and OTL Extras
Here are the logs. Thanks
|
|
#14
|
||||
|
||||
|
Before I check your logs, can you please explain better this:
Quote:
Did you try another browser? |
|
#15
|
|||
|
|||
|
Explanation of my statement
I am using Explorer 8 and I have a search bar on the top right thatallows me a choice of search providers Default (google), Bing, Google, Google desktop. When I use the default I get redirected, when I choose bing or the google choice in the drop down I do not get redirected (not yet at least).
I Went to mozilla and updated my firefox to the latest version but I have the same problem. Additionally if I use yahoo search within firefox it also redirects, my avast actually caught a malware when I did this and quarantined it. Do you need any more info? Thanks for your help. |
|
#16
|
||||
|
||||
|
Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
Alternative downloads: - http://majorgeeks.com/GMER_d5198.html - http://www.softpedia.com/get/Interne...ers/GMER.shtml Double click on downloaded .exe file, select Rootkit tab and click the Scan button. When scan is completed, click Save button, and save the results as gmer.log Warning ! Please, do not select the "Show all" checkbox during the scan. Post the log. |
|
#17
|
|||
|
|||
|
gmer log attached
To my untrained eye it seems that the last 2 lines of the log indicate suspicious changes to atapi.sys and redbook.sys files. Here is the log for your expert advice. Thanks
|
|
#18
|
||||
|
||||
|
Your untrained eye seems to be pretty good
![]() It looks like we're dealing here with the newest TDSS rootkit version. Please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2
|
|
#19
|
|||
|
|||
|
systemlook log
here it is. Thanks
|
|
#20
|
||||
|
||||
|
Please download OTM
Code:
:Processes
:Services
:Reg
:Files
C:\WINDOWS\system32\drivers\redbook.sys|C:\WINDOWS\$NtServicePackUninstall$\redbook.sys /replace
C:\WINDOWS\system32\drivers\atapi.sys|C:\WINDOWS\$NtServicePackUninstall$\atapi.sys /replace
C:\WINDOWS\ERDNT\cache\atapi.sys|C:\WINDOWS\$NtServicePackUninstall$\atapi.sys /replace
:Commands
[purity]
[resethosts]
[emptytemp]
[Reboot]
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Google search redirects, possible malware?
|
19 | Virus and Malware Removal | ||
Google search redirects browser. Cannot locate Trojan/Malware? Pls Help
|
20 | Virus and Malware Removal | ||
Google Search Redirects
|
2 | Virus and Malware Removal | ||
Google Search Redirects
|
1 | Virus and Malware Removal | ||
Google redirects search results
|
13 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 02:22 PM.





Google search redirects, possible malware?