Google redirect... again

Status
Not open for further replies.

yinato

Posts: 38   +0
I need help fixing my computer again. The same thing happened to me 6 months ago and I was able to get the problem fixed using this site. I followed the 8 step guide and I've attached the logs. I hope you can help me again.
 
Again?

When/Where were you helped before?

You are running two Antivirus softwares:
Norton and AVG9

I personally don't like either of them, but you need to decide on one or the other, and then uninstall the one you don't want
After uninstalling them you need to run the Removal Tools as well (as both those Antiviruses will not uninstall properly without it)
AVG Remover: http://www.avg.com/filedir/util/support/avgremover_en.exe
Norton Removal Tool: ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool.exe

Note: my preference is free Avira Antivirus: http://www.free-av.com/
If you decide to download and install this one, you will need to do a full scan as well (to pick up the things Norton and AVG missed)

Plus you are best to update Malwarebytes again, and run another quick scan

After that restart, and provide the new HJT and Malwarebytes log
And how its now performing as well

Edit:
Also startup HJT straight away and tick these 4: Then select Fix
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.227 esysprotector2009.microsoft.com
O1 - Hosts: 91.212.127.227 esysprotector2009.com
O1 - Hosts: 91.212.127.227 www.esysprotector2009.com
 
I don't exactly when, but I do know that the first time it happened, I came to this website. anyway, I've uninstalled norton and have run the removal tool. Here are the logs. Also, thanks for the quick response
 
DOH! I forgot to say run IE Reset

Try IE Reset Fixit Tool:

Or manually from here https://www.techspot.com/vb/post682762-2.html
Then restart Internet Explorer and run through the basic settings


-------------


ComboFix Instructions

Please download ComboFix from HERE or HERE to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  1. If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  2. During the download, rename Combofix to Combo-Fix as follows:

    CF_download_FF.gif


    CF_download_rename.gif


  3. It is important you rename Combofix during the download, but not after.
  4. Please do not rename Combofix to other names, but only to the one indicated.
  5. Close any open browsers.
  6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  7. Double click on combo-Fix.exe & follow the prompts.
  8. When finished, it will produce a report for you.
  9. Please attach the Combo-Fix log along with a new HijackThis log for further review. (Note You should Restart first)
**Note: Do not mouse click combo-fix's window while it's running. That may cause it to stall**

If you still cannot get this to run, try booting into Safe Mode, and run it there.

To boot into Safe Mode, tap F8 after BIOS, and just before the Windows logo appears. A list of options will appear, select "Safe Mode."

If this doesn't work either, try the same method (above method), but name Combofix.exe to iexplore.exe instead, or winlogon.exe..
This because It also happens in some cases that malware blocks EVERY process except for what is in its own whitelist, so this whitelist also includes system important processes such as iexplore.exe, explorer.exe, winlogon.exe...


-------------


Also why are you not running SP3 ?
 
IE fixit tool isn't working, and what's SP3? And do I have to run the IE fixit tool before proceeding with combofix?
 
Yes
Yes it is ;) lol :D

IE6 is very old, its so old that its outdated now, meaning really we all updated a long time ago :D

As Windows and IE is not up to date, its no wonder you are infected
Not only that, but if you were given support, then the support member definitely would have stated to update (otherwise it wasn't really good)

We have to do it manually :(

Please start up HijackThis and do a scan only
Place a check (tick) next to the following and then select Fix (making sure that IE6 and all other programs are closed first)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=%s
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Tony Long\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)

O15 - Trusted Zone: http://www.zixx.ca
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab

O23 - Service: Symantec Eraser Service (EraserSvc10823) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
I think I got them all ;)
 
thanks, btw, I DID try to upgrade it previously, but then i got the hal.dll error. Give me a few minutes
 
Yes :)

And definitely Restart if Combofix does not do it for your automatically
After Restart your computer is going to work a hec of a lot better too by the way :)
The HJT scan and log must be done after Restart

BUT, we are not finished yet
 
I must sign off
So here are some steps you need to do anyway ;)

------------------

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.

TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.

------------------

Uninstall Combofix
Start > Run > Combofix /Uninstall > ok
Note: Combofix will look as though its going to scan again (it won't) It will just uninstall

------------------

You may want to update to a more secure Hosts file
There's lots of important info on that here: http://www.mvps.org/winhelp2002/hosts.htm
As it's difficult to see the actual download, here it is: http://www.mvps.org/winhelp2002/hosts.zip
Important! Windows Vista requires special instructions: http://www.mvps.org/winhelp2002/hostsvista.htm

Simply download the hosts.zip file, extract, then run mvps.bat, then restart

[Important Notice - 2K/XP/Vista Users]
In most cases a large HOSTS file (over 135 kb) tends to slow down the machine. This only occurs
in W2000 and XP. Windows 98 and Windows ME are not affected.

To resolve this issue (manually) open the "Services Editor"

Start | Run (type) "services.msc" (no quotes)
Scroll down to "DNS Client", Right-click and select: Properties
Click the drop-down arrow for "Startup type"
Select: Manual, click Apply/Ok and restart.

------------------

Clear system restore points

  • Clear your existing system restore points and establish a new clean restore point:
    • Go to Start > All Programs > Accessories > System Tools > System Restore
    • Select Create a restore point, and Ok it.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.
    This will remove all restore points except the new one you just created.

------------------

Update Java by clicking here: http://java.com/en/download/installed.jsp?detect=jre&try=1
Then download and run JavaRa
This will remove all your old Java stuff (that is not required)

------------------

Restart
Report how everything is running well :)

------------------

If all seems well, I'd suggest updating to SP3 (but it may be best to uninstall AVG and run the removal tool first > then restart > then update :))
SP3: http://www.microsoft.com/windows/products/windowsxp/sp3/default.mspx

------------------

Also update to Internet Explorer 8: http://go.microsoft.com/fwlink/?LinkID=142198
 
heres the combofix and hjt logs, I have to go to a lecture for the next few hours. Also, I've done everything but uninstalled combofix and upgrade to IE8
 
Seems you have installed AVG8 then AVG9 in the last month
Is AVG9 the free version?
If so, as stated above you may want to uninstall it then run the removal tool > then restart. Before updating to SP3

Also you missed a couple of removals in HJT: (just start HJT and fix those 2)
O23 - Service: Symantec Eraser Service (EraserSvc10823) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

You have a file running here: c:\windows\system32\33D654663A.sys
That does not come up with anything known, I suspect it may be Malware
Please locate the file and rename it to: 33D654663A.sysOLD

Then Restart
 
okay, I've removed AVG and reset my computer. I haven't tried searching on google, as I don't have an anti virus right now(downloading avira as I type), but my computer is running quickly. Also, I can't seem to get Sp3


----------------------------

just finished downloading Avira but I keep getting Cannot find server page when I try to download SP3
 
-----------

You may want to update to a more secure Hosts file
There's lots of important info on that here: http://www.mvps.org/winhelp2002/hosts.htm
As it's difficult to see the actual download, here it is: http://www.mvps.org/winhelp2002/hosts.zip
Important! Windows Vista requires special instructions: http://www.mvps.org/winhelp2002/hostsvista.htm

Simply download the hosts.zip file, extract, then run mvps.bat, then restart
That may help
If not then you may need to provide another HJT log
 
I'm currently running a virus scan with avira just to make sure that AVG didn't miss anything. I also already downloaded the host files earlier
 
Okay, I've done everything but upgrade to IE 8 and download SP3, I've attached the HJT log. Do I need to include the Avira virus scan log as well?

----
btw, I want to upgrade IE 8 at the every end if possible since the last time I upgraded my IE browser, i had the hal.dll error
 
Wow...I just tried to use google search engine to see if the problem was fixed, and it isn't, but I did find out when this problem last occurred by typing yinato and combofix... it turns out this exact event happened on november 13 last year:dead:... and I got the virus this year on the 14th
 
There is no Malware in your log
But Symantec (Norton) still persists, plus a couple of others not required

Start up HJT and run a scan only, place a tick next to the following and then select FIX:
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Symantec Eraser Service (EraserSvc10823) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

The following could also be the culprit, but again, they are not Malware as such
I don't believe they need to be running, or even installed
You might want to check Add/Remove programs to uninstall it, and/or FIX them in HJT as well:
O23 - Service: Rogers SHS Service (RogersSelfHelpService) - Rogers Cable Communications - c:\program files\Rogers\SelfHealing\RogersSelfHelpService.exe
O23 - Service: Rogers Update Manager (RogersUpdateManager) - Rogers Cable Communications - C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe

So you did do an updated Avira full scan?
If not then definitely do it, if so (as you already stated) I expect that Avira found something ? to remove, and it did

Restart

What is happening now? You stated you are still being redirected?
Which page exactly is being re-directed? All does look fine at the moment
 
Here's the log that I got from Avira and a HJT log i just got. I updated avira as well. Also, I'm still being redirected while using google. I'm gong to reboot my computer now and repost a new log.
---------------------------
I've noticed that symantec keeps popping up even though I use HJT. I've fixed it 4 times.
 
Status
Not open for further replies.
Back