My Google links keep getting directed

Status
Not open for further replies.

Calinks

Posts: 28   +0
I've ran a bunch of programs but nothing seems to fix this. Here are my logs. My google links still get re-directed. This seems to be a common problem with a lot of people as of late. Thanks for the help!
 
Hello Calinks

That´s odd, both malwarebyte and superantispyware log´s looks clean, and nothing suspicious in hijackthis log.

I´ll therefore suggest we dig deeper ->

Please download http://oldtimer.geekstogo.com/OTViewIt.exe
by OldTimer to your desktop.

Double click on the OTViewIt.exe icon on your desktop.
Check the Scan All Users checkbox and leave Use Whitelist checked. Set the File Age to 30 days.

Click on the Run Scan button. Two reports that are located in the same location as OTViewIt will open.

OTViewIt.txt <-- Will be opened
Extra.txt <-- Will be minimized


Copy and Paste the logs into your next reply.
 
Thank you for the help. Here are the results, I couldn't copy and past them because they were too long so I added them as attachments.
 

Attachments

  • OTViewIt.Txt
    107.8 KB · Views: 7
My bad about the copy and paste line, sorry.


Download The Avenger by Swandog46 from http://swandog46.geekstogo.com/avenger2/download.php.
Unzip/extract it to a folder on your desktop.
Double click on avenger.exe to run The Avenger.
·Click OK.
·Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
·Copy all of the text in the below Quotebox to the clibpboard by highlighting it and then pressing Ctrl+C.



Files to delete:
C:\WINDOWS\System32\wuzapone.dll
C:\WINDOWS\System32\fodevuna.dll
C:\WINDOWS\System32\sasagasu.dll

Folders to delete:
C:\WINDOWS\System32\jerodoyu

In the avenger window, click the Paste Script from Clipboard icon, button.
Click the Execute button.

You will be asked Are you sure you want to execute the current script?.
Click Yes.

You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
Click Yes.

Your PC will now be rebooted.

·Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.


·After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).

Please attach Avenger log. And tell if you still are getting redirected ?
 
Ok I did this. I clicked around for about 10 links and things looked good but then I got redirected. I clicked about 8 more and it happened again so it is still happening but it seems to do so less frequently.
 

Attachments

  • avenger-1.txt
    1.8 KB · Views: 5
Ok. We´ll dig deeper then.

Please download Combofix:
http://subs.geekstogo.com/ComboFix.exe

And save to the desktop.

Close all other browser windows.

Please connect all your external hard drive/flash drive before running Combofix, if you have any


Double-click on the combofix icon found on your desktop.

Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

When finished, it will produce a logfile located at C:\combofix.txt.

Attach the contents of that log in your next reply.
 
I'm trying to drag and drop the pad into the combo fix icon but it wont go in. It just starts up the combo fix program. My icon does not look the same as the one in the gif however. Mine has like a lions head on it or something, kind of like the thunder cats. It's not a circle with a big X in the middle.
 
Ok. Then I suggest you have avenger to remove them -


Files to delete:
c:\windows\000001_.tmp
c:\windows\system32\FBE7215B71.sys
C:\WINDOWS\System32\jerodoyu


As decscribed here:
4 Days Ago 03:56 AM
 
My bad. I should have provided you a proper instruction ->

Download The Avenger by Swandog46 from http://swandog46.geekstogo.com/avenger2/download.php.
Unzip/extract it to a folder on your desktop.
Double click on avenger.exe to run The Avenger.
Click OK.

(if you still have avenger exe on your desktop, there is no need to download avenger again)

Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
Copy all of the text in the below textbox to the clibpboard by highlighting it and then pressing Ctrl+C.
·

Files to delete:
c:\windows\000001_.tmp
c:\windows\system32\FBE7215B71.sys
C:\WINDOWS\System32\jerodoyu

In the avenger window, click the Paste Script from Clipboard icon, button.
Click the Execute button.
You will be asked Are you sure you want to execute the current script?.
Click Yes.

You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
Click Yes.
Your PC will now be rebooted.

Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
·If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.

After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).

Please attach Avenger log.
 
No problem on the lack of instructions, I'm sure with all the post you have to review and everything sometimes things will be forgotten. I appreciate all the help.

Here is my log.
 
You´re right, thank you for understanding :)

I´ll hope, after avenger have removed the files, you don´t are getting redirected more ?
 
I have clicked around for about 5 minutes and although it doesn't seem to be nearly as bad I have been redirected a few times. A could of time I went to a blank page that said Google unidentified or something like that.
 
That´s odd :rolleyes:

Rightclick on hijackthis, and rename it hjt exe.

Please attach fresh hijackthis log.
 
Yea, it's strange though because it does seem better but shouldn't the problem be all or nothing? Maybe there is more than one virus or program doing this? Who knows. Anyway here is the new log.
 
It looks clean. Please update SUPERAntiSpyware, and run a complete systemscan

Then ->

Download http://eric.71.mespages.googlepages.com/LopSD.exe
by Eric_71 and save it to your desktop.
Lop S&D will only run on Windows XP and Windows Vista

Double-click LopSD.exe

Choose the language by typing of the corresponding letter and press Enter
Click OK at the informative window
Type 2 to choose Option 2 (Fix + Hosts), then press Enter
Wait until the end of the scan have finished

A report will be generated, attach the contents of it in your next reply, along with Superantispyware log.
 
"I'm sorry, but we do not support piracy. Due to the fact that your LopSd logfile clearly shows you have at least one known crack/keygen, we will not help you.

This is the main reason your computer is infected. Visiting cracksites/warezsites - and other questionable/illegal sites is always a risk.

Even a single click on the site can drop multiple forms of very serious malware, many of which disable your onboard protection, and System Restore.

When you install the cracked software, you are running executable files from these dubious, unknown sources. You are in effect giving these sources access to information on your hard disk, and potential control over the operation of your computer, and download new infections .
 
I see. So perhaps if I find these files and delete them this problem may be resolved? I hope so. Thank you for everything you had done and thank you for helping me as much as you could. I'm very grateful, you guys do a great service!
 
Status
Not open for further replies.
Back