Avast WEBforum

Other => Viruses and worms => Topic started by: ruperty on September 14, 2011, 05:17:54 PM

Title: Another Google redirect virus
Post by: ruperty on September 14, 2011, 05:17:54 PM
This time it's to 64.11.199.226, but pretty sure it changes on each one, mostly starting with 64.

I've tried everything. Avast scan, malware bytes, TDSS killer, checked host file, all clean.

Problem is that the redirect is very infrequent, but is annoying all the same.

I've attached OTL file. Assistance would be much appreciated!
Title: Re: Another Google redirect virus
Post by: essexboy on September 14, 2011, 08:02:37 PM
Are these alerts with firefox, IE or both ?

 Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Run OTL
Title: Re: Another Google redirect virus
Post by: ruperty on September 15, 2011, 05:27:02 AM
Hi essexboy. Thanks for your help.

I have no idea whether it's both IE or firefox as it's extremely hard to test. It happens on average once or twice a day, so unless I switch to IE for a week I really wouldn't know. I can start using IE instead from today and see... but I have already tried reinstalling firefox and this has made no difference. Would you like me to use IE instead from today? It might be a while before I can find out, or I can continue with firefox and I can say within a few days if the problem is still there. Such an annoying bug!

Attached logs from after the fix. Thanks again!

Title: Re: Another Google redirect virus
Post by: ruperty on September 15, 2011, 04:24:24 PM
Update. The problem appears to be still here but the symptoms may have changed. Instead of a redirect to 64.XXX.whatever, avast blocks it as going to http:// (empty).

Clicking on the details, I get:
Infection Details
Process:   file://C:\Program Files\Mozilla Firefox\firefox.exe
Infection:   url:Mal
Title: Re: Another Google redirect virus
Post by: essexboy on September 15, 2011, 07:33:25 PM
Lets try and remove that folder again

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Run OTL
Title: Re: Another Google redirect virus
Post by: ruperty on September 16, 2011, 04:39:44 AM
Hi Essexboy.

Done and done. Attached OTL.
Title: Re: Another Google redirect virus
Post by: essexboy on September 16, 2011, 06:04:15 PM
Is it still occuring ?
Title: Re: Another Google redirect virus
Post by: ruperty on September 17, 2011, 07:53:43 AM
I haven't used the computer yesterday but I'm on it over the weekend and I will see. It hasn't happened yet. I will let you know if it occurs again.

Thanks for your help!
Title: Re: Another Google redirect virus
Post by: ruperty on September 18, 2011, 06:06:13 PM
Hi Essexboy,
Damn the virus is still here. I thought it had gone for a bit as I didn't get one the whole weekend, but just got a redirect to 64.111.199.226.

Any ideas?
Title: Re: Another Google redirect virus
Post by: essexboy on September 18, 2011, 11:06:01 PM
OK bigger hammer time

Download and Install Combofix

Download ComboFix from one of the following locations:

Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop *

 IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216")

(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: Another Google redirect virus
Post by: ruperty on September 19, 2011, 07:19:30 AM
Excellent, I like the sound of big hammer time.

Ran the combofix. Got a few messages asking me to run certain things, etc. I clicked yes, agree, etc. to all. Screenshots attached, along with the log at the end.

Before the reboot, combofix closed a whole lot of my windows and this caused some windows errors, asking to send error reports, etc. to which I just selected cancel or close or whatever was appropriate.

Haven't noticed any changes yet other than my windows security centre settings appear to have been changed a bit.

Thanks.
Title: Re: Another Google redirect virus
Post by: ruperty on September 19, 2011, 09:11:05 AM
hmmmm problem is still here. getting the same redirect as before...
Title: Re: Another Google redirect virus
Post by: essexboy on September 19, 2011, 09:02:28 PM
Hmm this is becoming intriguing as at the moment nothing jumps out at me.. 

Is it only firefox ?

Please download GooredFix from one of the locations below and save it to your Desktop

Download Mirror #1
 (http://jpshortstuff.247fixes.com/GooredFix.exe)Download Mirror #2 (http://downloads.securitycadets.com/GooredFix.exe)



Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).[/list]
Title: Re: Another Google redirect virus
Post by: ruperty on September 20, 2011, 01:36:34 AM
hi essexboy,
Unfortunately I'll have to try this another time. I got pulled to work for 4 months and won't be able to use this computer for a while. Hope in that time this redirect doesn't manifest itself into a monster.

Anyway, I'll repost here when I'm back in Feb. Thanks for your help.
Title: Re: Another Google redirect virus
Post by: essexboy on September 20, 2011, 08:32:16 PM
No problem - have a nice trip  ;D