|
|
 |
12-11-2012, 11:14 AM
|
#1
|
|
Lifer
Join Date: Jun 2000
Location: Tupelo
Posts: 15,195
|
Need help removing browser redirect malware/virus.
I've got a single system here at the office that has been compromised with redirect malware. Not sure exactly which one it is, but most of the redirects point to "The Click Check" site. The browser is Firefox and I'm not sure if the problem exists in IE.
So far, I've done the following:
- Scanned with Malwarebytes Anti-Malware and SuperAntiSpyware
- Scanned for virus with AVG and Kaspersky rescue CDs (no virus found)
- Used RKill, Combofix, and TDSSkiller
- Checked all proxy, DNS, etc. settings
- Checked the windows host file for bad entries
Even after all that, the redirects are still occurring. My next step may be to completely remove Firefox, delete the user profile, and reinstall. I don't see any FF add-ons/extensions that could be the cause.
I've had systems loaded with tons of viruses that are easier to clean than this.
Any suggestions?
__________________
Desktop:: 2500K@4.4Ghz, 7870 OC, 16GB RAM, CM690, 120GB SSD, 2.0TB Storage, Win8x64
Server:: A64 3200+, 2GB RAM, 2.25TB, WHS PP3
Laptop:: Macbook Air (2012), 128GB SSD, 8GB RAM
Heatware 154-0-0
Last edited by BlueWeasel; 12-11-2012 at 11:26 AM.
|
|
|
12-11-2012, 11:19 AM
|
#2
|
|
Golden Member
Join Date: May 2011
Location: UK
Posts: 1,955
|
What is the product "Anti-Malware"? I've never heard of it I'm afraid. Try MalwareBytes (free, no trial)?
Confirm whether the redirect occurs with IE, then you know whether your efforts regarding a Firefox-specific problem are completely pointless or not
You could also confirm whether it happens with a different user on the same machine, then you know whether the infection is at the user-level or higher.
Can you take the disk out and scan it connected to another machine externally?
TBH I've tried an AVG Rescue CD (up-to-date of course) several times and it hasn't ever turned up a result.
|
|
|
12-11-2012, 11:27 AM
|
#3
|
|
Lifer
Join Date: Jun 2000
Location: Tupelo
Posts: 15,195
|
Quote:
Originally Posted by mikeymikec
What is the product "Anti-Malware"? I've never heard of it I'm afraid. Try MalwareBytes (free, no trial)?
|
Anti-Malware is one and the same.
__________________
Desktop:: 2500K@4.4Ghz, 7870 OC, 16GB RAM, CM690, 120GB SSD, 2.0TB Storage, Win8x64
Server:: A64 3200+, 2GB RAM, 2.25TB, WHS PP3
Laptop:: Macbook Air (2012), 128GB SSD, 8GB RAM
Heatware 154-0-0
|
|
|
12-12-2012, 05:19 PM
|
#4
|
|
Senior Member
Join Date: Nov 2011
Posts: 258
|
I would suggest to uninstall, then install to a different directory.
|
|
|
12-12-2012, 06:34 PM
|
#5
|
|
Junior Member
Join Date: Dec 2012
Location: USA
Posts: 8
|
I'm not sure of the rules for posting links to routines or other websites so I won't do that for now but basically there are a few sites that provide dedicated malware detection and removal. Malwarebytes is one of them, there is also Bleepingcomputer and TechSupportForum
These sites have trained members that can help you to clean your system.
|
|
|
12-13-2012, 06:55 PM
|
#6
|
|
Golden Member
Join Date: Jul 2001
Location: TN
Posts: 1,687
|
OP,
Looks like you ran almost all the correct av programs.
1. Did you try a System Restore?
2. Did you boot into Safe Mode with Networking and run Rkill first before running any AV program? After each reboot Rkill must be run again.
3. Did you try running Task Manager (Ctrl-Alt-Del) and check under processes for anything suspicious like Click Check running? If you find something suspicious running End the process.
After running Rkill, run TDSSkiller, then MBAM, then HitmanPro, then Combofix. Then run HijackThis and post the log here or copy and paste the log here http://www.hijackthis.de/ and click on Analyze.
If all this does not work you can try manually removing Click Check. Do a search of your local drives for Click Check and delete any files it finds. Run Ccleaner. Backup your registry file. Open your registry file, regedit.exe, under Edit, Find, type in Click Check, Find Next, right click on entries, Delete, hit F3, and repeat until all Click Check entries are deleted.
__________________
Asrock Z68 Extreme 4, i5-2500K @4.6 Ghz, 1.340V, Lian Li PC-7A Plus, Corsair A70, Corsair Force Series 3 120GB SSD, Samsung Spinpoint HD103SJ 1TB, 16GB Kingston HyperX DDR3 1600 @1.575V,Seasonic M12II 620W PSU, MSI GeForce GTX 650 Ti, Samsung SH-S223B, Win 7 Ultimate 64bit
|
|
|
12-14-2012, 05:19 AM
|
#8
|
|
Junior Member
Join Date: Dec 2012
Location: USA
Posts: 8
|
Indiscriminately running anti-malware and antivirus tools can actually make it more difficult to clean the computer from an infection. There are also infections that running the wrong tool will almost guarantee that without a lot more work you'll end up needing to format the drive and reinstall Windows.
In most cases these items are simply JavaScript or XML redirect tricks and AdwCleaner or JunkRemovalTool can clear them up.
However sometimes when these redirects have been on the system for a while sooner or later you'll hit some site with a drive-by and end up with a real infection.
You should NEVER use a temporary file cleaner until you've ascertained which infection you have. Doing so will cause you to lose data that cannot easily be recovered.
Don't forget you should also have an external backup of all important data. Hardware failure can potentially cause more harm than a serious infection if you end up losing all your data.
|
|
|
12-14-2012, 11:02 AM
|
#9
|
|
Golden Member
Join Date: Jul 2001
Location: TN
Posts: 1,687
|
Quote:
Originally Posted by AdvancedSetup
Indiscriminately running anti-malware and antivirus tools can actually make it more difficult to clean the computer from an infection. There are also infections that running the wrong tool will almost guarantee that without a lot more work you'll end up needing to format the drive and reinstall Windows.
In most cases these items are simply JavaScript or XML redirect tricks and AdwCleaner or JunkRemovalTool can clear them up.
However sometimes when these redirects have been on the system for a while sooner or later you'll hit some site with a drive-by and end up with a real infection.
You should NEVER use a temporary file cleaner until you've ascertained which infection you have. Doing so will cause you to lose data that cannot easily be recovered.
Don't forget you should also have an external backup of all important data. Hardware failure can potentially cause more harm than a serious infection if you end up losing all your data.
|
I do not agree with your first statement. I have never had an AV/AM program itself do harm to a computer. It’s the fallout damage from the viruses they remove that’s a PITA; i.e., no Startup Program or desktop shortcuts, empty Administrative Tools folders, cannot turn the Windows Firewall on, or no internet access.
I have never had any data loss after using Ccleaner as a temp file cleaner. I do recommend to run Ccleaner last if you have a virus. Some viruses when removed will delete your shortcuts. Before running Ccleaner check your shortcuts. Running Ccleaner deletes the %Temp%\smtmp folder making it harder to restore the shortcuts.
The Click Check virus may or may not be a simple browser hijacker. I have used AdwCleaner before. It will clean out some adware and leftover toolbar files, but it will also delete your browser homepage. I have not used it on a browser hijacker virus.
__________________
Asrock Z68 Extreme 4, i5-2500K @4.6 Ghz, 1.340V, Lian Li PC-7A Plus, Corsair A70, Corsair Force Series 3 120GB SSD, Samsung Spinpoint HD103SJ 1TB, 16GB Kingston HyperX DDR3 1600 @1.575V,Seasonic M12II 620W PSU, MSI GeForce GTX 650 Ti, Samsung SH-S223B, Win 7 Ultimate 64bit
|
|
|
12-14-2012, 09:22 PM
|
#10
|
|
Junior Member
Join Date: Dec 2012
Location: USA
Posts: 8
|
No problem. Everyone is welcome to their own opinions. I'm not here to argue with or upset anyone over it.
Groups authorized to help with HJT logs
|
|
|
12-16-2012, 09:34 AM
|
#11
|
|
Golden Member
Join Date: Jul 2001
Location: TN
Posts: 1,687
|
Quote:
Originally Posted by AdvancedSetup
|
That's what a tech forum is all about, an exchange of experiences, opinions, and knowledge.
__________________
Asrock Z68 Extreme 4, i5-2500K @4.6 Ghz, 1.340V, Lian Li PC-7A Plus, Corsair A70, Corsair Force Series 3 120GB SSD, Samsung Spinpoint HD103SJ 1TB, 16GB Kingston HyperX DDR3 1600 @1.575V,Seasonic M12II 620W PSU, MSI GeForce GTX 650 Ti, Samsung SH-S223B, Win 7 Ultimate 64bit
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 11:27 AM.
|