Question

Google results are redirected to random ad sites

Asked by: seduku

Since a recent virus/malware infection google searches are redirects to random ad sites.

Additionally, most programs (including most anti virus products) get the following error message
"Windows cannot access the specified device, path, or file.  You may not have the appropriate permissions to access the item."

I have scanned with Windows Defender and SUPERAntiSpyware but annd it gets a clean bill!!! yet problem persists.  I am unable to run Hijackthis. It quits in middle of scan.

I have Windows Vista on this machine.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-17 at 20:11:40ID24742193
Tags

Vista Google Search redirected

Topics

Operating Systems Network Security

,

Anti-Spyware

Participating Experts
7
Points
500
Comments
34

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. wareout infection on Vista
    I have a wareout infection on Vista. Fixwareout.exe will not run on Vista. HijackThis and Malwarebytes' Anti-Malware will not run. Help!
  2. Malware Doctor Infection
    Hi all, A friend of mine has a Sony Vaio he uses for his Topography and he got it infected with Malware Doctor last week. Apparently he wanted to install some defragging app and NOD32 was stopping him from doing so (and for good reason). So he disabled the antivirus and insta...
  3. Vista Home Box - suspected malware infection
    Vista Home Edition HP computer - extremely sluggish, blcoked access to some files, unable to run Norton AV software in normal mode - suspected malware infection after user clicked on link in phony e-mail from Facebook. Have tried running Malware Bytes in safe mode - indicate...
  4. HijackThis
    Hello, Wondered if anyone can help I have a machine that is having a lot of problems. I think it's been hit by a virus but I am having a nightmare cleaning it up. I have run Hijack this and it seems to have found a few problems however, when I fix and then run a gain it just...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: JeremySBrownPosted on 2009-09-17 at 20:16:46ID: 25362732

Run a temporary file remover...CCleaner is a good one and it's free.
http://www.ccleaner.com/

Download Combofix by sUBs.
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Before running Combofix, temporary disable any firewall(s) shield(s) ect...to prevent any conflicts with Combofix. After Combofix is done scanning, it will create a log, for futher instructions, save and paste the results by Attach File, or by Code Snippet so other experts and myself can take a look at it. Once after the log looks clean, you may enable your firewall(s) shield(s) ect. Combofix will disconnect your machine from the Internet. Your Internet connection will be automatically restored just before Combofix completes its scan. If Combofix runs into problems, your Internet connection can be manually restored by restarting your machine.

You'll might need to rename the file before saving to your desktop so it will not be blocked.

Please note: Don't run Combofix in Safe Mode.

Try scanning with Malwarebytes' Anti-Malware.
http://www.malwarebytes.org/mbam.php

 

by: PriceDPosted on 2009-09-17 at 20:33:48ID: 25362785

If you are still being redirected to radom sites.  Do the following:

go to trendmicro go to feetools and download the Rootkit buster, removed the rootkits.  http://free.antivirus.com/rootkit-buster/  You will love this little app.

After the reboot, use Malwarebytes to remove the other infected files. www.malwarebytes.org/mbam.php

Also, you can check the host file, which is found in C:\windows\system32\drivers\etc, open the file called host and you will most like see a bunch os entries.  All that should be in this file is below, not if you try to save the file and can't just remove the read on attribute and if you can't see if, check the show hidden files under tools.:
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

127.0.0.1       localhost

 

by: rpggamergirlPosted on 2009-09-17 at 22:02:35ID: 25363016


If a renamed Combofix as already suggested still won't run, redownload and rename Combofix to CF.bat prior to saving the file to your desktop.
Make sure the 'Save as Type:' is "All Files"



If the tools still won't run, run win32diag.exe and show us the resulting log. This diagnostic tool can tell us if a patched file is the culprit that blocked the tools from running.

Please download this tool and run it.
http://ad13.geekstogo.com/Win32kDiag.exe

Double-click on Win32Diag.exe to run it. Since you are using Windows Vista, please right-click and select Run As Administrator
A black command prompt window shall appear.
It will now begin to scan. This may take a while, please be paitent until the scan is complete.
Once it's done, in the black screen it will say "Finished! Press any key to exit....
A log file called Win32KDiag.txt will be created on your desktop.
Please copy and paste the contents of that log file here in your next reply please.


 

by: younghvPosted on 2009-09-18 at 05:50:10ID: 25365361

pankusareen,
Please take the time to read the suggestions that have already been posted.
It is extremely rude to duplicate the efforts of the other Experts.

 

by: sedukuPosted on 2009-09-18 at 06:25:55ID: 25365652

Here's some results from earlier suggestions:

ccleaner doesn't run, even after rename
rootkit-buster crashes in mid-scan
hosts file is fine
Win32kDiag.exe starts with error and never fully opens up (ran as admin)
Malwarebytes' scans die after 3 seconds
Hijack this doesn't run

i have attached a SREngLog

 

by: pankusareenPosted on 2009-09-18 at 06:40:50ID: 25365810

U can also try to restore the computer to earlier working point
Go to start->Accessories->system tools->System restore
Choose a good working point and restore ur pc

Post result

 

by: pankusareenPosted on 2009-09-18 at 06:43:07ID: 25365834

And also flush the DNS cache
Go to run->cmd->ipconfig /flushdns

 

by: jcutechPosted on 2009-09-18 at 07:18:44ID: 25366207

Turn Off System Restore, uninstall combofix and malwarebytes anti-malware if you've tried running them, some viruses will disable them so you can't run them again, so uninstall them for now.

Run Sophos Anti-RootKit
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

install combofix and run it

install malwarebytes anti-malware and run it

then you should be good.

 

by: jcutechPosted on 2009-09-18 at 07:20:34ID: 25366229

everytime i run into something where malwarebytes, hijack this and combofix won't run ... sophos anti-rootkit resolves it to the point where the other tools will run.  sophos is free, but you have to make an account on their website.

 

by: sedukuPosted on 2009-09-19 at 09:47:44ID: 25373627

I did not have restore enabled.
Sophos Anti-RootKit stops as soon as it starts to scan
Tried installing Kasperskis, but after a required reboot it is knocked out

 

by: sedukuPosted on 2009-09-19 at 09:51:32ID: 25373640

Appreciate all the advise so far. I have tried all of them and nothing seems be be able to work. Cureit scans finish but they do not find any viruses. Any of the experts have an opinion on the log I attached?

 

by: optomaPosted on 2009-09-19 at 10:08:07ID: 25373698

You could try Kaspersky live bootable cd to scan your system. May help if it detects anything. If it does you may be able to run previous suggestions.
Kaspersky live cd http://devbuilds.kaspersky-labs.com/devbuilds/RescueDisk/

 

by: rpggamergirlPosted on 2009-09-20 at 03:01:45ID: 25376507

You're able to run Sreng so not all .exes are blocked?
Did CF.bat able to run or not? You need to rename it prior to saving the file. If it won't run redownload it again and rename to svchost.exe or winlogon.exe

If it still won't run try this one, maybe this isn't blocked.
Download OTL to your desktop.
http://oldtimer.geekstogo.com/OTL.exe

Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.




Also check if Gmer and Rootrepeal are able to run.(Rename to svchost.exe if it won't run at first go)
Download RootRepeal from the following location and save it to your desktop.
Zip Mirrors: (Recommended)
http://rootrepeal.googlepages.com/RootRepeal.zip
http://ad13.geekstogo.com/RootRepeal.zip

Rar Mirror:
http://ad13.geekstogo.com/RootRepeal.rar

Extract RootRepeal.exe from the archive.
Open RootRepeal on your desktop.
Click the "Report" tab.
Click the "Scan" button.
Check all seven boxes:

o Drivers
o Files
o Processes
o SSDT
o Stealth Objects
o Hidden Services
o Shadow SSDT

Push Yes
Check the box for your main system drive (Usually C:), and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the "Save Report" button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.




Download the GMER Rootkit Scanner. Unzip it to your Desktop.
http://www.gmer.net/gmer.zip

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Click NO
In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity.
Click OK.
GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
Save it where you can easily find it, such as your desktop.

 

by: pankusareenPosted on 2009-09-20 at 04:11:51ID: 25376710

If nothing works go for a fresh clean reinstall.
Did u try the restore feature of windows?

 

by: younghvPosted on 2009-09-20 at 04:12:18ID: 25376712

jcutech - please read through the advice that has already been posted. There is no need for you to be posting suggestions that have already been made.

 

by: sedukuPosted on 2009-09-20 at 14:35:07ID: 25379080

Kaspersky bootable cd scan stuck on 44% after 12 hours of scanning. Really slowed down when scanning the .eml mail files. This is second day in a row it gets slowed down on eml fiels. Still scanning. Don't think it should take 12 hours to complete 44% of the scanning...

 

by: JeremySBrownPosted on 2009-09-20 at 14:56:39ID: 25379172

Do you have a backup image of your system available for you to restore to? I'm NOT talking about system restore, I'm talking about an actual backup image, example like Acronis True Image or Norton Ghost?

 

by: optomaPosted on 2009-09-20 at 15:02:50ID: 25379203

If its still scanning let it it keep going.

You say that its the second day in a row it slows down on .eml files.
Did you try kaspersky cd already and got stuck or scan was aborted?

 

by: rpggamergirlPosted on 2009-09-20 at 15:26:08ID: 25379280

seduku,

Did the OTL run?
There are many nasties that have the same symptoms e.g. google results redirect, programs are blocked, or .exe blocked. Once we know what we're dealing with or if we can manage one of the scanners to run then it should be easily removed.

To rule out one particular variant, check in the system32 folder if this file is present --> logevent.dll
make sure hidden files and folders are shown, or if using Search make sure it is configured to look for hidden files and folders.

 

by: sedukuPosted on 2009-09-20 at 15:26:37ID: 25379283

JeremySBrown: no I only have the lenovo restore CD. I don't have a back up image

 

by: sedukuPosted on 2009-09-20 at 16:48:06ID: 25379522

rpggamergirl didn't find  logevent.dll in system32.
Yesterday I ran kaspersky boot CD but aborted it myself after 8 hours of scan. However, it did manage to find the following Trojans....
hfik.exe
bojitevi.del
towarume.del

kaspersky deleted all three, but after a reboot problem persisted.

 

by: rpggamergirlPosted on 2009-09-20 at 16:52:57ID: 25379542

Please try running OTL and see if it runs... have you also tried redownloading and renaming Combofix prior to saving its file?

 

by: sedukuPosted on 2009-09-20 at 17:29:10ID: 25379647

I redownloaded and renamed combofix a long time ago and it did not work. I have not tried OLT yet and will do that as soon as Ksperski is done scanning. Amazinglu it is still at 44% after 15 hours... running very slow!

 

by: rpggamergirlPosted on 2009-09-20 at 18:56:07ID: 25379851

<<<"I redownloaded and renamed combofix a long time ago and it did not work">>>

You mean you already have the Combofix file there in that pc before the problem started?
It needs to be renamed before the file is in contact with the infected system...
Renaming the file once it's already in the system will not work if braviax, TDSS and other nasties that monitor the presence of any security programs, hence it has to be renamed before saving the file, before it is in contact with the system.

 

by: sedukuPosted on 2009-09-20 at 20:19:48ID: 25380102

Yes they were renamed right as the download began so once it saved to my hard drive it was called something different. I will try it again just for good measure.

 

by: sedukuPosted on 2009-09-21 at 06:17:33ID: 25382503

Renaming combofix prior to download didn't fix it
OLT quits moments after starting it
gmer blue screens
RootRepeal doesn't run
is the SREngLOG.log file I attached in the thread of any help?

 

by: sedukuPosted on 2009-09-21 at 06:19:13ID: 25382514

I aborted Kaspersky boot CD-after 26 hours it was still stuck on 44%.

 

by: JeremySBrownPosted on 2009-09-21 at 06:40:32ID: 25382706

At this stage, you might want to backup all of your information you want to save and reload Windows with your restore CD that you have. Let's wait and see if any other experts have a solution for you to try before you do that, of course this would be the last resort.

 

by: jcutechPosted on 2009-09-21 at 08:57:39ID: 25384290

younghv -- i did read through the other posted advice, and no one suggested sophos anti-rootkit

 

by: optomaPosted on 2009-09-21 at 12:25:12ID: 25386588

Seduku,
It's unfortunate that Kaspersky frooze on those .eml files. If you want you could re-run the scanner and exclude those files form the scan, just to see if anything will be detected after them.

Also, you said that the machine blue screened when you tried to run gmer. It would be no harm to look at that minidump file: located at C\Windows\Minidump.
To upload the dump file rename it from .dmp to .txt

 

by: rpggamergirlPosted on 2009-09-21 at 23:52:47ID: 25390143

Still no luck huh?

Did you try fixing the .exe file associations using SREng? not that it will make any difference if the malware is active it will mess it up again.

In SREng, Boot Items > Registry > can you see what's the data under these values "load" and "run", just curious if it's empty or hidden.
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
   <load><>  [N/A]
   <run><>  [N/A]

You can also delete the "Win32Update" service/Driver, the file is already missing.
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
   <Win32Update><C:\Users\ItsMe\AppData\Local\Temp\216.exe>  [File is missing]

I'm not familiar with SREng.
The log showed so many entries like the one below which I find suspicious.... very similar to a new infection that patched system file which usually shows up in Gmer, RootRepeal and Win32Diag.exe.

[\\?\globalroot\Device\__max++>\80E9F39B.x86.dll]  [N/A, ]



Also try renaming the RootRepeal to svchost.exe(not any other generic name).. or svchost.com
Also changing Combofix extension to a .com instead.

Do the same thing with OTL change it to OTL.com


Since some executables are able run hoepfully we'll find a program it doesn't target and will be able to help.

Download avz4.zip from here http://z-oleg.com/avz4.zip
Unzip it to your desktop to a folder named avz4

1. Double click on AVZ.exe to run it.
2. Run an update by clicking the Auto Update button on the Right of the Log window:  
3. Click Start to begin the update

Note: If you receive an error message, chose a different source, then click Start again

After the update,
4. from the "File" menu, choose "Standard Scripts"
5. Put a check next to item 2: Advanced System Analysis
6. Click "Execute selected scripts"
7. At the next prompt, click the Yes button

8. Let the scan run and click "OK" when the completion prompt pops up
9. Now Close out of the Standard Scripts window, and exit AVZ
10. Navigate to the avz4 folder and locate the folder LOG

Inside the LOG folder you will find virusinfo_syscheck.htm, virusinfo_syscheck.xml and virusinfo_syscheck.zip
Attach the Compressed file, virusinfo_syscheck.zip, to your next reply.


 

by: sedukuPosted on 2009-09-22 at 05:09:34ID: 25391813

optoma: trying your suggestion and it seemes to have made it past 44%. this morning it is at 46% and seems to be scanning files without being stuck. Keeing fingers crosses it will be done by the time I get home today.

rpggamergirl: I will try your suggestions this evening hopefully...

 

by: sedukuPosted on 2009-09-22 at 17:36:02ID: 25399075

***NEWS***
Kasperski had muddled it's way to 82% (after 18 hours of scanning) and had detected and deleted several nasties that were preventing the detection tools from running. After a reboot, scanners are running for the first time. Running Malwarebytes and a few others, system getting healtier with every scan. sincere thanks for all the suggestions!!!

 

by: optomaPosted on 2009-09-22 at 22:20:11ID: 25400193

Good to know!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...