1. welovehockey

    welovehockey Private E-2

    I am trying to get to a website and my web is getting redirected to a different site.
    Example www.whatever.org and it is getting redirected to www.org.com
    Any help or suggestions?
     
  2. bem

    bem Private E-2

    Welcome to the wonderful world of browser hijacking! Nothing like a little of the unexpected to spice up your life...

    Download the new beta for MS Antispyware and give it a run. Go thru a few online scanners for the help they can give.

    http://www.pandasoftware.com/activescan/

    http://house.call.trendmicro.com/

    http://ravantivirus.com/scan/

    If you don't have them, download Adaware SE and Spybot (available here) update and run those.

    If you're still buggy, come on back and post again. Cleanup is step one, makes the HiJack log much easier to read. Good luck.
     
  3. welovehockey

    welovehockey Private E-2

    Have adaware se and Spybot Search and Destroy. Ran both and sytem clean. What next?
     
  4. bem

    bem Private E-2

    What about the ms beta and the online scans?
     
  5. welovehockey

    welovehockey Private E-2

    I am using dial up and it was taking forever...
     
  6. bem

    bem Private E-2

    Doesn't it though? Much less time and trouble to get protected to start with. We all learn together...

    Read and follow all the advice posted at the top of the forum. There are only so many people qualifed to help, and the first thing they need is to know that all the little stuff is done so they can help with the hard part. Help them to help you. After that, get the recommended protections, update regularly, and avoid this hassle in the future.

    Run through it all, if you're still having trouble, come on back.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know you are on dialup and this may take some time but as Bem said, we need to follow some guidelines to get systems into a know state.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  8. welovehockey

    welovehockey Private E-2

    I followed all the instructions and did as the said in the order it said. I am still having the problem. I will run the Hijack and post the results sometime soon.
     
  9. welovehockey

    welovehockey Private E-2

    Attached is my log file
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please go back and read and follow the stickies again! You are supposed to click on and download from our links and make sure you have the correct versions of ALL software. The HijackThis version you have is way out of date. Please use our links!

    It also does not look like you ran the online scans from TrendMicro and Symantec.

    Why are two instances of Getright running when you did this scan. It should be shutdown.
    C:\Program Files\GetRight\getright.exe
    C:\Program Files\GetRight\getright.exe
     
  11. welovehockey

    welovehockey Private E-2

    I fixed the problem. I feel so dumb. The way I fixed the problem was added the site to my Trusted sites and it was fixed.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wrong approach! It should not be necessary to add a site to your Trusted Zone.
    I assume you are talking about in IE?


    Those bad sites you were being hijack to can not be solved that way.

    Post a HJT log from the correct version of HJT as I requested.
     
  13. welovehockey

    welovehockey Private E-2

    attached is an updated log file...
     

    Attached Files:

    Last edited: Jan 12, 2005
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You are using WinXP SP2 which has a built-in firewall which is enabled by default. Did you disable it? The reason I ask is because you also appear to being using a firewall from Symantec. You cannot run more than one software firewall.

    Also the site you added to your trusted zone is http://www.educationalcu.org
    I see no reason that this should need to be added to your trusted zone to get access. You must be blocking something in your firewall. Also if you are going to another site, instead you must have something configure to send you to those sites when an address is unrecognized.

    Have you done a Reset of Web Settings:

    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    After doing the Reset and checking for multiple firewall conflicts and checking to see that you firewall is not blocking the site, remove it from you Trusted Zone in IE and see you can surf to it.
    Tell me what happens.
     
  15. welovehockey

    welovehockey Private E-2

    Ok I did as instructed and that did nothing for the website. I looke and I am running Norton System Works 2004 and seen nothing in there about a firewall. I disabled the one in Windows and nothing. What next?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you remove the address from your trusted zone yet? If not pleases do so.

    Open a command prompt window by click Start, Run and enter cmd and click OK!

    In the command prompt window enter the following commands each followed by the enter key
    ipconfig /flushdns
    exit

    Now open a Windows Explorer (yes Windows Explorer not Internet Explorer) window and enter the following the address bar and hit the enter key (or click Go) :
    www.educationalcu.org

    Does that work?
    Then try the same in IE? What happens?
     
  17. welovehockey

    welovehockey Private E-2

    I did as instructed and in both explores I got the Page could not be displayed after searching for a long time.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange! Now you are not being sent to some other website.
    What website were you redirected to before?

    Have you looked at your Restricted Zones in Internet Explorer to make sure that www.educationalcu.org is not restricted?
     
  19. welovehockey

    welovehockey Private E-2

    it was going to www.org.com or something like that. I looked in the restricted site but didnt see it listed.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and install Mozilla Firefox

    Exit all Internet Explorer sessions and run Firefox. Use it to go to www.educationalcu.org
    What happens?

    Now exit Firefox and run IE. Enter the below into address bar and click Go:
    http:// 208.191.34.194

    What happens?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds