IE redirection via adware part 1

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aloysius7234, Oct 12, 2010.

  1. aloysius7234

    aloysius7234 Private E-2

    Hello,
    My ms internet explorer has 2 problems.
    -When I open it up and choose a site a second window is opened with some adware site.
    -Any search I do comes back with the correct results. When I click on the result I am directed to some adware site with their search results.

    I have followed the procedures in "read me first" and "Windows XP cleaning procedures". I am still having the same precedure. This bug seems to have infected 2 of my computers.

    The log files are attached in part 1 & 2 of this thread. I had to split combo log into 3 files since it was over the text file limit in size.

    Thanks
    Rick
     

    Attached Files:

  2. aloysius7234

    aloysius7234 Private E-2

    IE redirection via adware part 2

    here are the combo file logs part 1-3

    here's an example of a search redirect when I searched on Major Geeks and clicked on the result google gave me:
    *removed malicious link*

    Thanks
    Rick
     

    Attached Files:

    Last edited by a moderator: Oct 13, 2010
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    And in the meantime I shall review your other logs.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also, AFTER running TDSSKiller please complete the below few steps:

    If you did not deliberately set this proxy up yourself then please include it to be fixed with HJT:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Use Windows Explorer to find and delete the below:
    • c:\windows\Vpevokaxuwenanoj.bin

    Now run this:
    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    (If you have a second computer which is infected then you will need to create a whole new thread for that here in the malware removal forum, as it would be best not to add to this thread with logs from another PC)
     
  5. aloysius7234

    aloysius7234 Private E-2

    It looks like you fixed the problem (pardon me while I sing a verse of the Halleluiah choir ). All is well for now however I am attaching the requesting log files just in case.
    Rick
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget this part:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds