" redirecting browser "

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HK1, Jan 8, 2011.

  1. HK1

    HK1 Private E-2

    Been having this redirection problem for about 2 weeks after I installed Google Chrome! Not to mention I think it's the culprite. After I found out about the Google Analytics virus not cool at all! Anyway , I downloaded Hijack This and made a log ,hope someone could please help to remove this.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. HK1

    HK1 Private E-2

    Thanks for your pquick reply Tim :) I tried to follow the instructions on the run me read me page. Which I got up to the TDSS KILLER part. Up till now nothing has taken away the problem.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. HK1

    HK1 Private E-2

    Yes , I tried doing everything in that thread. And I got up to the part about TDSS KILLER ,but I will try to do the other things your requesting. Sorry ,bare with me i'm not very pc savy lol!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. Take your time. I will be here to view your logs when you are ready.

    One other thing to run while I am thinking of it:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  7. HK1

    HK1 Private E-2

    Okay Tim, here's the data requested. The only one I could not get to run properly was MGTools. Hopefully this will be enough for you I appreciate your time thanks :cool
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.

    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  9. HK1

    HK1 Private E-2

    All ran fine no problems ,is this the info you need thanks?
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall Messenger Plus! Live.

    Now you should have a complete C:\MGLogs.zip to attach.

    Are you running through a router? Have you tried connecting directly to the modem? Does that fix the problem?

    Which browser are you using and does it happen in all browsers?
     
  11. HK1

    HK1 Private E-2

    Okay ,I uninstalled windows plus live. As ,far as the browser problem goes. I originally had it on Google ,when I got tired of it constantly happening. I deleted Google altogether thinking this would solve it ! Guess not lol! Anyway ,I then started to use IE9. Same thing happens much less but still happening. I use a router for my lappy , I never connect directly.
     

    Attached Files:

  12. HK1

    HK1 Private E-2

    By the way Tim. I think I ran all this software on my PC , it may have resolved my problem. So far it's stopped hope it stays that way. The only weird thing that happened is after I deleted Messenger Plus Live. And rebooted my PC , I got these desktop ini icons , and also album art icons on the desktop. Anyway ,what's that all about? Let me know if you need to know anything else thanks mate.
     
  13. HK1

    HK1 Private E-2

    Spoke too soon it's back!!!!!!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Connect directly to your modem and see if the issue continues. If it stops, then you will need to reset your router to factory setting by holding down the recessed button for a few moments. Any special configurations that you had set up in the router will need to be reset.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  15. HK1

    HK1 Private E-2

    Sorry ,I just connected directly and it still continues to redirect.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can't get C:\MGtools\GetLogs.bat to give you a complete set of logs. Let me know if you have error messages.
     
  17. HK1

    HK1 Private E-2

    Made a mistake , I deleted MGTools. Could you resend it to me thanks.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Now run the exe and attach the new log. Make sure you wait until it says it is finished.
     
  19. HK1

    HK1 Private E-2

    Here you go.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the current version of FireFox. Get it here: Mozilla FireFox

    After the install, do you get redirected with FireFox?
     
  21. HK1

    HK1 Private E-2

    Should I uninstall IE9 ,prior to Forefox install?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No need. But you may want to uninstall IE9 and go back to IE8. Just don't import anything from IE to Firefox.
     
  23. HK1

    HK1 Private E-2

    Hey Tim, I reverted back to IE8. Just to see if that would do anything but it didn't. However ,I noticed that the redirecting only is happening when I first reboot the computer. Also ,it happens only once now and then it does'nt do it anymore. And I've noticed also ,that it only does it when I open and click on a certain site. on all others it seems fine by the way it's a clean Dj site. Should'nt have any problems at all so it's weird. I will try the Firefox browser thanks.
     
  24. HK1

    HK1 Private E-2

    I installed Firefox and it's not redirecting which is good. Have to keep testing it to see what happens.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like that one site is giving you the issue. If it is not happening with FF and only on that one site in IE, then as your logs suggest, you are not having a malware issue.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  26. HK1

    HK1 Private E-2

    I might have made a mistake. I already went ahead and just deleted everything off my desktop. Just right clicked everything and deleted ,but I do have files throughout my pc that were left by the software. I did keep the SAS software ,it really cleaned up stuff that my other software did'nt pick up. I already had a full version of MBAM actually. What do I need to do to clean up everything else now sorry ,I just got ahead of myself and thought I was finished with everything and threw it all out.

    I installed ,

    MGTOOLS

    COMBOFIX

    SAS

    MBRCHECK
     
  27. HK1

    HK1 Private E-2

    Took about a day to finally work itself into the new firefox browser. But , it's only with the very same website ,it will open a new page everytime I enter it. What can I do ,please help thanks mate!
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then it sounds like it is an issue with that web site. Not an issue with malware that is redirecting you.

    Did you reinstall those programs that you listed? If so, my final instructions cover what to do to remove them.
     
  29. HK1

    HK1 Private E-2

    Could you please send Combofix once again thanks.
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  31. HK1

    HK1 Private E-2

    I uninstalled it incorrectly the first time. So ,I will install it again to uninstall it correct this time thank you.
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. :)
     
  33. HK1

    HK1 Private E-2

    Tim ,I installed combofix and tried to uninstall it as I said. And it just keeps running the program again. I followed the instructions you sent to uninstall but it's not working.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it is on your desktop and the script doesn't remove it, you can just right click it and delete it. Then you can delete the rest manually as well. If you are still showing hidden files, go to the control panel / folder options and under view, recheck to have system files hidden.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds