Redirects & Slow Browsing

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by KaaCee, Aug 16, 2010.

  1. KaaCee

    KaaCee Private E-2

    Hi

    Thanks for a wonderful service here.

    I am having trouble with occasional redirects and pop ups. My browsing seems a little slower than usual. I use Firefox. I don't have much more info than that. I have gone through the procedures outlined on your "Read & Run Me First" page and shall attach the logs.

    I'm not all that tech savvy but feel confident about following your instructions. I have used these forums in the past and received outstanding help and results from you guys.

    Cheers
     

    Attached Files:

  2. KaaCee

    KaaCee Private E-2

    Logs

    Thanks

    KaaCee
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not allow MGTools to run to completion. If it created the C:\MGTools folder, then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Wait till it tells you to hit any key to continue.

    Then attach the below logs:

    * C:\MGlogs.zip
     
  4. KaaCee

    KaaCee Private E-2

    Thanks

    I could not get MGTools to run, it kept giving me error messages. I ran GetLogs.bat to get the file I attached.

    I will rerun MGTools and let you know the exact error messages.

    KaaCee
     
  5. KaaCee

    KaaCee Private E-2

    TimW

    Sorted that out, I must have had antivirus or similar running last time, sorry. Attached is the log.

    KaaCee
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you get redirects using IE?

    Use windows explorer to find and delete:
    C:\Documents and Settings\Karl\Local Settings\Application Data\okwqcjpqc
    C:\Documents and Settings\Karl\Local Settings\Application Data\tughptxvt
    C:\Documents and Settings\Karl\Local Settings\temp\17.dir
    C:\Documents and Settings\Karl\Local Settings\temp\17.tmp

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:

    C:\Documents and Settings\Diane\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?
     
  7. KaaCee

    KaaCee Private E-2

    Still getting redirects. Same goes for IE.

    After reinstalling FireFox I did not need to import bookmarks and all my other customisations were still in place. I had assumed they would have disappeared.

    We have two users and I made sure the documents and settings were deleted for both. And I did reboot between steps.

    Shall retry, see what happens and repost.

    KaaCee
     
  8. KaaCee

    KaaCee Private E-2

    I have gone through the same procedure without success. This time I ensured I checked the FireFox option of removing all user preferences.

    Results from a simple google search keep getting redirected. When I go to a search result the address bar displays http://results5.google.com/ then takes me to a random unhappy place.

    Any ideas?

    KaaCee
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you going through a router? If so, please connect directly to your modem and see if you still get redirected.
     
  10. KaaCee

    KaaCee Private E-2

    Router / modem? What's the difference? I have just the one thing anyway. A wireless router / modem.

    But what I do see when I log in to it is that the DNS server addresses are different than what is on my ISPs web site. Could they have been altered somehow? If I change them will the world end?

    I have noted my existing settings and will change them and see what happens.

    If this is something to do with all the redirects how did it happen and how do I prevent it happening in the future?

    KaaCee
     
  11. KaaCee

    KaaCee Private E-2

    Beautiful. The redirects are solved. After changing the DNS settings in my router everything is working again. My google searches are not being redirected and everything seems to be back to normal.

    Was it that simple?

    KaaCee
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, it was that simple. There is some newer malware that changes your dns settings in your router. In your case, your router/modem. Good that you decided to log into the modem and check your settings. ;)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  13. KaaCee

    KaaCee Private E-2

    Thanks heaps for your help. Everything is going fine.

    All the best

    KaaCee
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds