MajorGeeks Support Forums

MajorGeeks Support Forums (http://forums.majorgeeks.com/index.php)
-   Malware Removal (http://forums.majorgeeks.com/forumdisplay.php?f=35)
-   -   Browser Redirect and slow performance - (http://forums.majorgeeks.com/showthread.php?t=282076)

Davidmems 12-10-13 05:06

Browser Redirect and slow performance -
 
4 Attachment(s)
I've been having trouble with my browser being redirected, but it does not happen all the time. I am using Chrome on a 32-bit Windows 7 OS.

I followed all the instructions in the guide for fixing redirects and they did not solve my problem. I've also followed the Malware Removal/Cleaning Procedures (downloaded the 5 tools and ran the scans for Windows 7) and have attached all logs.

Any help would be VERY much appreciated.

Davidmems

Kestrel13! 12-10-13 05:14

Re: Browser Redirect and slow performance -
 
Hi there and welcome. :)

Are you purposely set up to use a proxy?

Davidmems 12-12-13 08:28

Re: Browser Redirect and slow performance -
 
Thanks Kestrel13! I don't think I am set up now.

Kestrel13! 12-12-13 15:16

Re: Browser Redirect and slow performance -
 
Hi. :)

Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

Uninstall >>> Browser Manager


Re run Hitman and have it delete all of the Malware and Potential Unwanted Programs.


http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
When it opens, press the Scan button
Now click the Registry tab and locate these 3 detections:
  • [SERVICE][BLVALUE] HKLM\[...]\CCSet\[...]\Services : IBUpdaterService ("C:\ProgramData\IBUpdaterService\ibsvc.exe" /SERVICE [x]) -> FOUND
  • [SERVICE][BLVALUE] HKLM\[...]\CS001\[...]\Services : IBUpdaterService ("C:\ProgramData\IBUpdaterService\ibsvc.exe" /SERVICE [x]) -> FOUND
  • [SERVICE][BLVALUE] HKLM\[...]\CS002\[...]\Services : IBUpdaterService ("C:\ProgramData\IBUpdaterService\ibsvc.exe" /SERVICE [x]) -> FOUND
  • [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (72.64.146.136:8080 [Country: UNITED STATES (US), City: Reston, VA]) -> FOUND
Place a checkmark each of these items, leave the others unchecked.
Now press the Delete button.
When it is finished, there will be a log on your desktop called: RKreport[2].txt
Attach RKreport[2].txt to your next message. (How to attach)
Reboot the machine.



Please re run Malware Bytes and attach the log.


Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

Quote:

REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]

Make sure that you tell me if you receive a success message about adding the above
to the registry. If you do not get a success message, it definitely did not work.


Delete this if it shows:

C:\ProgramData\IBUpdaterService


Is your browser still redirecting now? :confused If so I have a easy fix hopefully. We just had to 'de crapify' first.


All times are GMT -5. The time now is 21:44.

Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger