![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi there,
I first noticed this in Firefox, but then it also happens in IE. whenever I do a search in either google or yahoo I get redirected to a weird site (but it only happens some of the time...some times I get to the real site, and whenever I do get the weird webpage, I just back out of it and click on the same link and I get to the page i'm supposed to get to). I attached the gooredfix.txt file to this. Hopefully someone can help out and let me know how to fix it. I originally downloaded Adware by Lavasoft, Housecall by Treadmicro, and CW Shredder as well as Malwarebytes. And while some of them found stuff, I still had the redirect problem. Then I purchased and downloaded Webroot Secure Anywhere (because of the high marks it was given by PC magazine) and that didn't find anything...so I ended up here and found the thread about using gooredfix.txt. Thanks |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
Follow the instructions in the below thread. Make sure that you complete all steps as indicated if still having problems. And if and when you get to step 5, make sure you do everything in step 5 including the READ & RUN ME FIRST Fixing Google Redirection/hijacking and other redirection problems
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
So I followed that link and did all the steps (flushed the java cache, the firefox and IE caches, and the dns cache) and have included the Kaspersky TDSSKiller report because the problem persists (the browser redirect).
Thanks, in advance, for helping! |
|
#4
|
|||
|
|||
|
Also - I noticed that it said to see if the redirect problem persisted, so I did and the problem persisted - so I went on to step five and have attached the MBRCheck thing to this post.
Thanks! |
|
#5
|
||||
|
||||
|
Quote:
Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Oops - sorry, I did that too, I just thought the reports that I put below were all you needed at this point. Attached are the reports from the malware removal attempt.
I have the SuperAnti Spyware log, the Malwarebytes log, the combofix, and the MGlog. I am running vista on a 64-bit so I didn't do the RRlog. I'm still having the browser redirect problem. Let me know if you need to know which sites its redirecting to... Thanks in advance! Last edited by meshaq2000; 04-08-12 at 13:06.. Reason: adding what my current problem is |
|
#7
|
||||
|
||||
|
Your MBRcheck log shows a possible infection
Code:
Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: E6CCDBFD8F5B3DAA80CE1AA64C67955A606A347D
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#8
|
|||
|
|||
|
So, of course, I've searched everywhere and I can't find my windows vista boot disk anywhere. I did find an old windows XP professional (version 2002) from a pc that died a long time ago. Could I use that or should I buy or try to find a replacement for windows vista?
|
|
#9
|
||||
|
||||
|
Quote:
Let's see if we can get lucky and use the below. Sometimes it will work but more frequently, it can not fix newer forms of MBR infections.
Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
I think i'm reading that it still lists an unknown MBR code...
I've attached the MBRfix as well as the MBR check. |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Quote:
Please download aswMBR to your desktop.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
I ran the aswMBR scan and have attached the log.
|
|
#13
|
|||
|
|||
|
And then I did the rest of it and here's the second scan log.
|
|
#14
|
||||
|
||||
|
Quote:
Quote:
Also let me know if you are still having any problems.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 04-12-12 at 19:06.. |
|
#15
|
|||
|
|||
|
I ran MBRcheck again - and here's the log
|
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Also - I'm still getting the browser redirect.
|
|
#17
|
||||
|
||||
|
Hmmm! The log from MBRcheck still indicates an unknown MBR code. This would seem to indicate that aswMBR really did not fix your MBR. Possibly because the infection in the MBR itself is actively blocking it.
You need a boot CD to avoid having the infected MBR getting loaded. You need to fix a Vista boot DVD. You could borrow a friends temporarily just for the fix. Or another possible option may be to try what was posted in message # 12 of the below thread and see if you can get this CD to run. whistler/black internet@mbr again!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#18
|
|||
|
|||
|
I'm glad you guys have solutions for morons like myself who somehow lose their boot cd. I downloaded Hiren's Boot CD to a clean pc, burned it to disc and followed all the instructions from there.
Then I ran another MBR check and have uploaded it. It has a different thing on it this time, so hopefully that means it's fixed...but, of course I wouldn't be here if I knew how to read it myself... |
|
#19
|
||||
|
||||
|
Quote:
How are things running? Are you still having redirects? If so, is it only with Firefox?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#20
|
|||
|
|||
|
Hi there,
So it appears that IE doesn't redirect any search links (I clicked on more than 20 and no redirect)...but it happens still in Firefox. What should I do about that? |
| Sponsored links |
|
|
![]() |
| Tags |
| gooredfix, gooredfix.txt |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Tojan/Rootkit/Browser redirection problems | bryars308 | Malware Removal | 4 | 05-26-11 14:15 |
| Fixing Google Redirection/hijacking and other redirection problems | chaslang | Malware Removal | 0 | 01-02-11 14:33 |
| BROWSER redirection, STRANGE POP UPS | oceanbeachJP | Malware Removal | 8 | 08-10-10 23:39 |
| Browser Redirection Virus | Transference | Malware Removal | 8 | 07-19-10 23:37 |
| Browser Redirection Problem | timestone2000 | Malware Removal | 3 | 03-12-09 14:13 |