Malware causing browser redirects

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by 1611guy, Jan 1, 2009.

  1. 1611guy

    1611guy Private E-2

    Problem started Dec. 26, browser redirects, will not go to here or other sources of anti-virus updates, etc. Redirects google/yahoo. Had 'Rapid Antivirus' pop-up saying it was infected and needed to be scanned. Followed 'read and run first', still redirects. Specified logs attached. Thanks.
     

    Attached Files:

    Last edited by a moderator: Jan 1, 2009
  2. 1611guy

    1611guy Private E-2

    Avira antivirus also will not update, 'scheduler not started...' Thanks, again.

    Additional logs:
     

    Attached Files:

    Last edited by a moderator: Jan 1, 2009
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please make sure that in the future you attach logs properly.

    How did you manage to get SUPERAntiSpyware installed with a name like shown below?
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\6409c250-6857-47be-9d71-f3c52f862cb2.exe

    I suggest that you uninstall it now and then reboot and install it properly with it normal default name.

    I also suggest that you uninstall Win Patrol and then see if you still have problems with updating Avira. Also Win Patrol may get in the way of cleaning your PC. If you still have a problem, try shutting down Spyware Terminator and see if you still have a problem. Either way continue on to the below and let's see what happens.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds