Browser hijacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by keiths, Dec 13, 2010.

  1. keiths

    keiths Private E-2

    Hi,

    When clicking any links from Google search results in IE8 I'm redirected to advertising sites.

    Logs attached.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    These were set up by you I assume?

    Disable Teatimer as shown here:

    How to disable Spybot's TeaTimer

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Tell me, or show me with a screenshot, what is inside of the below folder:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running for you now?
     
  3. keiths

    keiths Private E-2

    Hi - thanks for the very fast reply.

    I've followed your instructions and have attached the requested logs.

    TDSSKiller didn't find anything but I'm afraid the browser hijack is still in place.

    Thanks,
    Keith
     

    Attached Files:

  4. keiths

    keiths Private E-2

    Sorry, also meant to say that the host file entries are intentional.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do the redirects occur in safe mode? But... you did not tell me the contents of that folder, could be the culprit I am thinking...
     
  6. keiths

    keiths Private E-2

    Sorry - contents of the folder are:

    0x0409.ini
    1033.mst
    Play Wireless USB Adapter.msi
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay then, contents of that folder was not the culprit then!

    At this point I am going to suggest you uninstall AVG and then run Combofix as per the instructions in the R&R.

    Then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    And I had asked whether the redirects still occur in safe mode?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds