being redirected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jagdryan, Jun 20, 2011.

Thread Status:
Not open for further replies.
  1. jagdryan

    jagdryan Private E-2

    hey i keep getting redirected i have use a program called hijackthis i will post log.



    plz tell me how to stop it from redirected me to diffent sites and slowing down the pc
     
    Last edited by a moderator: Jun 20, 2011
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. jagdryan

    jagdryan Private E-2

    TDSSkiller does not even run it just sits there and does nothin i click on it 2 times and nothin i even renamed it and still nothin any ideals ? and IEXPLORE.EXE keeps trying to run but no ideal why.. i used atf cleaner and it's done.. i use firefox not iexplore.. and still being redirected
     
    Last edited: Jun 20, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running it in safe mode. If still no luck, do the rest of the scanning in the R&R instructions. Possibly once SAS and MBAM have run, TDSSKiller may run then. But I need to see the following logs:
    SAS
    MBAM
    RootRepeal
    ComboFIx
    C:\MGLogs.zip -- from running C:\MGTools.exe
     
  5. jagdryan

    jagdryan Private E-2

    can u post links for those tools
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I did in post #2.
     
  7. jagdryan

    jagdryan Private E-2

    great this redirecting put a new program on computer Oo called butdefender and use some like info|1|.exe some thing that fire wall stoped exe from running but not the program
     
  8. jagdryan

    jagdryan Private E-2

    i mean bitdefender still haveing the redirecting problem.. running mgtools atm
     
  9. jagdryan

    jagdryan Private E-2

  10. jagdryan

    jagdryan Private E-2

    sorry for all the post but theres the redirecting problem and the svchost.exe i used to have 4 now i h vae 8 and some reson my cpu is at 100% it is 1 of the svchost.exe network service is running at like 100% and disableing it makes the computer shutdown says like time before shit down 40 secs LOL plz help reallying wanan stop this wana go back to playing my games
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't run either SAS or MBAM. Please do so and attach those logs to your next reply.

    You are also running ComboFix from the wrong location, it needs to be directly on your desktop, not here:
    Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Application Data\25485092
    C:\Documents and Settings\All Users\Application Data\~25485092
    C:\Documents and Settings\All Users\Application Data\~25485092r
    C:\Documents and Settings\All Users\Application Data\g2j3um277pw4oe71uk64
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
    • SAS Log
    • MBAM Log

    Make sure you tell me how things are working now!
     
  12. jagdryan

    jagdryan Private E-2

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Was there a reason you ran the scans in safe mode? Are you still being redirected? What issues are you still having, if any?
     
  14. jagdryan

    jagdryan Private E-2

    yes being redirected still and was still being redirected in safe mode and still haveing the problem with the file or exe svchost.exe useing 100% cru
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you being redirected in only FF? What about other browsers? Do you get redirected in them?
     
  16. jagdryan

    jagdryan Private E-2

    all i have is firefox and still haveing problems with my svchost.exe useing 100% cpu and i deal how to fix that ?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your XP boot CD?

    You need to use your Windows XP CD to boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command then boot back to normal mode Windows and try running TDSSkiller now. Then attach the log. Also explain if you are still having any malware problems.
     
  18. jagdryan

    jagdryan Private E-2

    no i bought the computer and no disk came with it.. thats why i really trying to not reinstall windows and also i think my cd drive stop working.. i just wana fix the problem and get it to run right again
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't want you to reinstall XP, I would like you to be able to address the MBR infection that I am sure you have though. Only other option I can think of would be the below:

    You may want to try creating and using Hiren's CD to fix the MBR. See what was posted in message # 12 of the below thread and see if you can get this CD to run. If you still need special drivers to access your drive, you will need to post in the Software Forum on how to do this.

    whistler/black internet@mbr again!
     
  20. jagdryan

    jagdryan Private E-2

    i can't use a cd my cd drive seems not to be working but i do have a usb drive 1gb thumb drive and yes the computer and boot off usb
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Dammit, of course, my apologies.

    You say it detects the flashdrive?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Earlier on ComboFix installed the Recovery Console. (Correct?) We're going to use that now.

    Reboot your machine and when the Boot Menu flashes up - select "Microsoft Windows Recovery Console"
    (you need to be very fast with the arrow key as you only have a couple of seconds before it defaults to the windows XP bootup)

    http://i1111.photobucket.com/albums/h479/MysticalMagpie/1.gif?t=1303862256


    http://i1111.photobucket.com/albums/h479/MysticalMagpie/2.png?t=1303862286

    When you get to the above screen, take note of the number that references your operating system.

    If it's '1' like the picture above, type 1 and press Enter

    http://i1111.photobucket.com/albums/h479/MysticalMagpie/3.png?t=1303862308

    Next type FIXMBR

    If it ask if you're sure you want to write a new MBR, answer 'Y'

    Then type EXIT to reboot the machine.

    With that done, please post back and let me know how things are now.
     
  23. jagdryan

    jagdryan Private E-2

    yes it will install windows off a flash drive if made right ( was reallyhard to do)
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about my post number 22? You trying that?
     
  25. jagdryan

    jagdryan Private E-2

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about the redirects?! Do they persist or not? Give it some time, reboot, surf.... come back and let me know.
     
  27. jagdryan

    jagdryan Private E-2

    yes i am still being redirected still about to install google chrome to hope that fixes
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Surf around... still being redirected? If so tell me whether Internet Explorer redirects too. Or whether these redirects occur in safe mode also.
     
  29. jagdryan

    jagdryan Private E-2

    i delete internet explore when i was in safe mode when i was in windows norm it always was trying to run even tho i did not click on it.. so i delete the internet explore and it stop trying to run :D will reinstall fire fox in a sec or 2
     
  30. jagdryan

    jagdryan Private E-2

    also any 1 not looking at the pic i posted ? that would yall in telling me where to delete those 3 files that i have to keep end tasking
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you just follow my instructions for now please? It would be much easier. ;)
     
  32. jagdryan

    jagdryan Private E-2

    now firefox will not even start not even iexplore that i reinstalled.. on moms labtop now
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is your computer the only one that is having redirects or are all the computers on your network having the same issues? If you plug your computer directly into the modem, does it still redirect?
     
  35. jagdryan

    jagdryan Private E-2

    yes even when that if u look at the pic i posted the 3 things useing cpu i end task witch stops firefox and iexplore from running but if i do not end task those 3 things svchost.exe will use 100% cru and i am plug via cable not wireless
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Be more precise about how you answer Tim's questions.

    You just said "yes" but he asked:

    So to help us, to help you, be clearer in your response. :) Thanks.
     
  37. jagdryan

    jagdryan Private E-2

    no its just my computer haveing the problem my computer is connect to the lan. i am not wireless.. and i am still trying to fix the files in the svchost.exe useing 100% cpu
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks. Now re-read my post number 33 and answer my question.
    Yes! and I only want you to do what we ask you to do at the moment.
     
  39. jagdryan

    jagdryan Private E-2

    yes i started it safe but and still did not work bescue of the 3 problems i had to end task in witch are in svchost.exe
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do not see any problems in the screenshot. I will have Chaslang have a look to be sure.
     
  41. jagdryan

    jagdryan Private E-2

    in the screen shot it shows 3 programs useing almost or useing 100% cru with outgoing down its staying at that all the time at 100% when i end task them the computer goes back to normal but the browser do not work any ideals how to fix it
     
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What programs? No ideas at the moment because I need some sleep, it is now almost 5am here. :( Are you able to install another browser such as Chrome onto the affected computer via a flashdrive?
    Bad idea, as you can see now.
     
  43. jagdryan

    jagdryan Private E-2

    the kernel32.dll so on.. is useing maxing my cpu out at 100% but when the program is end tasked none of the browser work
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes because you are doing more harm than good I think by doing what you are doing .
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you plugged directly into your modem or are you plugged into a router? You also need to put your system into normal start up through msconfig.

    We were not seeing malware in your logs. Are there other issues you are having with this computer which may indicate a need to do a repair install?
     
  46. jagdryan

    jagdryan Private E-2

    yes still being redirected and still haveing the problem with svchost.exe.. and i can't do a clean install i do not have the windows disk and Microsoft wants to charge 50 bunks for a new windows cd Oo and i can't do a repair with no disk that why i am trying to fix the problem the the hard but it seems thats is not gona help.. if the problem with the svchost.exe would to stop that would give me more time to figure out the redirecting of the browser
     
  47. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are misdiagnosing cause and effect. You are also breaking, or in reality already broken your PC by taking it upon yourself to remove things you should not be touching. A repair of Windows may be in order. :(

    Did you do this?

    Also you mentioned BitDefender earlier on. This is not malware.
     
    Last edited: Jun 25, 2011
  48. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can get Recovery Media by contacting the computer manufacturer and requesting a disc. They only charge a nominal fee to send you a CD.

    Now please put msconfig in normal start up mode and get me new logs for ComboFix and C:\MGLogs.zip. Your last logs were done in safe mode, so we need them done now in normal start up mode.
     
    Last edited: Jun 25, 2011
  49. jagdryan

    jagdryan Private E-2

    and again i do not have a windows cd to put in the computer to fix or broken files and still can use cd drive
     
  50. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you post in the software forum about your cd problem. But as I said, you may need to contact the computer manufacturer and as for an install disc. Unless you can find someone who has one and can borrow it. It must be the same version of Windows as what you have installed. You may also need to get an external cd player to use the disc.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds