Redirecting Issue on All Browser and Devices

Discussion in 'Malware Help (A Specialist Will Reply)' started by Comeback, Oct 24, 2012.

  1. Comeback

    Comeback Private E-2

    My redirecting issues seems to mainly come from Google when on Firefox, but when it happens, it happens on all browsers. When using Chrome normally, it seems to happen to Facebook. When I flush the DNS via command prompt, the issue tends to disappear for the moment. I've ran a boot-time scan with Avast!, which found a PuP(Windows Vista Activation .exe), but that was it. After Avast! I tried Malwarebytes and Microsoft Malicious Removal Tool; both found nothing. I also tried resetting my router, to no success of eliminating the issue. When the issue begins to happen, google usually redirects to Cloudfire, but other times it gives me an odd list of sites like "amazonaws", ".ru" sites others.

    One major concerning issue is that it doesn't just affect my PC when it happens. It seems to happen to others, including small devices like an ipad.

    I'm stumped here and I'm currently looking over other steps from the tutorials here. Any help would be great!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.


    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.


     
  3. Comeback

    Comeback Private E-2

    Thanks for the heads up! Logs are up! Whatever this is, it worries me. I'm really unsure as to why it's also affecting smaller devices.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested logs from TDSSKiller and MGtools
     
  5. Comeback

    Comeback Private E-2

    Argh! Sorry about that! Here are the rest.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then uninstall Chrome now. Then reboot. After reboot, delete the below folder:

    C:\Users\Nightdrive\AppData\Local\Google\Chrome

    Then if you wish to still use Chrome, use Internet Explorer to download the current version from the below link and reinstall. See the download links under this icon: http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    Google Chrome 22.0.1229.94 Stable

    See how it is working after reinstall.

    Now let's also cleanup some other junk.


    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT will reset your home page to a google default so you will need to restore your home page setting.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  7. Comeback

    Comeback Private E-2

    Here's the report! I was wondering, should I do the same with Firefox? It's what I primarily use. I won't be reinstalling Chrome.
     

    Attached Files:

    • JRT.txt
      File size:
      2.3 KB
      Views:
      4
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if it is having the same type problems. We typically do the below to save bookmarks first.



    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    C:\Users\Nightdrive\AppData\Roaming\Mozilla
    C:\Program Files (x86)\Mozilla Firefox\extensions

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).
     
  9. Comeback

    Comeback Private E-2

    Steps above have been taken. The redirecting seems to happen randomly, so I'll have to monitor for a bit; I'll report when if happens again. Hopefully we got it! Another thing: How exactly did the redirecting also affect smaller devices like ipads and iphones? Also, I have a laptop that uses our network as well. Should I take these same steps to ensure that the laptop isn't infected as well?
     
  10. Comeback

    Comeback Private E-2

    UPDATE: The redirecting happened again. I'm not 100% sure, but it seemed to have happened when the laptop was turned on. Firefox wouldn't let me get on Google on my current desktop PC, and it seemed to have happened around the time the laptop was on. Laptop has been turned off and will not be turned on till further instructions.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not being able to get to Google is not a redirect. So are you having redirects or are you having a problem getting to Google. And not sure why this would have anything to do with your other PC being on unless it totally breaks the ability to connect to any website.

    Please rerun Hitman Pro and attach a new log. I want to see if that Babylon junk still shows. It looks like it was missed by JRT.
     
  12. Comeback

    Comeback Private E-2

    It's not an always happening thing. Usually I'll get some kind of cloudflare error when trying to use Google, but other times, when it stops me, it says it's trying to redirect me to random, shady looking sites. Some with Russian ".ru" in them. I was once even redirected to CNN from going to Google. And when trying to use another search engine like Yahoo, I'd be able to search, but any links I click from it tries sending me to the same bad site.

    Like I said earlier as well, when this happens, the cloudflare notice goes to all devices, including ipads and phones, until I go into console and flush the DNS; that only subsides it. Couldn't the issue be affecting everything on the network? Just seemed odd how everything was fine until the laptop was turned on and I was once again getting the notices.

    Anyways, here's the new Hitman log.
     

    Attached Files:

    Last edited: Oct 28, 2012
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Power cycle your router. If that does not help, then reset it back to factory condition.

    Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    Allow Hitman to fix the below items.
    HKLM\SOFTWARE\Classes\AppID\secman.DLL\ (Babylon)
    HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}\ (Babylon)
    HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1\ (Babylon)
    HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager\ (Babylon)
    HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\AppID\secman.DLL\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}\ (Babylon)

    Then reboot. After reboot run a new scan with Hitman and attach this new log.
     
  14. Comeback

    Comeback Private E-2

    Hitman only has Delete or Ignore. What do I do?
     
  15. Comeback

    Comeback Private E-2

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete.

    Uninstall Firefox and leave it uninstalled for now. Just use Internet Explorer and tell me what happens when using it.
     
  17. Comeback

    Comeback Private E-2

    Firefox is deleted once again, and thanks to having to watch a child while doing this, I accidentally skipped and rebooted Hitman after I deleted those files. I ran it again after reboot though; hopefully that's alright!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay those items are gone from the Hitman log. How are things working when just using IE?

    Also please download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  19. Comeback

    Comeback Private E-2

    After uninstalling Firefox and putting up logs from Hitman, I reset my router. After getting back online, I attempted getting on google with IE, only to get a "can't get online" when I tried. I was able to get on any other site but Google, which was odd. So I did what I always do when my redirecting issue occured, flushed DNS through command prompt, and google was back to normal.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your last log did not show any problems with getting to Google
    Code:
    ================================================================= 
    Pinging 74.125.113.106 with 32 bytes of data:
    Reply from 74.125.113.106: bytes=32 time=93ms TTL=49
    Reply from 74.125.113.106: bytes=32 time=93ms TTL=49
    Ping statistics for 74.125.113.106:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 93ms, Maximum = 93ms, Average = 93ms
    ================================================================= 
    Pinging [URL="http://www.google.com"]www.google.com[/URL] [74.125.224.48] with 32 bytes of data:
    Reply from 74.125.224.48: bytes=32 time=18ms TTL=54
    Reply from 74.125.224.48: bytes=32 time=18ms TTL=54
    Ping statistics for 74.125.224.48:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 18ms, Maximum = 18ms, Average = 18ms
    ================================================================= 
    Doing nslookup google.com 
    Server:  UnKnown
    Address:  192.168.1.1
    Name:    google.com
    Addresses:  2001:4860:4001:803::1009
       74.125.224.134
       74.125.224.135
       74.125.224.131
       74.125.224.128
       74.125.224.142
       74.125.224.136
       74.125.224.137
       74.125.224.132
       74.125.224.133
       74.125.224.130
       74.125.224.129
    Is it still okay?
     
  21. Comeback

    Comeback Private E-2

    So far so good with Google, although someone did use this PC to log onto his ebay page, then later tried getting on his ebay page on his phone, and got a "risk" warning when trying to do so; so I tried getting on his ebay page on this PC and was being given HTTP 400 error from Internet Explorer. I did the usual flush DNS from console, and it went back to normal. I've been checking back and it hasn't done it again so far.

    Also, when do you think I should try installing Firefox again? I'm really not liking IE, hah.
     
  22. Comeback

    Comeback Private E-2

    The issue with my.ebay.com seems to have happened again. Getting a HTTP 400 error.

    Pinging it gave me the ip of "96.17.148.104"

    I wasn't sure if MGTools will say anything about the issue, but I decided to run it while the issue was actually happening. Here are the logs, if it matters any. Google has yet to cause issues.
     

    Attached Files:

  23. Comeback

    Comeback Private E-2

    Another update. IE just warned me that I was trying to be redirected when using Google. This time I ran MGTools WHILE the issue was happening. I didn't clear it with flushing the DNS.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing and has been nothing in any of you logs to indicate infection or redirection issues. It seems to me that you may be mistaking problems with getting connected ( like the above error ) with redirection. This is not a redirection.

    pinging what gave you 96.17.148.104
    Code:
    96.17.148.104 - Geo Information
    IP Address:   [URL="http://cqcounter.com/traceroute/?query=96.17.148.104"]96.17.148.104[/URL]
    Host:         a96-17-148-104.deploy.akamaitechnologies.com
    Location:     [IMG]http://n1.dlcache.com/flags/us.gif[/IMG] US, United States
    City:         Cambridge, MA 02142
    Organization: Akamai Technologies
    ISP:          Akamai Technologies
    AS Number:    AS7922 Comcast Cable Communications, Inc.
    
    Looks like your ISP?
     
  25. Comeback

    Comeback Private E-2

    That's not my ISP. Differen't State as well.
     
  26. Comeback

    Comeback Private E-2

    Stupid me. I can't edit, but I didn't notice the part at the bottom. Yes, my ISP is Comcast, but I'm not in the same state. But again, why would pinging my.ebay.com give me that IP? Also, I'm going to try getting back on Firefox. I can't stand another minute on IE!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your ISP is ComCast and they appear to be using that address from Akamai. Notice the line I posted that shows AS Number:

    Akamai Technologies, Inc. is an Internet content delivery network headquartered in Cambridge, Massachusetts. Akamai's network is one of the world's largest distributed-computing platforms.

    Malware would not reroute your ping IP to a valid internet hosting company. It would serve no purpose. Also my.ebay.com is not a valid URL that you can ping. Neither is www.ebay.com. They will not answer pings
    Code:
    C:\Windows\system32>ping my.ebay.com
    Pinging my.g.ebay.com [66.135.204.53] with 32 bytes of data:
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    Ping statistics for 66.135.204.53:
        Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
     
     
    C:\Windows\system32>ping [URL="http://www.ebay.com"]www.ebay.com[/URL]
    Pinging [URL="http://www.g.ebay.com"]www.g.ebay.com[/URL] [66.135.210.61] with 32 bytes of data:
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    Ping statistics for 66.135.210.61:
        Packets: Sent = 4, Received = 0, Lost = 4 (100% loss), 
    And your ISP or some software you have installed my be capturing errors like this in and redirecting on errors to HTTP 404 error. Try pinging something valid like www.google.com or www.microsoft.com or www.apple.com And note, when I ping apple.com it goes thru akamai to get there. And I don't live in Mass. either and Akamai is not my ISP.
    Code:
    C:\Windows\system32>ping [URL="http://www.apple.com"]www.apple.com[/URL]
     
    Pinging e3191.c.akamaiedge.net [23.45.13.15] with 32 bytes of data:
    Reply from 23.45.13.15: bytes=32 time=114ms TTL=251
    Reply from 23.45.13.15: bytes=32 time=120ms TTL=251
    Reply from 23.45.13.15: bytes=32 time=118ms TTL=251
    Reply from 23.45.13.15: bytes=32 time=113ms TTL=251
    Ping statistics for 23.45.13.15:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 113ms, Maximum = 120ms, Average = 116ms
    Have you tried by passing your router completely ( assuming you have a router ) and directly connecting your PC to the internet? If not then try this. We have seen many cases where routers have been causes of issues like this.
     
    Last edited: Nov 1, 2012
  28. Comeback

    Comeback Private E-2

    I nearly went two days without it happening till just now. Google was giving me the cloudflare thing. I wouldn't be so confused or worried if it wasn't for the time it kept trying to send me to some crazy Russian site that my anti-virus was stopping from doing something. There's times where it says it's trying to go to apple.com, and another time where it was sending me to CNN.com. Seems like we're at the end here. I may try connecting straight from the modem; only trouble is that everyone in this house will go insane while I try and see if it'll start its trouble.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to do this just to test it out. Malware is not showing on your PC. Your router ( and sometime even the modem ) can be the cause. Assuming there are other PCs, in the house base on you statement, is anyone else having similar kinds of problems.

    Also please do the below.

    Please download OTL by OldTimer.
     
  30. Comeback

    Comeback Private E-2

    Like I said before, when the issue happens, it happens on all devices on the network, including phones and ipads at the same time, and when I flush DNS from command prompt on my PC, it fixes it for all devices as well. There's another desktop and a laptop. Desktop has been gotten rid of ever since I reported this issue; it's just old and will no longer be used. Laptop hasn't been turned on in about a week.

    Here is OTL log. It also made an "extra" log. Should I upload that as well?
     

    Attached Files:

    • OTL.Txt
      File size:
      291.8 KB
      Views:
      2
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then the problem is not with your PC but with your DNS server which is in your router which is why I said to by pass it quite awhile ago but you have not tried this. Your PC is clean as already stated.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds