Brower Hijacked/Redirected

Discussion in 'Malware Help (A Specialist Will Reply)' started by IBleed4Thee, Aug 16, 2013.

  1. IBleed4Thee

    IBleed4Thee Private First Class

    Two or three days ago my browser was hijacked or redirected by what appeared to be Google. It claimed the I had won a prize for the area I live in. Of course, I didn't click on the link. I currently use Firefox.

    The first time it happened a new tab opened and overrode the website I was on. This occurred a second time. I had ran CCCleaner, MalwareBytes (free version)that day and my AV which is AVG...they showed nothing out of the ordinary.

    I had shut down the pc last night and this morning when I opened Firefox instead of going to last tab and windows opened it went straight to this so called Google page. I scrolled down to the bottom of this so called Google web page and it states that is actually is not connected with Google but doesn't state where or what it's from.

    I ran the programs for redirected browser and they are attached.

    I also ran all the Windows XP Malware Removal/Cleaning Procedures and will attached those to a second thread.

    I did notice some "garbage" in the logs that I've never seen before.

    As always, your help is more than appreciated.
     

    Attached Files:

  2. IBleed4Thee

    IBleed4Thee Private First Class

    Windows XP Malware Removal/Cleaning Procedures logs attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [APPINIT][SUSP PATH] HKLM\[...]\Windows : AppInit_DLLs (c:\docume~1\alluse~1.win\applic~1\browse~1\23796~1.11\{16cdf~1\browse~1.dll [x]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Delete this:
    C:\Program Files\Common Files\Spigot

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )

    How are things running now at this point?
     
  4. IBleed4Thee

    IBleed4Thee Private First Class

    Kestrel13!

    Thanks so much for replying and addressing my issue so quickly.

    I ran both programs and deleted what you stated.

    It seems to be running fine and no sign of the "google page" reared it's ugly face either time I shut down and opened Firefox. Hopefully it's gone but as it appeared on opening Firefox or while I was surfing websites, I guess it's a wait and see. Or can you tell by the logs that it's gone?

    See attached.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Surf around a while and see how it goes. If all is well then you can follow final steps outlined below:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.

    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. IBleed4Thee

    IBleed4Thee Private First Class

    Everything seems to be running great and I haven't had a issue with redirect.

    Went through the final steps that you suggest.

    Thanks so much for all your help.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds