Browser Redirect and keyboard glitch

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pitt, Jan 18, 2010.

  1. Pitt

    Pitt Private E-2

    Hello and thanks in advance for your help. Like many, my problem started when my girlfriend downloaded some tattoo app from facebook. Next thing I knew, there was a tool bar I couldn't get rid of on both Explorer and Firefox, and worse, I'm being redirected to Mal sites no matter what link I click on in Google.

    Now both Firefox and Explorer redirect, have pop-ups and firefox keeps closing due to errors.

    I have even removed Firfox and all the files associated with it. When I reinstall, POOF! the toolbar is gone, but the redirecting and errors continue.

    The latest, is that if I'm typing or opening a box, the computer "burps" by refreshing said page/box/email, and everything I typed will be gone. You retype and its fine. I have tried all the suggestions I have found here, to no joy, still happening. :tas

    Thank you for any and all suggestions and help

    Pitt
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We need the logs from ComboFix and RootRepeal. It appears that you skipped running both of these since I do not see them on your computer. You will need to attach a new log from MGtools after running ComboFix & RootRepeal since MGtools needs to be run last.

    Why are you running without an antivirus program?
     
  3. Pitt

    Pitt Private E-2

    I forgot to add, I'm running XP pro. I thought those two did not work with XP? I will go back and reread now.

    Ok, the RR worked. Combofix will not. Here is the Root R report as well as MG tools.

    I also want to add, AOL's browser works and seems unaffected by the virus/Mal. Google redirects and has popups and browser errors in IE and Firefox only.

    ]Thank you for your help by the way.
     

    Attached Files:

  4. Pitt

    Pitt Private E-2

    Opps. did something wrong. Here are the attachments.:-D
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly happens when you run ComboFix.

    Please do not create your own MGlogs.zip file. You must only attach the one that we create which is ALWAYS C:\MGlogs.zip. It will never have any other name. What you attached is not our log. Also you need to stop doing things on your own and only follow our instructions as stated in the very beginning of the READ & RUN ME.

    Is your copy of Spyware Doctor a paid version or free trial? If just a trial, uninstall it now.



    Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Pitt

    Pitt Private E-2

    Ok, Sorry if I did something wrong. I try to keep a file on the Desktop of all these reports, but I will leave them in C: if that's what you want.

    Dumb question, is there a way of switching this forums view? I see the options but I see the last post made on the top, not the bottom.

    I followed all the directions and found that the combofix would not install with my COMODO system turned off. It seemed to lock up the install files. What I had to do was allow the Comodo to stay on, excuse all the files it marked as infected, then without running ComboFix, I rebooted after the install and then shot down the virus protection, malware, etc, then allowed the Combofix to run, which it did to success.

    I then deleted the temp files, cleaned the internet files via explorer and firefox, and I don't seem to be rerouted on every google search, yet it does on some with Firefox. Its still giving me varius popups on both browsers, and that "burp". Burp meaning that say your looking at a sign in page for email, a forum, or even an email your writing. within the first few letters you type, the screen reboots the page and your writing is gone. Almost like its being stored or sent out ( my paranoia?)
    sometimes an hr glass appears and the drop down on a page will open when the page "burps". PS( Just came back to edit my post and the page refreshed on its own again, lost all my writing)



    Here are the logs, and once again, thanks. IF It where me alone,. I would be formatting this thing already.

    Do you guys ever actually give up and advise a reinstall? Are there viruses and Mal that leave a system unrepairable?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is important to only do what we request. Do not rename things. Do not move than anywhere else. Doing so will make automatic fixes and cleanup tools unable to work properly.

    The normal view most users want is to see the newest message at the top. Not sure why you would want to see older messages first. When threads get longer than one page, this becomes a real problem. However like all forums, you can go to the User Control Panel under Quick Links and change it to what you prefer.

    Are you saying that only Firefox is still causing redirections.

    Shutdown Firefox and delete the below folder:
    C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

    Then reboot your PC and test Firefox for problems.

    What popups?

    We only suggest reinstalls ( and overall this is rare ) when it is necessary or the most secure thing to do based on infections being seen. One example where reinstall is necessary is a Virut or any similar PE file infector.

    Did you install Comodo with an antivirus or only the firewall? I suggest that you uninstall a-squared which is prone to way to many false detections.


    Your logs are clean. When you ran TDSSkiller on Jan 13 2010 08:42:25, it removed the source of your problems
     
    Last edited: Jan 25, 2010
  8. Pitt

    Pitt Private E-2

    Despite being set to filter popups, since this issue, both EI and FF have popups. No, both EI and FF are redirecting me, but it seems that the redirections are now either variable or Its my imagination. They don't seem to send me to the same places, and I would say 1/4 of the searched actually send me to the right site, especially if I use Cashe instead of the hyperlink.

    My next Idea was to reinstall FF since its the only browser I use usually, but I wanted to wait and get your advice. See!I'm following the rules!:wave

    Any handle on why my windows keep reloading? It happened again right here.

    Sir, Dood, Mam, I want to tell you again, Thanks! I'm very greatful for the help

    Pitt
     
    Last edited by a moderator: Jan 25, 2010
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you delete the folder I asked you to delete? Did it have any affect?


    Just reinstalling Firefox will not help. You must uninstall it, and you must delete all related folders and files before reinstalling. Like the below folders must be deleted:
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox


    No idea but it does not seem to be malware especially since your logs are basically clean.
     
  10. Pitt

    Pitt Private E-2

    I deleted all of anything that said Firefox, reinstalled, and I dont have anymore Redirecting. THANK YOU! By the way, it also fixed the keyboard jumping, so that's a double thanks.

    Pitt
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. Pitt

    Pitt Private E-2

    Ok, well that didnt last long. Its back. All back again. Both IE and Firefox are rerouting. Obviously, I know how to go through the thread and fix, but what is causing this Chaslang?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First I need to know did you complete 100% of my final instructions.

    If the same exact problem came back then it is more that likely due to something you are doing. Some website you are going to, something you are downloading....etc.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds