browser redirecting ads

Discussion in 'Malware Help (A Specialist Will Reply)' started by miketan, Apr 13, 2010.

  1. miketan

    miketan Private E-2

    Hi there, I am currently experiencing browser redirecting across different browsers (both firefox and internet explorer)
    I have also had a pop up from Avant literally every 5 mins saying threat detected svchost.exe, win32:rootkit -gen [rtk] in windows temp folder.
    However, this appears to have stopped happening since running the "READ AND RUN ME FIRST GUIDE" and "Vista Cleaning Procedure", but I don't know whether this is because it's actually gone, or if has just moved or something when I had to disable virus checkers to complete the logs for the read and run guide.

    Any help on either of these would really save my bacon! Have been working on them all day (having such a big machine means about 2-3hrs per complete scan at the moment!)

    This started happening a couple of days ago, after AVG found a couple of detections (now moved onto Avast) and Google chrome stopped working, it never actually loads any pages, just continual blank pages on opening Chrome (now moved onto Firefox which does work!) I assumed Chrome not working was because some virus had got tangled in it and the whole lot got cut off by windows or a virus checker.

    Am happy to give you any more info you need or anything, Logs for SuperAntiSpyware, Malwarebytes, combofix and RootRepeal attached, MGtools log to follow in next post.

    Many thanks in advance!
     

    Attached Files:

  2. miketan

    miketan Private E-2

    MGtools log attached to this post.
    By the way, had a quick glance at the ComboFix.txt file on previous post in notepad and it seems remarkably smaller than the example one shown in the tutorial for ComboFix in vista cleaning procedure guide.

    Many thanks again, really appreciate any help, was almost at the point of reinstalling earlier until I discovered your forum.
    Mike
     

    Attached Files:

  3. miketan

    miketan Private E-2

    update, new virus? + scan

    UPDATE:
    I turned on the pc this morning and I got a pop up window with "total vista security" program trying to scan my pc.
    I ran task manager and killed all the processes associated with the running program as I understand it's a virus!
    I then ran a complete malwarebytes scan. I have attached the log to this post.

    2 of the 'infected files' it came up with are located in programs that I use everyday, Cycling '74 and Waves. I would say they were safe, unless you suggest otherwise I would hesitate to remove the files from these two locations. They are the first two under "Files Infected" in the attached scan.

    Will happily respond to any requests asap, as this is on a work machine that I can't use until virus is fixed.

    Thanks again (again!)

    edit: still have malwarebytes results up on screen so any advice which to deal with appreciated
     

    Attached Files:

    Last edited: Apr 14, 2010
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your Combo log was interrupted. Please re-run it and dont do anything while it runs.

    I hope you had MBAM fix everything other than the cycle and wave uninstall files.

    Attach a new COmbo log and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds