Google is redirecting in FireFox Please take a look at my combofix log

Discussion in 'Malware Help (A Specialist Will Reply)' started by redbourn, Jan 2, 2011.

  1. redbourn

    redbourn Private E-2

    Hi,

    I tried a couple of malware removal tools including hijack this and malwarebyte but Firefox still gets redirected when I do a Google search.

    I just ran combofix and would appreciate somebody taking a look at the log for me - I did disable AV: ESET NOD32 Antivirus 4.2

    My heart skipped a beat when I saw files and folders being deleted! The last time I saw that a couple of years ago I had to restore my system from a clone :(

    Any help would be much appreciated.

    Thanks,

    Michael
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message


    Please read this:
    How to attach items to your post.

    Now if you are still having redirect issues, please do the following:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. redbourn

    redbourn Private E-2

    Thanks for the help.

    I'll get back to you when I've done it.

    Michael
     
  4. redbourn

    redbourn Private E-2

    >If the scan completes with nothing found, click Close to exit.

    Nothing was found; but at least it was quick!

    I had the Microsoft Windows Malicious Software Removal Tool running for several hours and it had only done 14% so far so I cancelled it to run TDSSKiller, but I might let it run all night.

    Michael
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you need to do the Read and Run First instructions that I linked you to so we can see what is happening in your system. Please reply with the requested logs attached. ;)
     
  6. redbourn

    redbourn Private E-2

    I ran SuperAntiSpyware and the problem has gone away ;)

    Let's hope it doesn't come back!

    Apart from tons of cookies, the following is all that it found and quarantined;

    s0.2mdn.net [ C:\Users\Mike\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\WXEWQSNS ]

    Trojan.Agent/Gen-Falcomp[Cont]
    C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB COMPONENTS\MESSENGER.EXE

    I can't imagine that a cookie was the problem, although I know little about malware, and I couldn't find out any information about ..

    Trojan.Agent/Gen-Falcomp[Cont]

    Michael
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it does come back, you will need to run all the requested scans and attach those logs for me to look at.
     
  8. redbourn

    redbourn Private E-2

    All still seems to be OK and I just bought the pro version of SuperAntiSpyware and said that I heard about it here ;-)

    Thanks,

    Michael
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds