Help brower being redirected

Discussion in 'Malware Help (A Specialist Will Reply)' started by WCHIN4, Mar 1, 2009.

  1. WCHIN4

    WCHIN4 Private E-2

    Hi,

    My browser (Chrome/Firefox) is randomly being redirected to different sites. I have had the problem now for about 3 weeks. I have run the procedure in Malware Removal Guide. None of the programs appeared to have identified the problem. During the last program, MGtools, it was not able to open the host file (it was locked? or read-only?); anyways, I looked in the file and it appeared to have a number of unknown mapping instructions. I will attachthe host file (host.txt) in addition to the series of log files from the spyware programs.

    Thanks for your help in advance,

    Warren
     

    Attached Files:

  2. WCHIN4

    WCHIN4 Private E-2

    Also, when I try to edit out the host file, I get error message saying that the file is locked and I need admin access. Here are remaining attachments.

    Warren
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. WCHIN4

    WCHIN4 Private E-2

    Ran from desktop. Attached is log
    Thanks,

    Warren
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you re-immunized with spybot lately?

    If you right click the host file and check properties, is there a permissions tab?
     
  6. WCHIN4

    WCHIN4 Private E-2

    Have you re-immunized with spybot lately? No

    If you right click the host file and check properties, is there a permissions tab? No. Also the read only box is checked and I cannot uncheck - get and "access denied" error msg.

    Please advise what are next steps - thanks!

    Warren
     
  7. WCHIN4

    WCHIN4 Private E-2

    Made a mistake below. I did immunize with spybot on 3/1/09.

    Warren
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    According to your hosts file, you need to immunize against this address:
    89.149.227.223

    You can also check that in you firewall.

    I am going to attach a clean hosts file....open it in notepad and save it to the sys32\drivers
    etc folder.
     

    Attached Files:

  9. WCHIN4

    WCHIN4 Private E-2

    Thanks. I do not know hw to immunize against a specific site - please advise. Also, I am not sure how to setup my firewall against an address. i am using the Windows firewall.

    ...and I opened my hosts file and replaced the text from your attached file into the hosts file. i saved it as "hosts", but I get error message that "..cannot create hosts file...".

    Warren
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Window firewall is no protection!! You need a real software firewall such as PCTools Firewall....PC Tools Firewall Plus --> just do not install the threatfire add on.

    What I wanted you to do is to click on the Hosts file I gave you to save to your desktop. then go to the system32/drivers/etc folder and copy and paste it there..it should ask if you want to replace/overwrite the existing file.
     
  11. WCHIN4

    WCHIN4 Private E-2

    I installed the PC tools firewall. I copied the hosts.txt file to the ....etc subdirectory. I was able to delete the old hosts file. I rebooted. It looks like the problem is gone!!!!! Thanks!!! I am still not sure how to block that address from within the pc tools firewall.

    Thanks again!
    Warren
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Post the question in the software section. And glad to here you got it to work!! :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds