Is this redirector Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by cj1122, Sep 17, 2010.

  1. cj1122

    cj1122 Private E-2

    2 to 3 weeks ago, I noticed that sometimes when the window finished loading, it would start clocking again and take me to a Google error page. Is this a redirector malware error?
    A friend's fix for the problem was to uninstall the URL Assistant. I determined that he had just put a Band-Aid on the situation. After the window had finished loading, it would start clocking again, but now it is not being redirected to the error page. Since he removed the URL Assistant, won’t that interfere with my browsing when a website has changed their URL? Can I reinstall that component when my PC is clean?
    After completing all the scans, it appears that something is still not quite right. Once the window finishes loading, it will start clocking again (very slowly now), but now it is not showing the web address that it is trying to go to. Before the scans, it would show the web address (it was being redirected to) on the bottom tool bar.
    Logs attached. Second post will follow with the final log. Please advise.
    Many thanks!
     

    Attached Files:

  2. cj1122

    cj1122 Private E-2

    Final log attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It is more than likely bloatware installed by Dell which probably isn't even needed. Choice is yours about that.

    LiveUpdate 2.6 (Symantec Corporation)
    <--- I see this in your installed programs listing, what are you currently using from symantec?

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Not seeing anything malware related in your logs, how are things running now then?
     
  4. cj1122

    cj1122 Private E-2

    Hi Kestrel13,

    I do believe you are right...the URL asst was probably installed by Dell & if I don't need it..it's already forgotten. One less thing to worry about.....

    As far as I know, I am not currently using Symantec Corp. for anything. Could this be related to the Norton Ghost trial (I removed it) that was installed by Dell? I might be wrong...I am a bit of a novice......should I remove it?

    After running the fixMX.reg, I DID receive a confirmation that it was successfully added to the registry. Yeah!

    As far as how things are running now....let me first say this is an old PC and I have the slowest DSL connection (I try to be frugal) so I don't expect miracles, but this PC is performing wonderfully since I did all the scans (that was really painful since I only like to play on a computer) and updated the registry per your instructions. I am still seeing the PC clocking after the window has finished loading (not as much though), but I can live with it if there is not an evil entity lurking in the background causing it. Any idea what caused the original redirector errors I was getting?

    Please advise what further action(s) I need to take. Thank you so much for you help!!!!
     
    Last edited: Sep 18, 2010
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this then to cover all angles.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  6. cj1122

    cj1122 Private E-2

    Here is the log....after the scan it said no infections found. Let me know....thanks!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log is clean. What malware issues are you still having, if any?

    You really need to, at a minimum, double your amount of RAM. You can go to crucial.com and let them scan your system and tell you how much RAM your motherboard will accept.
     
  8. cj1122

    cj1122 Private E-2

    I am still having an issue with....after the window finishes loading, it continues to clock like it's trying to redirect me somewhere. The URL asst has been removed so I am not being redirected (I was being redirected to a Google error page before), but the clocking continues. The situation is not as bad as it was before all the housecleaning and scans, but the problem is still there. My concern was that there was something evil lurking in the background causing it since this was not happening before....that might be why I was given this last scan to do. Is this something I should no longer be concerned with? I recommend any further suggestions.

    Your recommendation to upgrade the memory is duly noted and I will take care of that ASAP.

    Thanks for your help!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you mean by "clocking"? Are you being redirected still?
     
  10. cj1122

    cj1122 Private E-2

    Let me back up just a little bit so that you will know what I am talking about. This started 2 or 3 weeks ago.....sometimes (not always) after a window had finished loading and it said "done" on the lower left of the windows toolbar, the window would start clocking again and I would be redirected to a Google window with an error stating that it could not find such and such address (when I had not been trying to go to whatever address it was anyway). A friend removed the URL assistant and I was no longer being redirected to the Google page, but the clocking continued showing some weird address on the windows toolbar. This continued and my PC was performing poorly(and weird) so after some research, I thought it was probably the redirector malware error. I went through the housecleaning and scans before posting a thread here.

    No, I am no longer being redirected...that stopped when the URL assistant was removed. (Kestrel13 said I didn't really need the URL assistant anyway as it was bloated software installed by Dell.) My PC is performing much better now, but I am still seeing the clocking (now without the weird address showing) after the window has finished loading (this use to not happen). By clocking, (forgive me if I am not using the correct terminology) I mean....the blue bar in the middle of the toolbar at the bottom of the page that moves from left to right while the window is loading and then once the window has finished loading, the blue bar disappears and the area becomes gray again. I hope that makes sense.......

    Thanks again for all your help!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Interesting, so what you are saying is that once you get to a web page and it finishes loading, you then see the progress bar starting to try to load something again, but it never goes there?

    Let's have you run CCleaner and after that run ATF Cleaner by Atribune.
     
  12. cj1122

    cj1122 Private E-2

    Yes, yes, yes! That is exactly what I am saying! :-D

    One quick question on the ATF Cleaner. Do I select all files? Just wanted to make sure....

    Thanks for your patience!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, and be sure to exit all browsers when you do the cleaning.
     
  14. cj1122

    cj1122 Private E-2

    I ran the CCleaner and the ATF cleaner per your instructions. Then I rebooted because it seemed like a good idea. This may not be related and could just be one of those things, but when I opened Internet Explorer, the background of the right half of the 2nd and 3rd toolbars (not sure of proper names for them-maybe menu & status bars) at the top of the window were black instead of gray. I rebooted again and it's gray like it should be. The only reason I mentioned this is because of what we are working on. If it means nothing, just disregard it.

    Anyway, I did a little browsing for testing purposes. I am only seeing the misbehaving progress bar (note the proper terminology) maybe 10% of the time. So, it appears that the scans you are having me do keep reducing the frequency that I am seeing it, it's just not completely going away. It's kind of frustrating, but I'm sure it's probably just another day at the Forum for you.......any ideas?

    Thanks a bunch!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, visit the software forum to further discuss this because as stated, malware is not the cause. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:

    Safe surfing!
     
  16. cj1122

    cj1122 Private E-2

    You guys are awesome. I really appreciate all your help. I hope you have a fabulous day!:-D
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds