Redirect virus...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fhoosa, Dec 13, 2012.

  1. Fhoosa

    Fhoosa Private E-2

    I've DEFINITELY got myself some kind of redirect virus :cry...I ran the TDSKiller and the MBRCheck and have attached the reports...I'll be waiting for your reply...(P.S. I've never posted anything to this site before so PLEASE bare with me...) :wave
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach all the requested logs.
    MBAM
    RogueKiller
    HitmanPro
    C:\MGLogs.zip
     
  3. Fhoosa

    Fhoosa Private E-2

    Here are the reports you requested, except for one...
    I don't mean to sound ignorant, but where would I find the c:MGLogs.zip file...?
    I couldn't find it anywhere... rolleyes
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you were following the Read and Run First instructions, you would have downloaded MGtools and saved it to your root folder. C:\MGTools.exe. Run the exe file and it will produce a log at that location.

    While you are doing that, also run RogueKiller and have it fix these items:

    Then re-run RogueKiller and attach the new log along with the C:\MGLogs.zip.
     
  5. Fhoosa

    Fhoosa Private E-2

    Hi...
    Sorry about the MGTools file...

    Attached you will find both the reports you requested.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not finding much. You need to tell me which browsers are affected.

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!
    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!


    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Again, tell me which browsers are affected.
     
  7. Fhoosa

    Fhoosa Private E-2

    Hey TimW...

    Ok, here's the scoop.

    I received a SUCCESS message. :)

    The browser I'm using is IE9.

    Also, thought I'd let you know that I can't access my g-mail account anymore. When I try to log in, it kicks me out and tells me that Internet Explorer ran into a problem and had to close. It opened up the log in page again, but the same thing happened when I tried it a second, third and fourth time.

    Yesterday morning, the only time it would redirect is when I would click on one of the search hits. Now it's doing it whenever it feels like it.

    I sure hope you can solve this very nasty problem.

    And "THANKS" for all the help you have given me so far.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like you ran Combo a little while back. Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds