redirected on mozilla/IE alot

Discussion in 'Malware Help (A Specialist Will Reply)' started by ska_t_meladd, Jan 28, 2011.

  1. ska_t_meladd

    ska_t_meladd Private E-2

    any time i click links i am redirected. this started on my netbook a long time ago, just have not used it since. I hope these logs will help in assessing the problem.
     

    Attached Files:

  2. ska_t_meladd

    ska_t_meladd Private E-2

    this has the MGlogs.zip along with tdsskiller log and get goored log as well.
    i hope this help and thank you for your time
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"=""    
    
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"=""    
    
    [HKEY_LOCAL_MACHINE\system\controlset003\services\tcpip\parameters]
    "DhcpNameServer"=""
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  4. ska_t_meladd

    ska_t_meladd Private E-2

    ok did that..
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. That should have taken care of any malware on your system.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
    Last edited: Jan 29, 2011
  6. ska_t_meladd

    ska_t_meladd Private E-2

    I'm sorry, I put in a search to your site from the problem computer and was redirected to some other site. As well I have not been using this browser for anything else but to fix this problem. Once again THANK YOU for your time.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Which browser are you using? If you haven't already uninstalled it, get me a new MGLogs.zip so I can recheck that the DNS infection didn't return.
     
  8. ska_t_meladd

    ska_t_meladd Private E-2

    This instance Mozzilla(wife uses IE(but has not been on this comp lately)).
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"=""    
    
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"=""    
    
    [HKEY_LOCAL_MACHINE\system\controlset003\services\tcpip\parameters]
    "DhcpNameServer"=""
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  10. ska_t_meladd

    ska_t_meladd Private E-2

    When I opened browser a pop-up occurred this time
     
  11. ska_t_meladd

    ska_t_meladd Private E-2

    using mozilla
     
  12. ska_t_meladd

    ska_t_meladd Private E-2

    sorry forgot upload
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, that removed it again, so let's do this:
    let's flush the DNS cache
    • Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Are you still being redirected now?
     
  14. ska_t_meladd

    ska_t_meladd Private E-2

    Yes! I believe this problem has been fixed Thankyou very much!
     
  15. ska_t_meladd

    ska_t_meladd Private E-2

    it was working:( redirect on mozilla till it froze then crashed and would not work till I canceled its process. Of course after i uninstalled both Combo and mglogs!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe file and attach the new log.

    Did you flush the DNS cache?
     
  17. ska_t_meladd

    ska_t_meladd Private E-2

    dns cache flushed here is the zip
     

    Attached Files:

  18. ska_t_meladd

    ska_t_meladd Private E-2

    i'm sorry i loaded getlog.bat . this is the exe. run log. i dont know if they are the same, but i need to follow your directions
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your still having the issue with your DNS settings.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now let's flush the DNS cache again.

    • Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now go to your network connections and right click your internet connection and choose properties. Click on IPV 4 and choose properties again. Make sure that the Obtain DNS automatically is selected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  20. ska_t_meladd

    ska_t_meladd Private E-2

    saved as .reg
    added to reg
    cache flushed
    dns automatic was set
    getlogs.bat runned
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your runkeys log indicates the issue is fixed, but your network log still shows the same DNS settings. When you went into the IPV 4 properties, did you wipe out the settings and then made it as an automatic obtain?

    Have you reset your router to factory settings?
     
  22. ska_t_meladd

    ska_t_meladd Private E-2

    (TCP/IPv4 was not an option. clicked internet protocol properties and those said dns auto. if this is wrong i am a bit lost. i can restore router to factory settings, but have not
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Were there any setting in the DNS settings box? Did you remove them?

    Yes, it would be a good idea to reset the router unless you have other computers that run through this router but are not being redirected.
     
  24. ska_t_meladd

    ska_t_meladd Private E-2

    no settings in the dns box, automatic was already selected. My other comp, which is not wireless has no redirection issues at all.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then it is not your router that is causing this. Are you still being redirected?
     
  26. ska_t_meladd

    ska_t_meladd Private E-2

    mozzilla works but IE is redirecting till it says page cant be displayed very aggessive
     
  27. ska_t_meladd

    ska_t_meladd Private E-2

    completely restored factory settings on router with WPA2 with 26 character key to help perhaps
     
  28. ska_t_meladd

    ska_t_meladd Private E-2

    So.. after I reset router I reflushed cache and run getlogs.batch. and TAH DAH I really think it is now fixed! Here is the zip for you to check out. Does this mean that I have some malware on the other comp!? I'll check and let ya know. BTW if there is some way I can buy ya a beer or make a donation to you for your help i'd like that. SKA_T THANKS YOU!!!
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Very good. Your networking log shows you have a clean DNS setting!!

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds