redirecting problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by need1, Oct 26, 2013.

  1. need1

    need1 Private E-2

    My daughters laptop is redirecting some of the time. Not sure what triggers it. I have noticed it in firefox. It even happened when i clicked on a majorgeeks download link from the read and run page. It opened a page then mcafee said this is a untrused site. I closed that tab and tried it again with no problem. I have gone through the list of stuff to do. gooredfix refused to work even in safe mode. So here are the logs.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [V2][SUSP PATH] IHUninstallTrackingTASK : CMD - /C DEL C:\windows\TEMP\IHU5791.tmp.exe [x][x] -> FOUND

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Delete this:

    • C:\windows\TEMP\IHU5791.tmp.exe


    The problem is not going to go away for you unless we uninstall firefox.

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except we will be uninstalling with Revo Uninstaller rather than the standard method.) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    -------------------

    Any better now?
     
  3. need1

    need1 Private E-2

    Everything seems to be working. Thanks for taking the time to help me out.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything still okay? Ready for final steps? :)
     
  5. need1

    need1 Private E-2

    Sure thing. Final steps please.

    BTW My Daughter only uses facebook and pogo. So im not sure how she got infected. If you have an idea that would be great. I am assuming she clicks on pics or vids in facebook and somehow accepted this infection. Should I be concerned with either site? She was running mcafee security sweet and had spybot up and running.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Every now and again, a dubious link might be clicked upon causing something like this, but I would not be too concerned. I find the more contacts you have on your facebook, the more likely you are to have these dubious links appear, as what your friends post, appears in your "feed"

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  7. need1

    need1 Private E-2

    Thanks again! Your community service is very much appreciated.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds