redirection on searches - random pages opening and cannot access windows update

Discussion in 'Malware Help (A Specialist Will Reply)' started by derty, Oct 4, 2010.

  1. derty

    derty Private E-2

    Hey guys thanks for your assistance in advance.

    My issue is similar to a few others here who have been getting redirected searches, new pages opening up in tabs (sometimes with popups) and unable to access windows update page.

    I have gone though the read and run me first page and the XP cleaning program. Following that I can now access the windows update page which is a good start and haven't seen any redirections yet, though that is usually quite sporadic in it's occurrence.

    I have attached the log files as requested.

    A note about the files. When running RootRepeal it crashed 3 times without generating a log file. The fourth time I ran it I limited it to just C: and it completed and generated a log file. The drives that were not included in the forth run were a Vista partition and two file drives that do not contain any installed programs.

    Also I have included two MGTools logs as I initially ran an old version of MGTools (log has suffix 1) and then did what I should have done initially and downloaded the latest version and ran it (log has suffix 2). Apologies if this has complicated anything.
     

    Attached Files:

  2. derty

    derty Private E-2

    here are the MGTools log files - please see previous post for reasons for double files.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you cleaned out your temp internet files? Are you using a router? If you are, does the redirects happen if you are plugged directly into the modem?
     
  4. derty

    derty Private E-2

    I ran CCleaner during the Read and Run Me process and have just checked the firefox cache and the only data there is post CCleaner (I don't use IE). Will CCleaner have totally cleaned out my temporary internet files or is there more one needs to do?

    Yes I am using a router (NB6Plus4W) and this computer is always physically plugged into it. So yes the redirects did occur whilst physically plugged in. Though the redirects have now ceased since completing the Read and Run Me process as far as I can tell.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My question was whether the redirects were happening when you were plugged into your modem. But if you are no longer being redirected, we can do the final cleanup.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  6. derty

    derty Private E-2

    Thanks Again :)

    Apologies if I did not understand the question, though I thought I had answered it for you.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The reason I was asking is that routers can be infected and cause redirects. The way to test for that is to plug into your modem, not your router. If the redirects stopped, then we would want you to reset the router to factory settings.
     
  8. derty

    derty Private E-2

    I see, yes I did confuse the issue and didn't answer the question correctly.

    No I don't have a router, the NB6Plus4W is a modem/router but it is functioning as a modem and I am plugged into it.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thank you for the explanation. That clears it up for me.

    Are you having any issues at this time or is all working properly?
     
  10. derty

    derty Private E-2

    All seems good now, no unusual behaviour at all since I completed the Read & Run Me section. I have completed the clean-up and am a happy camper.

    Thanks again, you guys are legends :cool
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds