Redirects are random

Discussion in 'Malware Help (A Specialist Will Reply)' started by kman949, Dec 28, 2012.

  1. kman949

    kman949 Private E-2

    Redirects (Firefox and Explorer) only occur on search result clicks, pasting the URL finds the correct site. Have run TDSSkiller, CCleaner, and went through a number of Youtube fixes with nothing found. Followed specific guide for XP OS. Found a few issues with Roguekiller and MBRCheck, also attached report for Hitman Pro. Appreciate any help members can provide.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach the logs from running:

    • Malware Bytes
    • MGTools

    Thanks. :)
     
  3. kman949

    kman949 Private E-2

    requested zip and log attached, thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:

    [HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.


    Run this and attach the results.

    Using ESET's Online Scanner

    Any better?
     
  5. kman949

    kman949 Private E-2

    Attached the reports after running the programs you noted, ran a few searches on firefox and explorer and did not have any redirects, have not rebooted but will after posting this. Were the ESET threats benign? Any other concerns? Can I go back to custom startup or should I stay in normal? My sincere thanks for your help, I would certainly recommend Majorgeeks to others.
     

    Attached Files:

  6. kman949

    kman949 Private E-2

    Unfortunately, after reboot the redirects are still appearing in firefox, most frequent is the "click.livesearch.now" appears briefly followed by the fake but real looking site
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Delete this: C:\WINDOWS\tasks\tuwgxl.job

    We are going to be uninstalling your old version of FireFox (Except please use Revo Uninstaller to uninstall) and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Any better?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds