Webpage redirect, roar.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by DaveLister, May 10, 2007.

  1. DaveLister

    DaveLister Private E-2

    I've been having an issue recently with several websites accessed via FireFox 2.0.0.3 [one of which I require access to for work purposes] seemingly redirected to a classified ads page. I checked the page source and the base href was, in this case, http://www.austco.com/common/roar/landing/rpos/.
    As I write this I can access the page I'm after but the unwanted page has 'come back' before. While performing these scans I was a bit concerned to see the number of 'hits', particularly when running ActiveScan.
    I should note that in the stages requiring the system to be run in safe-mode without networking that I was unable to log on under my main username in Windows 2000 but had to run an account previously used. Additionally for the BitDefender and ActiveScan procedures I was not able to run Internet Explorer [FireFox ran fine] and so had to perform these scans in normal mode.
    Attached logfiles below
     

    Attached Files:

  2. DaveLister

    DaveLister Private E-2

    Followup post for additional log files;
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not sure what you are trying to tell me hear but that full URL is not valid. The www.austco.com is valid and I assume that is the one you want to access. I see nothing in any of your logs that would indicate redirection problems other than the fact that you have a ridiculously large hosts file. Did you use a program to insert lots of stuff into your hosts files. Like MVPS-Hosts or similar. We personally think tools like that are a bad idea since they slow surfing down and they give an easy hiding place for a few malware things to hide. Just think how hard it is to find one or two bad lines in a hosts file that is thousands of lines long. Banning the internet is the wrong approach. Properly protecting your PC to begin with and educating people on good surfing habits is the correct approach. I recommend that you reset your hosts file to Microsoft's default using the below.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    You need to run the scans on the account that is infected. Otherwise things that are unique to the problem account will not be found since the account is not active. Which logs were not obtained from the problem account?

    Other than all the junk in your email folders (which was pointed out by Panda and BitDefender) you are clean. You need to cleanup these email folders and files yourself manually. If anything the scans are pointing at are known to be valid (you are they one that will need to know this), then keep the email.

    Are you still have redirection problems? If so, exactly when and what is the exact site you are being redirected to? Is it only when using FireFox?

    Why do you load explorer at startup?
    O4 - Startup: Windows Explorer.lnk = C:\WINNT\explorer.exe
     
    Last edited: May 14, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I forgot one other thing. You should uninstall the below old Sun Java version since you already have the current version installed:

    J2SE Runtime Environment 5.0 Update 11
     
  5. DaveLister

    DaveLister Private E-2

    The Log not obtained from my account was the AVG anti-spyware scan report.

    What was happening is that I would type in www.austco.com and instead of the expected page I would see a page filled with various advertising links. The href I listed above was what I saw when I looked at the page source.
    I should've taken a screen capture, I have found exactly the type of page referenced on another site. I refer this for the screenshots;
    http://www.revenews.com/samharrelson/2006/12/infected_linux_via_cpa_network.html
    The Screenshots there show the sort of unwanted pages that were loading.
    I had the same 'bad' page loading this morning [about 3 hours ago] but instead of affecting austco.com access it was when I tried to access this forum. That was using Firefox, I tried Internet Explorer and had the same problem. I've now been able to access this forum to look for an update hence my reply here.
    Most of the problem files in the logs I've traced to some old archives on the secondary drive from the previous user. Deleted. Running explorer on startup was another carryover which I didn't consider a problem, removed from startup folder. I missed that Java 11 uninstall, done now.

    This first problem of any kind I've had after a few years of surfing, the main thing I hope to rule out is any PC-side culprits.
    Thanks for the reply.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run HostsXpert to reset your hosts file? If not, please do so now. Then do the below.

    Now run this WareOut Removal and attach the requested log.

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

     
  7. DaveLister

    DaveLister Private E-2

    I have run HostsXpert and restored the hosts file.
    I've performed the WareOut Removal and Blacklight steps, logs attached.
     

    Attached Files:

    Last edited: May 14, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your log from FixWareout, you did not install and run it properly! The log was incomplete and it could not even find one of its own files that is installed when you run the program. Try again. Make sure that you do not allow any antivirus or antispyware program to interfere with the install or running.

    Also do the below!

    Click Start, Run, and enter ipconfig /flushdns and click OK.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Make sure you have only one Internet Explorer brower open.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplore.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
     
  9. DaveLister

    DaveLister Private E-2

    Hmm, I've tried FixWareOut several times, disabling anti-spyware applications beforehand and upon restart I get the same error as per screenshot.
    Process Explorer log included.
    I should note I have not had the problem reoccur so far in the past two days.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto the C:\fixwareout\FindT folder and tell me all the files you see.


    Well that sounds promising!
     
  11. DaveLister

    DaveLister Private E-2

    In C:\fixwareout\findt\ the following files are present;
    dumphive.exe
    FixWareOut.reg
    nircmd.exe
    patterns.txt
    report.txt
    RestartIt.exe
    runback.txt
    runs.txt
    runs.vbs
    setpath.bat
    swreg.exe
    vfind.exe
    XP-2K2.cmd

    I started my browser this morning and this damn page is loading again. The manager noticed this and commented that he's been getting this page come up as well when he accesses some sites. We have a small network with a server running 2003 SBS. I find it rather odd that this is happening intermittently, could there be a problem further down the line from the PCs themselves?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! That looks okay. The only reason I can think of that you cannot run FixWareOut properly is that you may have illegal characters in some of your file or folder names somewhere. This is documented by Microsoft here: http://support.microsoft.com/kb/103368

    I'm not sure the FixWareOut was going to find anything anyway.


    Yes the problem could be at some other point in your network. You may need to cleanup your server and flush the DNS cache there too.

    One other thing that may be interesting to try is:
    • Save your FireFox favorites somewhere to
    • uninstall FireFox
    • reboot
    • delete the C:\Program Files\Mozilla Firefox folder
    • reinstall FireFox
    • see if the problem still occurs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds