Websites in Chrome redirecting

Discussion in 'Malware Help (A Specialist Will Reply)' started by shingdao, Sep 2, 2012.

  1. shingdao

    shingdao Private E-2

    Hello - I have recently started having at least a couple web pages redirect to spam/ad sites in Google Chrome. It doesn't matter if I type the address directly into Chrome's address bar or use google search and go to the link from there. Not all sites are redirected and I note this does not yet appear to be an issue in FF or IE. Before visiting this forum, I did install and ran Kaspersky TDSS killer which found Rootkit.Boot.Wistler.a. I ran the cure and rebooted but at least one webpage continues to redirect. (e.g. If I type Justintv into Chrome's address bar I get redirected to surveyrewardz.org). I then ran MBR.exe per instructions and have attached the logs for both.

    Also, as a secondary and perhaps related issue, I can no longer use a flash drive on this machine. When plugged in they show in Device Manager but do not auto start and when I try to open them, Windows prompts to format the drive. The drives function normally in other machines. When I do run format it says the drive cannot be formatted.

    I have attached the TDSS Killer and the MBR.exe logs

    Thank you in advance for your assistance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. shingdao

    shingdao Private E-2

    OK, I have read and followed all procedures (except for MGTools) in the READ & RUN ME FIRST guide and also followed all the steps for fixing google redirecting/hijacking problems BUT am still having some problems with at least one website redirecting. FYI - I could not access the MGTools download link anywhere on majorgeeks.com as all the links directed me to the following message: "You don't have permission to access /chaslang/files/MGtools.exe on this server" I tried googling it in order to download directly but could not find a reputable site for download and so didn't want to chance it...I note that some sites suggested that MGTools itself was malware, but I'm sure you're aware of this already. I have attached all the relevant and requested logs (save for MGlogs.zip as noted above) per Step 3 in the RUN & READ ME FIRST Procedures. Thanks again for your assistance.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use safe mode with networking to download MGTools.exe and see if that gets around the problem.
     
  5. shingdao

    shingdao Private E-2

    I could not access the internet via safe mode with networking. I suspect because Windows is not managing my connection, that may have something to do with it. I am using Intel ProSet wireless, so perhaps that program is not running in safe mode.

    BTW, since my last post after running all the scans attached, I rebooted my computer and it took 10 min to boot up the first time and was running extremely slow. I restarted and the same thing occurred...10 min boot time and running at a snail's pace. Can't say with 100% certainty that the programs that were executed as part of the malware scanning had anything to do with it, but I did a system restore and things are back to where they were with boot time and system performance.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    See if you can do this then:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. shingdao

    shingdao Private E-2

    Hello - please see requested logs of OTL scan attached.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you uninstall Chrome using Revo Uninstaller anf then reinstall. Let me know if it is ok now.

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.
     
  9. shingdao

    shingdao Private E-2

    OK, I uninstalled Chrome with Revo and the problem still persists :(...although the website I try to go to is now being redirected to a different survey site. Again, so far as I can tell, the redirect only applies to one particular web address. I note that Revo did not prompt me to delete any registry keys after uninstall as is usually the case.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So it os ONLY when you try to access one paticular website that this happens? No strange behaviour otherwise? Let me have the website address?
     
  11. shingdao

    shingdao Private E-2

    Yes, to date only one website that I am aware of redirects. Justintv.com. If I type it directly into Chrome's address bar it will redirect to surveyrewardz.org, but if I search via google and hit the link, Chrome gives me a warning that says you are trying to access a website called a248.e.akamai.net. After flushing my DNS and rebooting my router, I did actually ignore the warning and went to the site and then justin.tv opens OK, although with a red line crossing out the https and a red x through the padlock. I am using the HTTPS Everywhere extension in Chrome and it states that only partial encryption for JustinTV which likely explains the red x and markings over https. I'd be curious to know if any of the scans sent showed any obvious signs of malware?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, they don't. Hmm, I want to know if this happens with other browsers or not.
     
  13. shingdao

    shingdao Private E-2

    Well, I tried both FF and IE and no issues with either one.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, this is a strange one.

    Well I just tried to go there and the site does not exist. Does it actually take you to this website or what? If so screenshot it for me.
     
  15. shingdao

    shingdao Private E-2

    CORRECTION...I just tried typing justintv.com in both FF's and IE's address bars and they BOTH redirected me to the same site! surveyrewardzcentral.org. However, when I google the sites and jump to the URL, unlike in Chrome, they both open fine in FF and IE with no security or certificate warnings.
     
    Last edited by a moderator: Sep 4, 2012
  16. shingdao

    shingdao Private E-2

    I've attached a screenshot of what comes up when I type justintv.com into Chrome's address bar. If you hit the survey start button it prompts you through a series of survey questions and then ends with a selection of prizes to choose that you could win. I didn't go this far into the survey.
     

    Attached Files:

  17. shingdao

    shingdao Private E-2

    BTW: Not sure if you got my corrected update on the issue happening in other browsers. I had originally posted that FF and IE were not having this problem however a subsequent check confirms that both are now redirecting to surveyrewardz.org when typing justintv.com directly into the address bar, however when using google search and jumping to the URL, the site opens without incident or warning on both FF and IE.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm getting warnings from firefox now when i type in justintv.com
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So... in conclusion, I would say that justintv.com have a problem, not us. As long as you are not being redirected in any OTHER ways when surfing normally?
     
  20. shingdao

    shingdao Private E-2

    So far, I'm not noticing any other surfing anomalies. It may very well be a JustinTV issue. In any event, its good to know it is not malware. Thanks for your help!
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. At first I was able to get to the proper justintv site but then when I tried again I was given a warning by my browser or some add on I have, and I got redirected to the same site as you described. Yea, I think we can safely say they got done over. Stay away from the site and use something else.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds