TechSpot

Browser redirecting trojan -- Help, please! -- Thanks

By paulmab
Jun 30, 2009
  1. I have a problem. I did all the steps, and there are the logs. Thanks in advance!
     

    Attached Files:

  2. tystanwick

    tystanwick TS Rookie Posts: 29

    Mainly going by the MBAM log, it looks like a rootkit. Please follow these directions for use of combofix.

    Download here:

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    or here:
    http://www.forospyware.com/sUBs/ComboFix.exe

    When saving combofix to your PC, rename it to 123.com so malware won't disable it. Launch combofix (now titled 123.com), allow it to download and install the Recovery Console if it prompts you. Once the scan starts, DO NOT TOUCH YOUR PC, clicking anywhere while combofix is running is enough to make your system become non-responsive. Be forewarned that combofix will make your desktop dissapear and will also reboot your PC as needed. This is normal.

    Once combofix has run, run MBAM again as well as HJT.

    Post logs when done please.
     
  3. paulmab

    paulmab TS Rookie Topic Starter

    Here you go!

    Here are the logs.
     
  4. tystanwick

    tystanwick TS Rookie Posts: 29

    Looks like combofix did the trick. Are you still being redirected?

    One last thing to do is, make sure you remove one of those anti-virus programs. You don't want to get a BSOD because of it.

    I would keep AVG and lose ParetoLogic.
     
  5. paulmab

    paulmab TS Rookie Topic Starter

    Thanks! The redirecting is fixed.

    However, there are some words in webpages that still have a little box pop up when I rollover them. Does that mean anything?
     
  6. tystanwick

    tystanwick TS Rookie Posts: 29

    Nope, those are usually just ads that help cover the costs of running particular web pages.
     
  7. Drigo

    Drigo TS Rookie

    I dont know how to start a new thread but here are my files and I have the same problem of redirection.
     
  8. paulmab

    paulmab TS Rookie Topic Starter

    Okay, thank you very much for helping me! :D
     
  9. tystanwick

    tystanwick TS Rookie Posts: 29


    Going by your SAS scan, it would appear that you have a rootkit very similar to the one we just fixed. Please follow the ComboFix directions from my post above.

    Once done please post new MBAM, HJT, SAS and ComboFix logs.
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.