TechSpot

IE Redirects search pages virus?

By Gozal
Oct 19, 2009
  1. Hi, when ever i use google my searches get redircted to some blank site, I did a hijackthis and here is my log
     
  2. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

  3. Gozal

    Gozal TS Rookie Topic Starter

    that thread is closed i cant attach my log there,
     
  4. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

    Follow the instructions posted there and post the logs here after you complete the steps
     
  5. Gozal

    Gozal TS Rookie Topic Starter

    i completed all 8 steps and here are 2 logs, i didnt post the malwarebyte log cause it came up clean
     
  6. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

    So are you still redirecting?
     
  7. Gozal

    Gozal TS Rookie Topic Starter

    yes i am still redirecting
     
  8. Gozal

    Gozal TS Rookie Topic Starter

    here is my updated hijackthis log
     
  9. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

    So the Malwarebytes log caught something this time. So are you still redirecting now?
     
  10. Gozal

    Gozal TS Rookie Topic Starter

    yes i am still redirecting
     
  11. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

    You have some serious infections that may take more actions to get rid of the problem for good
     
  12. momok

    momok TS Rookie Posts: 2,265

    You've got to fix these entries in HJT:

    O4 - HKLM\..\Run: [NI.UWAS5LP_0001_0811] "C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\0TUFO5QF\WAS5Scan[1].exe"
    O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnappm.exe
    O18 - Filter hijack: text/html - (no CLSID) - (no file)

    Your mbam log shows an entry to "delete on reboot". Have you reboot your system? If not, please do so and post a fresh log.
     
  13. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

    Thanks momok for helping me out here. I saw these entries, but I wasn't sure what to tell Gozal. I was out of ideas
     
  14. momok

    momok TS Rookie Posts: 2,265

    Hi Gozal, just realised theres an entry of "Rootkit.TDSS" in your mbam log.

    Please download Combofix from HERE and save to your desktop.

    Run it and post back with the log from C:\combofix.txt
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...