Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
|
|||||||
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
Google Redirecting Problem
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Google Redirecting Problem
Okay, I'm going to start from the beginning on my computer problem: Saturday night I was having really slow internet problems...No big deal...I shut my computer down and think nothing of it. Sunday morning I turn it on and have commercials playing out of my speakers, and my computer is lagging extremely. I was able to get that problem out of the way by doing a system restore. I think I'm in the clear...I was wrong. I start using my default search engine (Google) and every time I search about 2/3's of the time I am redirected to various "search engines" (I'm not even sure you could call them REAL websites), and have to constantly go back and reclick to attempt to get to the desired website.
So I have tried the 8 steps to the best of my abilities and to no avail am still in the same problematic boat. I have used: Ad-Aware SuperAntiSpyware BlackLight Symantec Antivirus I do not have the log for SuperAntiSpyware, but attached is the HiJackThis log. Thanks for the help! |AA| P.S. I also tried reseting my IE7 browser, and that didn't help. |
|
#2
|
||||
|
||||
|
Sorry,can't do anything with just the HJT log.
You have these on the system. O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Please update each, Mbam first, then SAS. Be sure to check the lone in each to remove what is found. Rescan with HJT.> no removals on this- that's my job. .Put all three logs in the next reply I'll review all three and we'll go from there. |
|
#3
|
|||
|
|||
|
First and foremost, Bobbye, let me thank you for helping me.
Attached are the appropriate logs. I am giving you the Malwarebytes log that I did yesterday AND the one I did this morning (the one this morning didn't pick up anything). Also, another symptom I noticed is if my internet browser is left open for the night (or a prolonged period of time) I have popups similar to the sites I'm being redirected to. Here are the logs. Awaiting orders. |AA| |
|
#4
|
||||
|
||||
|
Okay Alex- I started this last night but had to close up for a storm.
I see this old one is still around: minibugtransporter.dll C:\PROGRAM FILES\AWS\WEATHERBUG\MINIBUGTRANSPORTER.DLL MINIBUGTRANSPORTER.DLL Minibug is an adware that displays ads on to your computer. It seems to be a variant of adware WeatherBug. C:Program Files\AWS\WeatherBug. Weatherbug is installed as a secondary application with many popular pieces of software including AOL Instant Messenger. There was removal in Malwarebytes, but it sounds like you might still have at least part of it installed. I don't see it in the HJT log- did you remove the program? since it is classified as Aware, the removal is optional , but recommended. So let's see what's left: 1. If you have v6, it has it's own uninstaller so use that. If not> Add/Remove Programs: Look for Weatherbug. If seen, highlight and uninstall. 2. To delete the AWS directory
Extra removal instructions for Windows XP 1. Open "MY COMPUTER" icon on your desktop. 2. Double-click the C drive. 3. Double-click on Document and Settings 4. Double-click the folder that has your name next to it (or the name of whomever the machine is registered to) 5. Double-click the “Application Data” folder to open it and delete the folder entitled “WeatherBug”. 7. Restart your computer and the uninstall is complete.[/list] I notice you have nview loading: O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook This is a legitimate program. I just want to make sure you're using it and loading it intentionally as it can cause some problem on the system: rundll32.exe nview.dll, nViewLoadHook Command: Unknown at this time. Description: This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers You need to update the Adobe Reader. You have v6 and it's now up to v9+. The older version presents a vulnerability:
Once you have that all out of the way, please Empty the Recycle Bin then Please download ComboFix HERE:
Notes:
Rescan with HIJT when finished. Attach new log and Combofix report into next reply. Let me know existing system problems when through. |
|
#5
|
|||
|
|||
|
Okay, Bobbye, I *THINK* you may have done it. I did about 10 Google searches and they all came up with the correct URL, and no redirects.
I did have a few issues with the instructions, and just want to run things by you to see if it could be problematic: A) In regards to the WeatherBug issue, there were no folders on my computer that matched that criteria, and it wasn't in the location that you suspected it to be. I cannot recall completely deleting, but I did remove two things when I was playing around with HiJackThis before I posted my problem. I could tell they were both ad/popup type things just by the descriptions. Perhaps its possible WeatherBug was attached to one of those? Or maybe what MalWareBytes picked up were the last of it? Either way I don't think its on my computer. B) In response to the NVIEW file, I do from time to time display my computer on other monitors such as projectors and whatnot for college presentations. I'm not overly sure what you're asking me, but if I'm understanding you correctly, then yes, I am aware of my computer being displayed on other monitors. C) I was unable to disable my Symantec AntiVirus because it is the school's edition, so all the settings where you would typically disable things like Auto-Protect and whatnot are locked out of my control (all the boxes are greyed out and have a small black "lock" next to them). I am not sure how much this would have hindered ComboFix, but I'm sure the log will give you the needed information. Anyway, attached are your requested logs. I think I may be in the clear, and await your orders. Again, thank you for your continued help; I am greatly appreciative. |
|
|
|
#6
|
||||
|
||||
|
My apology- I read your reply but forgot to reply back!
The minibug might be a hidden file- jut give it a quick check: Open Window Explorer (right click on Start> Explore> go to Tools> Folder Options> View tab> Check 'show hidden files and folders'> Uncheck 'hide protected and system files'> Apply> OK Now look for the minibug. Go back and rehide the files when through. Empty the Recycle Bin nView okay. Just wanted to be sure you knew it was running. Please do the following: Run Eset NOD32 Online AntiVirus Scanner HERE Note: You will need to use Internet Explorer for this scan.
|
|
#7
|
|||
|
|||
|
I STILL cannot seem to locate the Weatherbug files. I searched the computer for about 30 minutes and still came up with nothing. I'm guessing from the ESET scan that yes, portions of it are still on my computer.
Here is the log that you requested; it seemed to find some sort of Trojan as well as the what I'm guessing are the Weatherbug files. |AA| |
|
#8
|
||||
|
||||
|
Here are the files we were looking for:
Please download OTMovit by Old Timer and save to your desktop.
--------------------------------------- The AIM install file had Win32/Adware.WBug.A application. The third one is in the Qoobox. This is where Combofix send it's quarantined files. When I have you uninstall Combofix, it will remove the entry. Howe is the system running now? Has the redirect problem been resolved? Run the Eset scan once more to make sure we got all the entries moved. If it's clean, I'll have you remove the cleaning tools and set new clean restore point. |
|
#9
|
|||
|
|||
|
Okay, Bobbye, here are the logs you requested.
The system has been running well. The redirect problems seem to have stopped! |AA| |
|
#10
|
||||
|
||||
|
Looking good! Are you still experiencing the redirect or any related problems? If not, you can remove the cleaning tools and old restore points:
Uninstall ComboFix.exe And all Backups of the files it deleted
If you are prompted to Reboot during the cleanup, select Yes. You should now set a new Restore Point to prevent infection from any previous Restore Points. The easiest and safest way to do this is:
More details and screenshots for Disk Cleanup in Windows Vista can be found here. Please follow these simple steps to keep your computer clean and secure: 1.Disable and Enable System Restore: This will help you to drop the old restore points and set a new, clean one: System Restore Guide 2.Stay current on updates:
3.Make Internet Explorer safer. Follow the suggestions HERE This Tutorial will help guide you through Configuring Security Settings, Managing Active X Controls and other safety features. 4.Remove Temporary Internet Files regularly: Use5. Use an AntiVirus Software(only one)
6.Use a good, bi-directional firewall(one software firewall)[*]See Understanding and Using Firewalls including links to download a firewall. 7.Consider these programs for Extra Security
If I can be of further assistance, please let me know. |
|
#11
|
|||
|
|||
|
I followed your last instructions, Bobbye.
Again, thank you for all your help. I think my computer is even running slightly faster...We probably uncovered something else not even related to the redirect problem. I've been redirect free for a few days now. Awesome! Thanks again! |AA| |
|
#12
|
||||
|
||||
|
You're welcome. Glad to hear the system is running well.
Please let me know if you need help in the future. |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Google redirecting problem
|
0 | Virus and Malware Removal | ||
Google redirecting problem
|
4 | Virus and Malware Removal | ||
Google Redirecting
|
10 | Virus and Malware Removal | ||
Google redirecting DNS problem
|
17 | Virus and Malware Removal | ||
Google Redirecting
|
7 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 02:38 PM.




Google redirecting problem