Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Download Now:
IE and Firefox redirect - please help
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
IE and Firefox redirect - please help
I have run my McAfee antivirus software several times, no luck. I am including the files indicated in the 8-steps intruction to help me solve this problem. Any help will be greatly appreciated. OS is windows vista sp1.
|
|
#2
|
||||
|
||||
|
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
Make sure, you re-enable your security programs, when you're done with Combofix. DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!! |
|
#3
|
|||
|
|||
|
I can't get past the ComboFix step
I hangs in there on the command window ... attempting to create a new recovery point.... never leaves this point, I have left it for hours. It creates a file/folder ComcobFix similar to the Computer folder that shows all the hard disk drives, network locations.. etc.
Any ideas? Thanks |
|
#4
|
||||
|
||||
|
Delete your Combofix file.
Download fresh one, but rename combofix.exe to broni.exe BEFORE saving it to your desktop. Do NOT run it yet. Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run. There are 4 different versions. If one of them won't run then download and try to run the other one. Vista and Win7 users need to right click Rkill and choose Run as Administrator You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus. * Rkill.com * Rkill.scr * Rkill.pif * Rkill.exe
Once you've gotten one of them to run then try to immediately run the following. Now download and run exeHelper.
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file). Now, run broni.exe |
|
#5
|
|||
|
|||
|
Same issue as before...
I am including the log file you requested, the tools ran just fine, however the ComboFix (renamed) did not go past the opening screen, I left it for one hour, no response. Any further help will be greatly appreciated.
Thanks |
|
|
|
#6
|
||||
|
||||
|
Restart in safe mode and try same three steps.
|
|
#7
|
|||
|
|||
|
I got the log file
Broni, I got the log file while in safe mode. ComboFix restarted the computer as it detected rootkit activiry. Here is the log.
Thanks a lot for your time and help. |
|
#8
|
||||
|
||||
|
Very good
![]() How is redirection? 1. Please open Notepad
2. Now copy/paste the entire content of the codebox below into the Notepad window: Code:
File:: c:\users\jose\AppData\Local\Anizeri.bin c:\users\jose\AppData\Local\Kbizoxiyalogu.dat c:\windows\system32\FBDA04FA5D.sys Folder:: c:\users\jose\AppData\Local\rjyoctpkk Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "GrpConv"=- 3. Save the above as CFScript.txt 4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. ![]() 5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
|
|
#9
|
|||
|
|||
|
Redirection is not occurring anymore... it used to happen right away, neither firefox nor IE are experiencing the problem.... thank you, it was a pain. I will go ahed and follow the next steps.
|
|
#10
|
||||
|
||||
|
Good
![]() Just make sure, you stay with me, because we're not done... |
|
#11
|
|||
|
|||
|
Errors .. See screenshot
I just got this error messages ... are they related to the activity you have indicated?
Should I disable my realtime antivirus software again? Thanks |
|
#12
|
||||
|
||||
|
Yes, you have to disable AV again.
|
|
#13
|
|||
|
|||
|
Latest log
Here is the latest log from the last instructions. Thanks.
|
|
#14
|
||||
|
||||
|
Looks good
![]() Uninstall Combofix: Go Start > Run [Vista users, go Start>"Start search"] Type in: Combofix /Uninstall Note the space between the "Combofix" and the "/Uninstall" Restart computer. ==================================================================== Download OTL to your Desktop. * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. * Under the Custom Scan box paste this in: netsvcs drivers32 /all %SYSTEMDRIVE%\*.* %systemroot%\system32\Spool\prtprocs\w32x86\*.dll %systemroot%\system32\*.wt %systemroot%\system32\*.ruy %systemroot%\Fonts\*.com %systemroot%\Fonts\*.dll %systemroot%\system32\spool\prtprocs\w32x86\*.tmp %systemroot%\*. /mp /s CREATERESTOREPOINT %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\user32.dll /md5 %systemroot%\system32\ws2_32.dll /md5 %systemroot%\system32\ws2help.dll /md5 HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
|
|
#15
|
|||
|
|||
|
OTL log
The file is too big to post ortoo long to include in the reply. Brake it up and post snippets in the reply or breake it up into 2 files and upload the file?
Let me know. Thanks. |
|
#16
|
||||
|
||||
|
It doesn't matter to me. Whatever is easier for you.
|
|
#17
|
|||
|
|||
|
OTL and Extras files
Here are the files. Thanks.
|
|
#18
|
||||
|
||||
|
Update your Java version here: http://www.java.com/en/download/installed.jsp
Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer. Now, we need to remove old Java version and its remnants... Download JavaRa to your desktop and unzip it to its own folder
======================================================================= Run OTL
|
|
#19
|
|||
|
|||
|
Spayware just detected a trojan
It was not there during the last run. So I must be still faily infected. What do you think about this scenario?
Thanks |
|
#20
|
|||
|
|||
|
Second trojan detected...
Second one detected during same run
|
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Search redirect in IE8/Firefox
|
12 | Virus and Malware Removal | ||
Redirect on Firefox
|
52 | Virus and Malware Removal | ||
Firefox redirect problem
|
1 | Software Apps | ||
Firefox redirect
|
1 | Software Apps | ||
Firefox redirect
|
2 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 02:22 PM.





Search redirect in IE8/Firefox