Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
|
|||||||
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
Browser keeps getting redirected
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Browser keeps getting redirected
I've picked up a nasty somewhere, and no matter how many anti virus/spyware programs i've ran i can't get rid of it.
My browser keeps getting redirected to ad sites. I've checked out my host files and they are clean. I've attatched my hijackthis log in the hopes someone can help me. I see the blatently obvious system32\.exe (file missing) entry, but hijackthis doesn't seem to be able to fix it?! as every time i do a reboot and rescan its still there. hope someone can help! thanks |
|
#2
|
|||
|
|||
|
Hello and welcome to Techspot.
Your system has been hijacked. You shouldn`t try and fix any entries in HJT yourself. Run HJT and click the config button, followed by the backups button. Place a tick in the little box next to all entries and click the restore button and click yes. Reboot your system. [color=red]Very Important:[/color] Before deciding whether you should clean or reformat your system, go and read this thread [color=blue]HERE[/color] and decide what it is you want to do. If after reading the above, you wish to clean your system, do the following. Please download FixWareout from one of these sites: http://downloads.subratam.org/Fixwareout.exe http://www.bleepingcomputer.com/file...Fixwareout.exe Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal. Then, go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly. Post fresh HJT, [color=red]AVG Antispyware[/color] and Combofix logs as attachments into this thread, only after doing the above. Also, attach the C:\fixwareout\report.txt. Also, let me know the results of the AVG Antirootkit scan. Regards Howard ![]() [color=red]This thread is for the use of[/color] kingfu [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.[/color] |
|
#3
|
|||
|
|||
|
thanks for your great info howard_hopkinso
I've attatched the updated logs as requested. I also ran smitfraudfix which found i had been the victim of a dns hijack. hopefully im clean now! |
|
#4
|
|||
|
|||
|
Please post all the requested log files.
Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there). O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE Click on the fix checked button. Close HJT. Locate and delete the following bold files and/or directories(if there). C:\windows\ALCMTR.EXE reboot your system and post a fresh HJT log as well as the AVG and Combofix logs. Let me know the results of the AVG Antirootkit scan. Regards Howard ![]() [color=red]This thread is for the use of[/color] kingfu [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.[/color] |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Google being redirected, webpages being redirected
|
2 | Virus and Malware Removal | ||
Google searches redirected - Browser Hijack
|
4 | Virus and Malware Removal | ||
Browser has been Hijacked? / Google searches being Redirected
|
5 | Virus and Malware Removal | ||
Browser Searches being redirected
|
6 | Virus and Malware Removal | ||
Please help p.c browser redirected, running really slow. (Hijackthis log attached)
|
3 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 09:57 AM.




Google being redirected, webpages being redirected