Solved IE8 redirect, help needed

Status
Not open for further replies.
Unfortunately, I'm not willing to open .doc files from unknown computers.

After resetting IE, are you still getting redirected?
Point me to some particular ad, where it happens.

Same with Firefox?

Any redirections while using search (bing, or whatever you use)?
 
I'm not sure, if I understand.
First of all, any ad on search engine page will have long address. That's normal.
I'm asking you different question.
Let's say, you have an ad for "Safeway". If you click on that ad, it doesn't go to "Safeway" site?
I don't care, what link properties are.
 
More info

I use bing in IE, but google in IE was failing also
In Firefox I am using google.
Knowing that I have sent you txt files before, I will attach a text file showing the full bad address.

thanks
 

Attachments

  • Address url.txt
    514 bytes · Views: 1
You didn't answer my question...
I'm asking you different question.
Let's say, you have an ad for "Safeway". If you click on that ad, it doesn't go to "Safeway" site?
I don't care, what link properties are.
 
Yes you are correct

If I click on the sponsor target add it may go to the yahoo site or it may go to my bing home page site. If i type in Target.com it will go to the correrct target site.

When I do a simple search the search results I seem to have are showing short url addresses like:
http://www.allelectronics.com/
Only the sponsor add search results have very long url results. In one case the sponsor add and the search results had the same company and looked to have the same WWW address. But the sponsor address failed and the search results went to the correct website.

Hope that answers your question, if not let me know and I will try again.
 
OK, telling the truth, I really care less about ads. They may be incorrectly written, or whatever...
All I care in malware forum is this...
You type in Bing search some word(s), you're looking for.
A list of results are displayed.
When you click on any link from the result list, does it always go to its correct destination?
 
Got to call it a day

Broni need to call it a day, many many thanks for your help.
Will live with the adds being bad.
Hopefully Xmas will bring a new computer and thus correct the memory problem
take care and hope our paths cross again.
 
Before you go anywhere, we still have couple of steps to complete...

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


2. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


3. Go to Kaspersky website and perform an online antivirus scan.

  • Disable your active antivirus program.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
 
Good morning Broni

I think the Kaspersky request has shot me down. The download of the database shows to be a 94741 KB size file. I take this file to be the virus definitions. Would this not require me to have about 95 GB of free hard drive space, which I do not have? Also I tried to download this file but after more than two hours and only 40% downloaded; the internet was slow to respond back to Kaspersky and the download failed. If I am looking at this wrong, please let me know. I could try to do the download tonight when the Internet is faster but need to know if this database file is not going to over fill my hard drive? Will attach the requested txt file.

thanks
 

Attachments

  • checkup.txt
    1 KB · Views: 2
1. Update your Firefox.

2. Update Adobe Reader

You can download it from https://www.techspot.com/downloads/2083-adobe-reader-dc.html
After installing the latest Adobe Reader, uninstall all previous versions.
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or other garbage.

3. Instead of Kaspersky....

Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • IMPORTANT! UN-check Remove found threats
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats
  • Push Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
 
Ran eset scan

After trying twice to run the eset scan, over 3 hours each, I think the instruction on how to run eset might have an error.

* Tick the box next to *YES, I accept the Terms of Use*
* _IMPORTANT!_ UN-check *Remove found threats*
* Click *Start*
* Accept any security warnings from your browser.

Found the "Click Start" above needs to move up one line.
If you hit "start" after you un-check "remove found threats", the scan starts
Thus the attached file does not have "scan archives" in its scan.
If you would like me to run the scan archives I can try to do it tomorrow night.

thanks
 

Attachments

  • eset.txt
    172 bytes · Views: 1
That's fine.....

Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point.

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. Run defrag at your convenience.

11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

12. Please, let me know, how is your computer doing.
 
No end in sight

Well Broni, we have thrown the kitchen sink at this problem and I guess there is no simple solution. Per your last request was trying to run step 6, malwarebytes' update and kept getting the following error: "mbam_err_updating (12007, 0, winhttpsend request)" Did an updated on and ran superantispyware and found no virus. Have open IE and done searches sometimes the results might have one bad results other times it will have many bad results. Ran otl with 360 days files list and attached the txt file. Broni, if you want to drop working on this problem I will understand, you have gone through the virus repair steps many times, thus I will respect your decision.

thanks
 

Attachments

  • OTL.Txt
    147.1 KB · Views: 0
Have open IE and done searches sometimes the results might have one bad results other times it will have many bad results.
What exactly do you mean by "bad results"?
 
Redirects

Bad results are where the search results do not go to the title website. I guess I should have called this a redirect? Title website is the highlited underline line at the first of the search results for that website. We are talking about the main list of search results and not the sponsored links. When I click on the underline title I expect the website to be the www.name.com that is listed on the last line for that search results.
 
Download RootRepeal.zip (Mirror1, Mirror2) and unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:

    • [*]Drivers
      [*]Files
      [*]Processes
      [*]SSDT
      [*]Stealth Objects
      [*]Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan
    Note: The scan can take some time. DO NOT run any other programs while the scan is running
  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
Open RootRepeal.txt file with Notepad, copy, and paste all content into your next reply.

If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.
 
Good news for you; Bad news for me

Well Broni you had hit the nail on the head in thread # 20, and I missed it. I did stick the paper clip into the router but the router did not do as you said "all lights briefly come off and on." Removing the router and going straight to the modem corrected the search redirects. This tells me I have a bad router and will need to replace it. Would guess the reset switch is bad and the router has bad information in it, but as you displayed earlier my computer is now mr. clean. Will try to pick-up another router this weekend or next weekend when we go to town. Thanks for hanging in there with me on this problem.
 
Status
Not open for further replies.
Back