Redirects and Framer.S

Status
Not open for further replies.
I am getting redirects on a number of sites and avg is also saying that i have a HTML/Framer.S virus.Have run Spybot S&D and Malwarebytes but am still getting the same problems.The redirects are with both Firefox and IE7.
 
Welcome to TS. Having said that -This is perplexing.

This is an unknown - often associated with LOP hacks. Can causes your symptoms.
User choice. HJT, Fix-Check removes this entry
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE0F8ABB-D3F5-4048-B147-AC03D308B2BC}: NameServer = 83.146.21.6,212.158.249.5
212.158.249.5………blacklisted by only 3 lists

What info do you have about these IPs?
83.146.21.6 Bulldog, Cable and Wireless Access Ltd
212.158.249.5, Bulldog Communications Ltd., London

MBAB & SAS posted & clean. Is there a recent history of infections reported by these tools?

Assessment - Fix-Check the O17 findings.
 
What info do you have about these IPs?
83.146.21.6 Bulldog, Cable and Wireless Access Ltd
212.158.249.5, Bulldog Communications Ltd., London

Bulldog was my old ISP.HAven't been with them now for nearly 6 months.Should i just delete this ?
 
Yes, that was my meaning.

Run HJT, apply checks against O17 entries. Click Fix.

Restart the computer,

Re-run HJT. Post back results.

Monitor for improvements. (hope)


P.S. I am usually cryptic when I use my 'express' notation. I am a lazy person.
 
The logs are clear. Resume happy computing.

I infer that the O17 findings were present & corrected with HJT.

They were the most likely cause of the symptoms. Report if problems persist.

Two cautions.
SweetIM is regarded as QUESTIONABLE. User judgement.

AVG & ZA (your protections) should be sufficient. One post reports that AVG caught a threat (macromed\Flash).
Source is unknown. Downloaded program files are always risky.
Be cautious. Especially when offered udates to working programs or plugins.

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - hxxps://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
 
Thanks for your reply.Computer runs better now.Applied all ticks to O16 & O17 entries.Also removed sweetim entries and deleted it from the system.

Thank you for your help!!:D
 
Status
Not open for further replies.
Back