Help - Search - Members - Calendar
Full Version: I am infected with redirects and popups.
BleepingComputer.com > Security > Am I infected? What do I do?
   
yamahonduki
hi, i have internet explorer 6 on my pc, and i also have mozilla firefox.
my IE6 seemed to have some kind of hijacker/redirecter attatched to it, and as a consequence i could not go to the sites that i wanted to.
instead it sent me to a wonderfull array of financialy oriented sites, offering me loans and extortionate rates of interest.
i tried everything i had in my antivirus arsenal, to no avail.
i tried, webroot spysweeper, adaware, spybot, asquared, and kaspersky av pro, to no avail.
i even tried using the search assistant to locate files on my pc which matched the names of the offending sites i was sent to, and as fast as i was deleting all their components, they were returning with new urls for me to visit.
so i downloaded mozilla firefox, which works okay.
what i need to know is,, can i remove IE6 from my pc, and if i do, will it remove the offending nasty with it?
and if i can, and it does, can i then reinstall a new IE6, and will it be clean?
thanks for any help.

yamahonduki, steve. thumbup.gif
quietman7
I suggest you read and follow all instructions in the pinned topic titled Preparation Guide For Use Before Posting A Hijackthis Log.

When you have done that, post a log in the HijackThis Logs and Analysis Forum, not here, for assistance by the HJT Team Experts.

It may take a while to get a response because the HJT Team members are very busy. Please be patient as they are volunteers who will help you out as soon as possible. Once you have made your post, please DO NOT make another reply until it has been responded to by a member of the HJT Team. Generally the staff checks the forum for postings that have not been replied as this makes it easier for them to identify those who have not been helped. If you post another response, a team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond.
yamahonduki
hi.

i feel like a bit of a fraud.
i seem to have sorted out my problem now.
seems like i had something called "winbrume.dll" in my system32 files.
once i isolated it, it was just a matter of changing the permissions.
after that, i simply erased it all with my eraser.
then i ran another hijack this scan, and low and behold, it said the file was missing thumbup.gif
just to be sure, i ran several search assistant searches, and they came up as no results found.
by IE6 is working fine again now and the wife can surf her auction sites again wink.gif

i will just add that i did this fix myself, and i would warn others that eraser is a dangerous program in the wrong hands.

also, i hope i havent caused anybody any unnessassary work in trying to research my problem.

steve.
quietman7
winbrume.dll is a variant of the Dropper.GF trojan which is a browser hijacker. Glad to hear you were able to resolve the problem.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.