My parent's laptop is currently experiencing a situation many others have reported. This being that attempting to navigate to results of a search engine query are being redirected various ad sites. It does not matter what search engine is used. On my parent's computer I have seen the redirection with yahoo and google through mozilla.
A search for a fix brings up many varied ideas as to how to fix the issue, so I'm looking for something definitive here as bleeping computer has provided excellent results for me in the past.
I have ran an updated malwarebytes and it turned up nothing.
Page 1 of 1
Search Engine Redirection Malware
#2
Posted 28 February 2011 - 01:55 PM
Before doing anything if you have not already done so, you should back up all your important documents, personal data files and photos to a CD or DVD drive as some infections may render your computer unbootable during or before the disinfection process. The safest practice is not to backup any files with the following file extensions: exe, .scr, .ini, .htm, .html, .php, .asp, .xml, .zip, .rar, .cab as they may be infected.
Please post the results of your last MBAM scan for review (even if nothing was found).
To retrieve the Malwarebytes Anti-Malware scan log information, launch MBAM.
Logs are saved to the following locations:
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7, 2008: C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd
Please download the TDSS Rootkit Removing Tool (TDSSKiller.zip) and save it to your Desktop. <-Important!!!
Be sure to print out and follow all instructions for performing a scan or refer to these instructions with screenshots.
-- If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these instructions. In some cases it may be necessary to redownload TDSSKiller and randomly rename it before downloading and saving to the computer.
-- For any files detected as 'Suspicious' (except those identified as Forged to be cured after reboot) get a second opinion by submitting to Jotti's virusscan or VirusTotal. In the "File to upload & scan" box, browse to the location of the suspicious file and submit (upload) it for scanning/analysis.
- How and Where to backup your files in XP or Vista
- How to Backup and Restore in Windows 7
- How to use Ubuntu Live CD to Backup Files from your dead Windows Computer
Please post the results of your last MBAM scan for review (even if nothing was found).
To retrieve the Malwarebytes Anti-Malware scan log information, launch MBAM.
- Click the Logs Tab at the top.
- The log will be named by the date of scan in the following format: mbam-log-date(time).txt
-- If you have previously used MBAM, there may be several logs showing in the list. - Click on the log name to highlight it.
- Go to the bottom and click on Open.
- The log should automatically open in notepad as a text file.
- Go to Edit and choose Select all.
- Go back to Edit and choose Copy or right-click on the highlighted text and choose Copy from there.
- Come back to this thread, click Add Reply, then right-click and choose Paste.
- Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
Logs are saved to the following locations:
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7, 2008: C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-yyyy-mm-dd
Please download the TDSS Rootkit Removing Tool (TDSSKiller.zip) and save it to your Desktop. <-Important!!!
Be sure to print out and follow all instructions for performing a scan or refer to these instructions with screenshots.
- Extract (unzip) the file to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the Desktop. Vista/Windows 7 users refer to these instructions if you're unsure how to unzip a file.
- If you don't have an extracting program, you can download TDSSKiller.exe and use that instead.
- Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
Vista/Windows 7 users right-click and select Run As Administrator.
- When the program opens, click the Start Scan button.

- Do not use the computer during the scan
- If the scan completes with nothing found, click Close to exit.
- Any objects found, will show in the Scan results - Select action for found objects and offer three options.
- If an infected file is detected, the default action will be Cure...do not change it.

- Click Continue > Reboot now to finish the cleaning process.<- Important!!

- If 'Suspicious' objects are detected, you will be given the option to Skip or Quarantine. Skip will be the default selection. Leave it as such for now.
- A log file named TDSSKiller_version_date_time_log.txt will be created and saved to the root directory (usually Local Disk C:).
- Copy and paste the contents of that file in your next reply.
-- If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these instructions. In some cases it may be necessary to redownload TDSSKiller and randomly rename it before downloading and saving to the computer.
-- For any files detected as 'Suspicious' (except those identified as Forged to be cured after reboot) get a second opinion by submitting to Jotti's virusscan or VirusTotal. In the "File to upload & scan" box, browse to the location of the suspicious file and submit (upload) it for scanning/analysis.
Microsoft MVP - Consumer Security 2007-2012 
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Share this topic:
Page 1 of 1

Help

Back to top









