google redirecting links and pop ups Malware logs
#16
Posted 09 April 2011 - 10:46 PM
This DNS - 93.188.166.105 is what is causing the redirects and needs to be changed
How have you been resetting the router?
Gringo
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.
#17
Posted 09 April 2011 - 10:48 PM
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.
#18
Posted 10 April 2011 - 07:03 PM
#19
Posted 10 April 2011 - 07:25 PM
I wopuld like you to set the dns on the router to open DNS - you can see how to do this here just pick the name of your router - https://store.opendns.com/setup/router/
Gringo
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.
#20
Posted 12 April 2011 - 10:42 PM
#21
Posted 12 April 2011 - 11:46 PM
Create and Run Batch File
- Open Notepad and copy/paste the entire contents of the codebox below, into Notepad:
@echo off >Log1.txt ( ipconfig /all nslookup google.com nslookup yahoo.com ping -n 2 google.com ping -n 2 yahoo.com route print ) start Log1.txt del %0
- Save this as router.bat Choose to Save type as - All Files and where to save - Desktop - then close the Notepad file.
It should look like this:
Double-click on router.bat to run it. it will open notepad when done please post back the results
gringo
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.
#22
Posted 16 April 2011 - 02:55 AM
48 Hour bump
It has been more than 48 hours since my last post.
- do you still need help with this?
- do you need more time?
- are you having problems following my instructions?
- if after 48hrs you have not replied to this thread then it will have to be closed!
Gringo
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.
#23
Posted 16 April 2011 - 11:57 AM
#24
Posted 16 April 2011 - 11:59 AM
Host Name . . . . . . . . . . . . : Michael-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : domain.actdsltmp
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : domain.actdsltmp
Description . . . . . . . . . . . : Intel® 82566DC-2 Gigabit Network Connection
Physical Address. . . . . . . . . : 00-1B-FC-B4-5F-45
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::8533:9342:83df:3867%8(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.101(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Saturday, April 16, 2011 9:55:24 AM
Lease Expires . . . . . . . . . . : Sunday, April 17, 2011 9:55:40 AM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 201333756
DNS Servers . . . . . . . . . . . : 93.188.166.105
93.188.161.105
1.2.3.4
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Local Area Connection* 6:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:2491:2a02:3f57:fe9a(Preferred)
Link-local IPv6 Address . . . . . : fe80::2491:2a02:3f57:fe9a%9(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter Local Area Connection* 7:
Connection-specific DNS Suffix . : domain.actdsltmp
Description . . . . . . . . . . . : isatap.domain.actdsltmp
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::5efe:192.168.1.101%11(Preferred)
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 93.188.166.105
93.188.161.105
1.2.3.4
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter Local Area Connection* 10:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : 6TO4 Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: 93.188.166.105.static.ukrtelegroup.com.ua
Address: 93.188.166.105:53
Name: google.com
Addresses: 74.125.226.179, 74.125.226.176, 74.125.226.180, 74.125.226.178
74.125.226.177
Server: 93.188.166.105.static.ukrtelegroup.com.ua
Address: 93.188.166.105:53
Name: yahoo.com
Addresses: 209.191.122.70, 67.195.160.76, 72.30.2.43, 69.147.125.65
98.137.149.56
Pinging google.com [74.125.226.113] with 32 bytes of data:
Reply from 74.125.226.113: bytes=32 time=125ms TTL=55
Reply from 74.125.226.113: bytes=32 time=120ms TTL=55
Ping statistics for 74.125.226.113:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 120ms, Maximum = 125ms, Average = 122ms
Pinging yahoo.com [209.191.122.70] with 32 bytes of data:
Reply from 209.191.122.70: bytes=32 time=136ms TTL=52
Reply from 209.191.122.70: bytes=32 time=136ms TTL=53
Ping statistics for 209.191.122.70:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 136ms, Maximum = 136ms, Average = 136ms
===========================================================================
Interface List
8 ...00 1b fc b4 5f 45 ...... Intel® 82566DC-2 Gigabit Network Connection
1 ........................... Software Loopback Interface 1
9 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
11 ...00 00 00 00 00 00 00 e0 isatap.domain.actdsltmp
10 ...00 00 00 00 00 00 00 e0 6TO4 Adapter
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.101 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.101 276
192.168.1.101 255.255.255.255 On-link 192.168.1.101 276
192.168.1.255 255.255.255.255 On-link 192.168.1.101 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.101 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.101 276
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
9 18 ::/0 On-link
1 306 ::1/128 On-link
9 18 2001::/32 On-link
9 266 2001:0:4137:9e76:2491:2a02:3f57:fe9a/128
On-link
8 276 fe80::/64 On-link
9 266 fe80::/64 On-link
11 281 fe80::5efe:192.168.1.101/128
On-link
9 266 fe80::2491:2a02:3f57:fe9a/128
On-link
8 276 fe80::8533:9342:83df:3867/128
On-link
1 306 ff00::/8 On-link
9 266 ff00::/8 On-link
8 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
#25
Posted 16 April 2011 - 12:19 PM
Yes it looks like the DNS settings on the router have been changed.
Resetting Router
Let’s try to reset the router to its default configuration.
- This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
- Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
- If you don’t know the router's default password, you can look it up. Here
- You also need to reconfigure any security settings you had in place prior to the reset.
- You may also need to consult with your Internet service provider to find out which DNS servers your network should be using or you can use OpenDNS
Note: After resetting your router, it is important to set a non-default password, and if possible, username, on the router. This will assist in eliminating the possibility of the router being hijacked again.
flush the DNS:
Now lets flush the DNS on the computer:
- click on Start
- select run
- enter cmd and hit enter
- a black window will open.
- please enter the following text into that window and hit enter:
- ipconfig /flushdns
Now lets check the router again
Create and Run Batch File
- Open Notepad and copy/paste the entire contents of the codebox below, into Notepad:
@echo off >Log1.txt ( ipconfig /all nslookup google.com nslookup yahoo.com ping -n 2 google.com ping -n 2 yahoo.com route print ) start Log1.txt del %0
- Save this as router.bat Choose to Save type as - All Files and where to save - Desktop - then close the Notepad file.
It should look like this:
Double-click on router.bat to run it. it will open notepad when done please post back the results
gringo
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.
#26
Posted 19 April 2011 - 12:41 PM
48 Hour bump
It has been more than 48 hours since my last post.
- do you still need help with this?
- do you need more time?
- are you having problems following my instructions?
- if after 48hrs you have not replied to this thread then it will have to be closed!
Gringo
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.
#27
Posted 22 April 2011 - 02:39 AM
In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->
<-- Don't worry every little bit helps.

Help
This topic is locked


Back to top








