BleepingComputer.com: Website being redirected

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Website being redirected Cant access site, it gets redirected

#16 User is offline   ester.cu 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 29-June 11
  • Gender:Female
  • Location:Costa Rica

Posted 30 June 2011 - 12:03 AM


#17 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 30 June 2011 - 12:06 AM

@ Parskahyes
Please, do NOT hijack someone else topic.
Create your own topic.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#18 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 30 June 2011 - 12:07 AM

MiniToolBox by Farbar
Ran by Administrador (administrator) on 29-06-2011 at 22:41:48
Microsoft Windows XP Service Pack 3 (X86)

***************************************************************************


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= End of IE Proxy Settings ========================
=============== Hosts content: ============================================

# Copyright © 1993-1999 Microsoft Corp.
#
# Éste es un ejemplo de archivo HOSTS usado por Microsoft TCP/IP para Windows.
#
# Este archivo contiene las asignaciones de las direcciones IP a los nombres de
# host. Cada entrada debe permanecer en una línea individual. La dirección IP
# debe ponerse en la primera columna, seguida del nombre de host correspondiente.
# La dirección IP y el nombre de host deben separarse con al menos un espacio.
#
#
# También pueden insertarse comentarios (como éste) en líneas individuales
# o a continuación del nombre de equipo indicándolos con el símbolo "#"
#
# Por ejemplo:
#
# 102.54.94.97 rhino.acme.com # servidor origen
# 38.25.63.10 x.acme.com # host cliente x

127.0.0.1 localhost
# Start of entries inserted by Spybot - Search & Destroy
127.0.0.1 [omitted]
# This list is Copyright 2000-2008 Safer Networking Limited
# End of entries inserted by Spybot - Search & Destroy

=============== End of Hosts ==============================================

================= IP Configuration: =======================================

# ---------------------------------------------
# Configuraci¢n de la interfaz IP
# ---------------------------------------------
pushd interface ip


# Configuraci¢n de la interfaz IP para "Conexi¢n de rea local"

set address name="Conexi¢n de rea local" source=dhcp
set dns name="Conexi¢n de rea local" source=dhcp register=PRIMARY
set wins name="Conexi¢n de rea local" source=dhcp

# Configuraci¢n de la interfaz IP para "Conexi¢n de red inal mbrica"

set address name="Conexi¢n de red inal mbrica" source=dhcp
set dns name="Conexi¢n de red inal mbrica" source=dhcp register=PRIMARY
set wins name="Conexi¢n de red inal mbrica" source=dhcp


popd
# Fin de la configuraci¢n de la interfaz IP




Configuración IP de Windows



Nombre del host . . . . . . . . . : ASUS

Sufijo DNS principal . . . . . . :

Tipo de nodo. . . . . . . . . . . : híbrido

Enrutamiento habilitado. . . . . .: No

Proxy WINS habilitado. . . . . : No



Adaptador Ethernet Conexión de área local :



Estado de los medios. . . .: medios desconectados

Descripción. . . . . . . . . . . : Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller

Dirección física. . . . . . . . . : 00-24-8C-03-E1-E9



Adaptador Ethernet Conexión de red inalámbrica :



Sufijo de conexión específica DNS :

Descripción. . . . . . . . . . . : 802.11n Wireless LAN Card

Dirección física. . . . . . . . . : 00-22-43-5F-3B-CC

DHCP habilitado. . . . . . . . . : No

Autoconfiguración habilitada. . . : Sí

Dirección IP. . . . . . . . . . . : 192.168.0.102

Máscara de subred . . . . . . . . : 255.255.255.0

Puerta de enlace predeterminada : 192.168.0.1

Servidor DHCP . . . . . . . . . . : 192.168.0.1

Servidores DNS . . . . . . . . . .: 192.168.0.1

Concesión obtenida . . . . . . . : miércoles, 29 de junio de 2011 20:49:26

Concesión expira . . . . . . . . .: miércoles, 06 de julio de 2011 20:49:26

Servidor: UnKnown
Address: 192.168.0.1

Nombre: google.com
Addresses: 74.125.229.113, 74.125.229.114, 74.125.229.115, 74.125.229.116
74.125.229.112



Haciendo ping a google.com [74.125.229.112] con 32 bytes de datos:



Respuesta desde 74.125.229.112: bytes=32 tiempo=818ms TTL=55

Respuesta desde 74.125.229.112: bytes=32 tiempo=2258ms TTL=55



Estad¡sticas de ping para 74.125.229.112:

Paquetes: enviados = 2, recibidos = 2, perdidos = 0

(0% perdidos),

Tiempos aproximados de ida y vuelta en milisegundos:

M¡nimo = 818ms, M ximo = 2258ms, Media = 1538ms

Servidor: UnKnown
Address: 192.168.0.1

Nombre: yahoo.com
Addresses: 72.30.2.43, 98.137.149.56, 209.191.122.70, 67.195.160.76
69.147.125.65



Haciendo ping a yahoo.com [69.147.125.65] con 32 bytes de datos:



Respuesta desde 69.147.125.65: bytes=32 tiempo=323ms TTL=51

Respuesta desde 69.147.125.65: bytes=32 tiempo=288ms TTL=51



Estad¡sticas de ping para 69.147.125.65:

Paquetes: enviados = 2, recibidos = 2, perdidos = 0

(0% perdidos),

Tiempos aproximados de ida y vuelta en milisegundos:

M¡nimo = 288ms, M ximo = 323ms, Media = 305ms



Haciendo ping a 127.0.0.1 con 32 bytes de datos:



Respuesta desde 127.0.0.1: bytes=32 tiempo<1m TTL=128

Respuesta desde 127.0.0.1: bytes=32 tiempo<1m TTL=128



Estad¡sticas de ping para 127.0.0.1:

Paquetes: enviados = 2, recibidos = 2, perdidos = 0

(0% perdidos),

Tiempos aproximados de ida y vuelta en milisegundos:

M¡nimo = 0ms, M ximo = 0ms, Media = 0ms

===========================================================================
ILista de interfaces
0x1 ........................... MS TCP Loopback interface
0x2 ...00 24 8c 03 e1 e9 ...... Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller - Minipuerto del administrador de paquetes
0x3 ...00 22 43 5f 3b cc ...... 802.11n Wireless LAN Card - Minipuerto del administrador de paquetes
===========================================================================
===========================================================================
Rutas activas:
Destino de red M scara de red Puerta de acceso Interfaz M‚trica
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.102 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.0.0 255.255.255.0 192.168.0.102 192.168.0.102 25
192.168.0.102 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.0.255 255.255.255.255 192.168.0.102 192.168.0.102 25
224.0.0.0 240.0.0.0 192.168.0.102 192.168.0.102 25
255.255.255.255 255.255.255.255 192.168.0.102 192.168.0.102 1
255.255.255.255 255.255.255.255 192.168.0.102 2 1
Puerta de enlace predeterminada: 192.168.0.1
===========================================================================
Rutas persistentes:
ninguno

================= End of IP Configuration =================================

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/07/2011 05:04:12 PM) (Source: Application Error) (User: )
Description: Aplicación con errores: skype.exe, versión: 5.3.0.111, módulo con error: , versión 0.0.0.0, dirección de error 0x00000000.
Procesando suceso específico de medio para [skype.exe!ws!]

Error: (06/02/2011 09:24:49 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 36875391

Error: (06/02/2011 09:24:49 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 36875391

Error: (06/02/2011 09:24:49 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/01/2011 11:10:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 43688

Error: (06/01/2011 11:10:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 43688

Error: (06/01/2011 11:10:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/01/2011 11:10:56 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 41688

Error: (06/01/2011 11:10:56 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 41688

Error: (06/01/2011 11:10:56 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (06/29/2011 03:58:30 PM) (Source: 0) (User: )
Description: 0xC0000243## aswSnx private storageHardd .. lume1

Error: (06/28/2011 10:55:50 PM) (Source: System Error) (User: )
Description: Código de error 1000008e, parámetro 1 c0000046, parámetro 2 804fc8f5, parámetro 3 a9ddb6b0, parámetro 4 00000000.

Error: (06/27/2011 09:56:10 PM) (Source: Service Control Manager) (User: )
Description: Intervalo de espera (30000 ms.) para la respuesta de transacción del servicio Dnscache.

Error: (06/27/2011 01:08:37 PM) (Source: Service Control Manager) (User: )
Description: Intervalo de espera (30000 ms.) para la respuesta de transacción del servicio Dnscache.

Error: (06/27/2011 01:08:07 PM) (Source: Service Control Manager) (User: )
Description: Intervalo de espera (30000 ms.) para la respuesta de transacción del servicio Dnscache.

Error: (06/27/2011 01:07:18 PM) (Source: Service Control Manager) (User: )
Description: Intervalo de espera (30000 ms.) para la respuesta de transacción del servicio Dnscache.

Error: (06/25/2011 07:31:22 PM) (Source: Service Control Manager) (User: )
Description: Intervalo de espera (30000 ms.) para la respuesta de transacción del servicio Dnscache.

Error: (06/25/2011 07:14:48 PM) (Source: Service Control Manager) (User: )
Description: Intervalo de espera (30000 ms.) para la respuesta de transacción del servicio Dnscache.

Error: (06/24/2011 10:43:34 PM) (Source: 0) (User: )
Description: 192.168.0.102D8:A2:5E:5A:B3:F1

Error: (06/24/2011 10:43:34 PM) (Source: 0) (User: )
Description: 192.168.0.102D8:A2:5E:5A:B3:F1


Microsoft Office Sessions:
=========================

========================= End of Event log errors =========================

========================= Memory info: ====================================

Percentage of memory in use: 68%
Total physical RAM: 1015.17 MB
Available physical RAM: 315.21 MB
Total Pagefile: 2442.34 MB
Available Pagefile: 1878.66 MB
Total Virtual: 2047.88 MB
Available Virtual: 1992.65 MB

======================= Partitions: =======================================

1 Drive c: () (Fixed) (Total:149.04 GB) (Free:110.21 GB) NTFS

================= Users: ==================================================

Cuentas de usuario de \\ASUS

-------------------------------------------------------------------------------
Administrador Asistente de ayuda ASPNET
Invitado SUPPORT_388945a0
Se ha completado el comando correctamente.

================= End of Users ============================================
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#19 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 30 June 2011 - 12:09 AM

@ ester.cu

Go Start>Run (Start search in Vista), type in:
cmd
Click OK (in Vista and Windows 7, while holding CTRL, and SHIFT, press Enter).

In Command Prompt window, type in following commands, and hit Enter after each one:
ipconfig /flushdns
ipconfig /registerdns
ipconfig /release
ipconfig /renew
net stop "dns client"
net start "dns client"


Turn the computer off.

On your router, you'll find a pinhole marked "Reset".
Keep pushing the hole, using a pencil, or a paperclip until all lights briefly come off and on.
NOTE. Simple router disconnecting from a power source will NOT do.
Restart computer and check for redirections.

NOTE. You may need to re-check your router security settings, as described HERE
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#20 User is offline   ester.cu 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 29-June 11
  • Gender:Female
  • Location:Costa Rica

Posted 30 June 2011 - 12:34 AM

havent turned the computer off yet just wanna make sure its right before... on the command window it says succesful after flush dns, then after register dns it says that the register has started but then after release it says it cant be done while being disconnected, same after renew.. then after net stop it says the specified service doesnt exist as installed service and after net start it says the service's name is not valid, you can get more help with the NET HELPMSG 2185 command... is that supposed to be like that?

#21 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 30 June 2011 - 08:10 PM

Go on with resetting a router itself.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#22 User is offline   ester.cu 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 29-June 11
  • Gender:Female
  • Location:Costa Rica

Posted 02 July 2011 - 02:51 PM

it's still being redirected :(

#23 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 02 July 2011 - 05:40 PM

At this point....

With the information you have provided I believe you will need help from the malware removal team. I would like you to start a new thread and post a DDS log HERE and include a link to this thread. Please make sure that you read the information about getting started before you start your thread.

It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal. Good luck and be patient. Help is on the way!
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#24 User is offline   swagger 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 457
  • Joined: 06-December 06
  • Gender:Male
  • Location:South Carolina

Posted 02 July 2011 - 08:50 PM

Parskahyes,

If you believe that you are having virus or malware-related issues, please create your own thread so a helper can assist you and you only. Each computer is different so each fix might be different. This will allow the helpers to help you more accurately.

Regards,
Keith

#25 User is offline   ester.cu 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 29-June 11
  • Gender:Female
  • Location:Costa Rica

Posted 12 July 2011 - 05:59 PM

Hi sorry it has taken me so long, i was bummed about it not working and i have been really busy.
A few days ago it kinda started happening also on hotmail, it would go in and i could see my inbox but i couldn't access each email itself and msn wouldn't log in.. Today i clicked on an link to twitter cause i kinda forgot about it and it worked! I was surprised so i check both hotmail and msn and they work too! I don't really know what happened or if something else is wrong and i haven't noticed yet but well.. it's working. If anything happens i will come back for sure and continue with your advice on contacting that team. Thanks a lot for your help!! Best regards :)

#26 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 12 July 2011 - 08:32 PM

Good news :)

I want you to run couple more steps...

Download Temp File Cleaner (TFC)
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.

=============================================================================

Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#27 User is offline   ester.cu 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 29-June 11
  • Gender:Female
  • Location:Costa Rica

Posted 12 July 2011 - 11:18 PM

Bad news... it didn't last for long :( for like 2-3 hours or so everything worked, then all of the sudden NOTHING worked! msn, hotmail, facebook or twitter.. but again after a while fb worked.. the issue is still going on with twitter, msn and hotmail in my household's computers, i guess i'll have to contact that team..
I did what you told me, you didn't say if i had to uncheck the option to remove found threats, i left it checked and checked scan archives, when it finished it didn't give the option to list found threats and it just said no threats found.

#28 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 12 July 2011 - 11:22 PM

Well again....

With the information you have provided I believe you will need help from the malware removal team.
Please make sure that you read the information about getting started first.
Then start a new thread HERE and include or required logs.
Including a link to this thread will be helpful.

Good luck and be patient. Help is on the way!
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users