BleepingComputer.com: Browser redirect, Windows Explore error

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 6 Pages +
  • « First
  • 4
  • 5
  • 6
  • You cannot start a new topic
  • This topic is locked

Browser redirect, Windows Explore error Several viruses & malware issues along with speed deterioration

#76 User is offline   Martin C 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 48
  • Joined: 01-January 12

Posted 11 January 2012 - 06:32 PM

Good question. I know the sound drivers all worked prior to the cleaning, but can't be precisely certain it wasn't the malware. It's a Dell Latitude D610.

What did you think of all the Trojan virus threads found?

Also, AVG and Malwarebytes is a good security combination?

#77 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,527
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 11 January 2012 - 07:35 PM

Hi,

you have had one of the most advanced rootkits we see on the forums. It's also highly versatile, the person distributing it can use "plugins" to make it do all kind of things. However the primary goal is to redirect you to those sites and create artificial traffics on the advertisements there. That's how they make their money primarily. (and they make lots of it).
Some of the variants however do have keylogging features and similar. As the rootkit is encoding its personal space, it's hard to say what you were seeing and what was there.

Regarding your sound, this should be the drivers you need: http://www.dell.com/support/drivers/us/en/04/DriverDetails/DriverFileFormats?c=us&l=en&s=bsd&cs=04&DriverId=R99254

With regards to your security, those tools are good, yes, but you also need to keep an eye on your software and make sure it's not outdated:

Important Note: Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.
Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 7 and save it to your desktop.
  • Look for "Java Platform, Standard Edition".
  • Click the "Download JRE" button to the right.
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • From the list, select your OS and Platform (32-bit or 64-bit).
  • If a download for an Offline Installation is available, it is recommended to choose that and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.

Go to Posted Image > Control Panel, double-click on Add/Remove Programs or Programs and Features in Vista/Windows 7 and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7u1-windows-i586-s.exe (or jre-7u1-windows-x64.exe for 64-bit) to install the newest version.
  • If using Windows 7 or Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
  • The McAfee Security Scan Plus tool is installed by default unless you uncheck the McAfee installation box when updating Java.

Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications but it's not necessary.
To disable the JQS service if you don't want to use it:
  • Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
  • Click Ok and reboot your computer.


Your version of Adobe Reader is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Adobe components and update:
  • Download the latest version of Adobe Reader Version X. and save it to your desktop.
  • Uncheck the "Free McAfee Security plan Plus" option or any other Toolbar you are offered
  • Click the download button at the bottom.
  • If you use Internet Explorer and do not wish to install the ActiveX element, simply click on the click here to download link on the next page.
  • Remove all older version of Adobe Reader: Go to Add/remove and uninstall all versions of Adobe Reader, Acrobat Reader and Adobe Acrobat.
    If you are unsure of how to use Add or Remove Programs, the please see this tutorial:How To Remove An Installed Program From Your Computer
  • Then from your desktop double-click on Adobe Reader to install the newest version.
    If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the "Adobe Setup - Welcome" window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
  • Once the installation is finished, open Adobe Reader and accept the warranty if prompted.
  • Click on Help and select Check for Updates.
  • A window will open and Adobe will check for Updates. If any updates are found to be available click on Download.
  • Once the update is downloaded you will get a system notification telling you so. Click on the popup to restore the window.
  • In the window that opens click Install.
  • Once the update is done click Close.
Your Adobe Reader is now up to date!
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

#78 User is offline   Martin C 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 48
  • Joined: 01-January 12

Posted 15 January 2012 - 12:14 PM

Myrti-
This is a duplicate reply as I sent it yesterday, but don't see it in the string.

I'm unable to download the driver you suggested as I get an error. The file unzips successfully, but when moving through the install wizard I get the following error: "Error in installation Call to GetClassdevs" And I cannot go further.

Additionally, I've downloaded what I think to be the right version of Java, but when installing I ALSO get an error that reads: "Could not find the required version of the Java™2 Runtime environment in '(null)'.

Please advise.
Thanks,
Martin

#79 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,527
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 15 January 2012 - 02:52 PM

Hi,

could you give me the exact name of the java file you're trying to install?

Can you please open the device manager (Press Windows-key+r and type in devmgmt.msc) and tell me if you see a yellow exclamation mark in front of anything. Please make sure you expand all the branches to see if there's a exclamation mark or not.

regards myrti
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

#80 User is offline   Martin C 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 48
  • Joined: 01-January 12

Posted 15 January 2012 - 03:13 PM

Myrti-

Here is the Java file that took about 45 minutes to download: java_ee_sdk-6u3-jdk7-windows.exe

Also, I typed the devmgmt.msc and the device manager window opened up with nothing in it at all, completely blank.

Next?

Martin

#81 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,527
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 15 January 2012 - 03:27 PM

Hi,


Please try to download the JRE instead of the JDK vesion for java. JDK is needed when you want to program in java, not when you just want to run applications with it.

can you open the services-manager (press windows-key+r, type in services.msc) and check if Plug&Play is running?

regards myrti
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

#82 User is offline   Martin C 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 48
  • Joined: 01-January 12

Posted 16 January 2012 - 01:43 PM

Plug and Play was NOT enabled. It is now and I have sound! Also, there were no yellow exclamation points in front of anything.

Do I save the Java JRE version to the desktop, and then uninstall the JDK version?

Thanks,
Martin

#83 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,527
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 17 January 2012 - 03:51 AM

Hi,

I thought the jdk version did not install yet? If it is please install the JRE first and then try to uninstall JDK.

regards myrti
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

#84 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,527
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 29 January 2012 - 09:08 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

Share this topic:


  • 6 Pages +
  • « First
  • 4
  • 5
  • 6
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users