browser redirect issues, popups. please assist

#1 mymoneypit


Posted 28 December 2009 - 09:30 PM

A little background- I run avast and spybot, and Norton personal firewall. As of Dec 12 I can no longer click search results (I get random websites) and poups appear at random intervals. Blocking the sites did not help. Computer is painfully slow, and occasionally I saw the modem showing activity when the computer should have been idle. I now keep the modem unplugged unless I am doing something online.

I scanned with avast, then spybot. Some malware was detected and removed, but my issues resumed. Scanned with MBAM. Nothing detected. Attempted system restore with no luck. Tried trend micro housecall, but nothing was detected. Had a friend look at it, he installed something else, scanned my computer with it, nothing detected. Read somewhere to try scanning in safe mode, but found I cannot start in safe mode.

Read some threads on here for people with similar issues but couldn't find the exact thing I am dealing with. Any help would be much appreciated.

DDS (Ver_09-12-01.01) - NTFSx86
Run by HP_Owner at 20:37:00.23 on Mon 12/28/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.204 [GMT -5:00]

AV: avast! antivirus 4.8.1368 [VPS 091227-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Personal Firewall *enabled* {825036E0-9F94-4752-8789-8B92454AF49B}

#2 syler


Posted 07 January 2010 - 06:42 PM


My name is Syler and I will be helping you to solve your Malware issues. If you have since resolved your issues I would appreciate if you
would let me no so I can close this topic, if you still need help please let me no what issues you are still having, in your next reply.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and
we are trying our best to keep up.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

  • Please download GMER from one of the following locations, and save it to your desktop:
    • Main Mirror
      This version will download a randomly named file (Recommended)
    • Zip Mirror
      This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs, as this process may crash your computer.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with gmer's driver.
  • Double click on Gmer to run it.
  • Allow the gmer.sys driver to load if asked.
  • You may see a rootkit warning window, If you do, click No.
  • Untick the following boxes on the right side of the Gmer screen.
    Show All
  • Click on Posted Image and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push Posted Image and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.

Then please post back here with the following:
  • log.txt
  • info.txt
  • Gmer log


#3 mymoneypit

Posted 08 January 2010 - 06:39 PM

Unfortunately, the computer afflicted by this died yesterday. Windows will not start in any manner. Safe mode, normal, and last good configuration all result in the same thing, it seems to be starting up, but then the machine restarts again and goes back to the screen asking what mode to use.

So I do still need help, but Unless you can assist me from that point, I can't do anything with it.


#4 mymoneypit

Posted 10 January 2010 - 02:26 AM

I managed to get into recovery and get the computer back to its original 2004 settings lol. 6 hours of downloading updates later, and I am running great and virus free, (as well as song, game, and photo free :( at least some of it was backed up...)

but have a question- What protection software do you recommend? Right now, it has reset the norton 2005 free 61 day trial it came with, but it is having issues collecting present updates. Add the fact that I do not care for norton...

Are there any actual Good free programs? Avast worked well for me till this last issue, I am not sure if I had the wrong stuff running together or what. I am hesitant to install anything new until i am sure what I run won't interfere with each other.


#5 syler


Posted 10 January 2010 - 02:49 AM

Sorry it took me a while to get back to you, I have been quite busy these last couple of days. By the sound of it you would have been better
doing a format and reinstall lol.

As for protection im not a fan of Norton either so I don't think it's a bad idea to ditch it plus that is a very outdated version. I think avast is ok
I have it on my VM and it seems to do a far job catching viruses, I also use AntiVir which again I think is ok, at the end of the day it's not just
down to what protection you have it what you do on your machine and on the internet.

I will list the steps that I give to people when they are clean it has suggestion for programs so you might want to use some of them.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Keeping Windows updated
It is extremley important to keep windows upto date with the latest service pack and patches. This will prevent you
from getting the malware which uses vulnerabilities found in windows to exploit your computer. The easiest way to
do this this is by making sure that Automatic Updates are always enabled.

To do this Click on Start >> Control Panel >> Automatic updates and click Automatic (recommended) then Apply and Ok

Update your AntiVirus Software
It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not
update your antivirus software then it will not be able to catch any of the new variants that may come out. If you
use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your
subscription runs out, you may not be able to update the programs virus definitions.

Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you.
Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly
patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Install a Firewall
I can not stress how important it is that you use a third party Firewall on your computer. Without a firewall your computer is
succeptible to being hacked and taken over. Windows firewall is good for blocking inbound connections but it does not block
outbound connections. So if Malware manages to get onto your computer it will be able to send data out when it wants.
Here are some free firewalls I would recomend, only install one of these.

Zone Alarm
comodo..........Note: Only Install the Firewall as a standalone if you already have an AntiVirus installed on your computer.

After you install the third party firewall, please disable your Windows firewall. Please go to My Computer >> Control Panel >> Windows Firewall
and choose Off (not recommended) option. Then click Apply and Ok.

Install an AntiSpyware Program
A highly recommended AntiSpyware program is SuperAntiSpyware. You can download the free Home Version. or the Pro version for a 15 day trial period.
Other recommended, and free, AntiSpyware programs are Spybot - Search and Destroy and Ad-Aware Personal.
Installing these programs will provide spyware & hijacker protection on your computer alongside your virus protection. You should scan your computer with an AntiSpyware program on a regular basis just as you would an antivirus software.
Tutorials on using these programs can be found below:
Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you
from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Use MVPS hosts file
Using a custom host file like the MVPS HOSTS file can help to block ads, banners, 3rd party Cookies,
3rd party page counters, web bugs, and even most hijackers. It doesn't use up any extra system resources
and may even speed up the loading of web pages. You can download and find instructions below.


Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Happy surfing :(


#6 mymoneypit

Posted 10 January 2010 - 09:39 PM

OK still gong well, just trying to finish up. As per your instructions, I have installed, updated, etc, and now have spybot, avast, comodo, and spyware blaster on here. Comodo seems very annoying, it sends up 4 or 5 alerts every time I update, install or remove anything. The yellow icon still alerts me that more upates are availabe every time it finishes updating. How much longer is this going to take?

Also, after I got it pretty well ready for internet, I discovered that my sound isn't working right. I have a sound icon, can adjust volume. I can hear the speaker test when in the sound effect thing, and I can listen to itunes. But I have no sound when I start up the computer, in webpages, or yahoo messenger, etc UNLESS i use earphones in the front of the tower.

So my rear speaker jacks pretty much only function with itunes. Any idea what happened?

Thanks for your assistance!

#7 syler


Posted 10 January 2010 - 10:22 PM

Yes Comodo can give alot of popups untill you have fine tuned it abit, alternatly you can disble defense+ which is not needed it's just an extra
layer of protection, this will cut out most of the popups.

Right click the Comodo item in the system tray and select Defense+ security level then change it to disabled.

The updating can take a few hours but it will help prevent future infections so it should definitely be done.

Im not sure about the sound issue you would be best asking in the following forum.



#8 syler


Posted 13 January 2010 - 09:34 PM

Since this issue appears resolved ... this Topic is closed. Glad we could help.

If you need this topic reopened, please request this by sending me a PM
with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.


