Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Can't seem to get rid of linksadoor redirect/popup


  • This topic is locked This topic is locked
15 replies to this topic

#1 FrustrtdByLinksadoor

FrustrtdByLinksadoor

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 31 May 2010 - 06:32 PM

Hi
Hoping for some assistance when someone has time to lend a hand, and thank you very much in advance.
My system is plagued by an adclicker type of redirect/popup, which seems to happen primarily when browsing using firefox

I am using Windows XP, with SP3.

Edited by FrustrtdByLinksadoor, 01 June 2010 - 03:34 AM.
Moved from AII ~BP


BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:18 AM

Posted 02 June 2010 - 03:37 PM

Hi and welcome. smile.gif

My name is Extremeboy (or EB for short), and I will be helping you with your log. I apologize for the delay.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a GMER log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or GMER log please refer to this page and in step #6 and Step #7 and Step #8 for further instructions on downloading and running DDS & GMER. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-GMER log
-Description of any remaining problems you may still have.


With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:18 AM

Posted 05 June 2010 - 09:28 PM

Hello.

Are you still there? Do you still require help?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 7 days from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 06 June 2010 - 12:50 AM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#5 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 06 June 2010 - 03:15 AM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:18 AM

Posted 06 June 2010 - 02:01 PM

Hello.

That's fine, don't worry about GMER for now.

I see that you ran Combofix however. Do you have the log to it? It should be in the C:\ drive named Combofix.txt, if that file is still there, please post it in your next reply.

As a warning however...

ComboFix is an extremely powerful tool and you should not be using Combofix unless instructed to do so by a Malware Removal Expert. It is a powerful tool intended by its creator to be "used under the guidance and supervision of an expert", NOT for private use. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again. Please read Combofix's Disclaimer.

Further, ComboFix logs are not permitted outside the Malware Removal forum forums and then only when requested by a Malware Reponse Team member.

---

Can you let me know the current problems you have with the machine then followed by running the following 2 tools...

We need to create an OTL Report
  1. Please download OTL from one of the following mirrors:
  2. Save it to your desktop.
  3. Double click on the icon on your desktop.
  4. Click the "Scan All Users" checkbox.
  5. Under "Extra Registry" please check "Use Safelist" and also check "LOP Check" and "Purity Check" as pictured.
  6. Copy and Paste the following code into the textbox. Do not include the word "Code"

    CODE
    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    CREATERESTOREPOINT

  7. Push
  8. Two reports will open, copy and paste them in a reply here:
    • OTListIt.txt <-- Will be opened
    • Extra.txt <-- Will be minimized
Download and run RootRepeal CR

Please download RootRepeal from the following location and save it to your desktop.
  • Unzip the RootRepeal.zip file it to it's own folder. (If you did not use the "Direct Download" mirror to download RootRepeal).
  • Close/Disable all other programs especially your security programs (anti-spyware, anti-virus, and firewall) Refer to this page, if you are unsure how.
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Double-click on RootRepeal.exe to run it. If you are using Vista, please right-click and run as Administrator...
  • Click the tab at the bottom.
  • Now press the button.
  • A box will pop up, check the boxes beside All Seven options/scan area
  • Now click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button.
  • Save it as RepealScan and save it to your desktop
  • Reconnect to the internet.
  • Post the contents of that log in your reply please.

Edited by extremeboy, 06 June 2010 - 02:02 PM.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 07 June 2010 - 05:33 PM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#8 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 07 June 2010 - 05:48 PM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#9 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 07 June 2010 - 06:15 PM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#10 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 07 June 2010 - 09:06 PM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#11 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:18 AM

Posted 08 June 2010 - 03:13 PM

That's no problem.

So, it's just in FireFox?

I'm thinking of a fresh install of FireFox as well and see how that goes.

Then, could you take in an OTL log for me to take a look. Thanks
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#12 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 09 June 2010 - 09:01 PM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#13 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:18 AM

Posted 10 June 2010 - 03:17 PM

Hello.

Could you expand and explain a bit more on what you mean by you can't seem to uninstall FireFox? What happens, removing it result in the program still being there? Remove function doesn't work? etc...

Let me know.

Edited by extremeboy, 10 June 2010 - 03:18 PM.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#14 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 11 June 2010 - 12:09 AM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.


#15 FrustrtdByLinksadoor

FrustrtdByLinksadoor
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 11 June 2010 - 12:15 AM

-edit upon user's request-

Edited by extremeboy, 11 June 2010 - 04:46 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users