1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved redirect virus in vista

Discussion in 'Malware and Virus Removal Archive' started by dodopie, 2011/09/03.

  1. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    firefox
     
  2. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Can you check if IE is affected as well?

    Please download [color= "#FF0000"]GooredFix[/color] from one of the locations below and save it to your Desktop
    Download Mirror #1
    Download Mirror #2
    • Ensure all Firefox windows are closed.
    • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
    • When prompted to run the scan, click Yes.
    • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
     

  3. to hide this advert.

  4. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    GooredFix by jpshortstuff (03.07.10.1)
    Log created at 15:20 on 05/09/2011 (jerry)
    Firefox version 6.0.1 (en-US)

    ========== GooredScan ==========

    Removing Orphan:
    "m3ffxtbr@mywebsearch.com "= "C:\Program Files\MyWebSearch\bar\1.bin" -> Success!

    ========== GooredLog ==========

    C:\Program Files\Mozilla Firefox\extensions\
    {972ce4c6-7e08-4474-a285-3208198ce6fd} [08:38 30/04/2011]
    {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [01:16 29/07/2009]
    {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [20:37 20/10/2009]
    {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [01:21 17/12/2009]
    {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [21:36 13/01/2011]
    {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [14:38 24/02/2011]
    {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [13:21 21/06/2011]
    {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} [22:04 04/09/2011]
    {f92a9fe4-2850-4198-b9d5-279880e49b16} [14:59 30/08/2009]

    C:\Users\jerry\Application Data\Mozilla\Firefox\Profiles\jljmyqw9.default\extensions\
    {635abd67-4fe9-1b23-4f01-e679fa7484c1} [00:27 02/08/2011]
    {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [18:46 05/09/2011]

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
    "{1E73965B-8B48-48be-9C8D-68B920ABC1C4} "= "C:\Program Files\AVG\AVG2012\Firefox4\" [12:18 04/09/2011]

    -=E.O.F=-
     
  5. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    IE seems to work just fine
     
  6. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    ok, the last log i used IE, now i'm on firefox and when i tried to click in the login box, it opened another window to a random site again, so its like this firefox is still corrupt
     
  7. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still happening after running GooredFix?

    If so...

    If you're using Firefox 3.x, close Firefox. Go Start>All Programs>Mozilla Firefox, click on Mozilla Firefox (safe mode).
    If you're using Firefox 4, or higher go Help>Restart Firefox with Add-ons Disabled.
    Same issue?
     
  8. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    yes it was, i followed your instructions above and now seems to be working right, at least on this site
     
  9. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Some of your add-ons must be causing this.

    Close Firefox.
    Open Windows Explorer, navigate to this folder:
    C:\Program Files\Mozilla Firefox\extensions
    Delete following subfolder:
    {f92a9fe4-2850-4198-b9d5-279880e49b16}

    Start Firefox and let me know.
     
  10. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    still the same, redirecting, and when i restart the computer now i get this script error
     
  11. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    the sites it taking me to the wot says its not a trusted site. it did it just now when i clicked in this message box to type this
     
  12. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  13. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    i copied it:
    http://imprus.admailtiser.com/st?cipid=11301&ttype=0&excid=10&cicmp=2544&tchannel=${ADV_CODE}&clickurl=http://ib.adnxs.com/click%3FPX0E_vDzwz90ah0LwPXAPwAAACDb-fQ_dGodC8D1wD89fQT-8PPDP2VuFUPlRmZ-73Nv32d792IPQ2VOAAAAAMU5CABGAQAAPwEAAAIAAABzwAYAqy0BAAEAAABVU0QAVVNEAKAAWALBLQAAogUAAgUCAQUAAAAAICX4agAAAAA./cnd=!FwXtKgjH4AcQ84AbGKvbBCAA/referrer=http%253A%252F%252Fgo.infodigest247.com%252Fbanner.php%253Fsize%253D160x600/clickenc=http%253A%252F%252Fclickus.admailtiser.com%252Fst%253Fcipid%253D11301%2526ttype%253D1%2526excid%253D10%2526cicmp%253D2544%2526tchannel%253D%2524%257BADV_CODE%257D%2526clickurl%253D%2526ciecp%253D1.3110%2526cirp%253D0.0000%2526extuid%253D7131304221024941039%2526invs%253D0%2526crid%253D442483%2526cia%253D0%2526ord%253D1315259151%2526cibp%253D0.155882%2526secid%253D11713%2526invc%253Dunaudited%2526cig%253Du%2526srcurl%253Dhttp%253A%252F%252Fgo.infodigest247.com%252Fbanner.php%25253Fsize%253D160x600%2526cisf%253D-1%2526cirf%253Dhttp%253A%252F%252Fgo.infodigest247.com%252Fbanner.php%253Fsize%253D160x600%2526cipp%253D0.155882%2526cirid%253D9108045246890339941%2526subid%253D539077%2526tgt%253Dhttp%25253A%25252F%25252Fservice.mail.com%25252Flp%25252Fybrant%25252Fwoman.html%25252F%25253Fkid%25253Dkid%252540display%252540x%252540x%252540banner%252540ybrant%252540women&ciecp=1.3110&cirp=0.0000&extuid=7131304221024941039&invs=0&crid=442483&cia=0&ord=1315259151&cibp=0.155882&secid=11713&invc=unaudited&cig=u&srcurl=http://go.infodigest247.com/banner.php%3Fsize=160x600&cisf=-1&cirf=http://go.infodigest247.com/banner.php?size=160x600&cipp=0.155882&cirid=9108045246890339941&subid=539077
     
  14. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    When and where are you getting that error?

    Did you try new Firefox profile?
     
  15. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    i got that on a restart, i'd seen it before we did anything so its not new, just happens sometimes when i restart. i'm trying to find the profile manager, its not where the instructions on that link you posted say it is?
     
  16. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    .....
     
  17. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    i type in the search firefox.exe -profilemanager and i click it and it just opens a new browser window showing my home page
     
  18. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    i tried firefox.exe -P too, same result
     
  19. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  20. 2011/09/05
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    ok, uninstalled firefox through control panel, downloaded new copy from cnet, installed and came here, as soon as i clicked in user name, it opened a new browers?
     
  21. 2011/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    New browser window?
    What was present in that new window? What webpage?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.