Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Web & Email
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Internet & Networking > Web & Email >
Firefox Redirects Without Warning!

Reply  
Thread Tools
sammey19's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2007
Location: Rockwell City, Iowa
Experience: Advanced
07-Feb-2009, 10:27 PM #1
Smile Firefox Redirects Without Warning!
When I Search With Any Search Engine, my browser automatically redirects me to the following websites!

Code:
http://www.google.com/undefined
Code:
http://www.realtor.com/?source=a22149
Code:
http://pressure-homework.info/search.php?aid=11774&said=2788-11&keyword=white%20cloud&ipr=&rej=1
This Is Too Long Of A URL to post! So, please go here:-
Code:
http://findtop365.com/search.php?q=white+cloud

Here Are Pictures!:-





Code:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:40 PM, on 2/7/2009
Platform: Unknown Windows (WinNT 6.01.2904)
MSIE: Internet Explorer v8.00 (8.00.7000.0000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Sam's Software\Sam's Software HijackThis\analyze.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://www.ask.com/?o=101863&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SeePassword] C:\Program Files\SeePassword\SeePassword.exe
O4 - HKLM\..\Run: [ErrorSweeper] C:\Program Files\ErrorSweeper\ErrorSweeper.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: DiaryOne: Save full text - C:\Program Files\DiaryOne\Script\fullcatcher.htm
O8 - Extra context menu item: DiaryOne: Save selected text - C:\Program Files\DiaryOne\Script\catcher.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix: 
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.2.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Profile Monitor (PMonSvc) - Salience Corporation - C:\Windows\system32\pmonsvc.exe
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe

--
End of file - 4875 bytes
Startup List:-
Code:
http://www.tinypaste.com/539d5

By The Way This Is a Windows 7 Installation!
Attached Files
File Type: log hijackthis.log (4.8 KB, 82 views)
File Type: txt startuplist.txt (4.5 KB, 202 views)

Last edited by sammey19; 08-Feb-2009 at 06:38 PM.. Reason: Computer Version
PCcruncher's Avatar
PCcruncher has a Photo Album
Computer Specs
Distinguished Member with 3,006 posts.
 
Join Date: Oct 2007
Location: On the computer
Experience: learning more daily :)
08-Feb-2009, 01:15 AM #2
Is this just an experimental install of Windows 7?

It looks like it is infected, but if it isn't a real computer, please don't bother the Malware people with it.

What is the computer used for?
sammey19's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2007
Location: Rockwell City, Iowa
Experience: Advanced
08-Feb-2009, 06:37 PM #3
Yes, This Is Windows 7!
PCcruncher's Avatar
PCcruncher has a Photo Album
Computer Specs
Distinguished Member with 3,006 posts.
 
Join Date: Oct 2007
Location: On the computer
Experience: learning more daily :)
09-Feb-2009, 01:23 AM #4
Can you just restore it to an earlier date?
I am not qualified to help remove malware (yet)
And I doubt if many people would have experience with Win7 anyway
sammey19's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2007
Location: Rockwell City, Iowa
Experience: Advanced
09-Feb-2009, 07:51 PM #5
Question Ok, But Can You Help Me?
Ok, But Can You Help Me?
PCcruncher's Avatar
PCcruncher has a Photo Album
Computer Specs
Distinguished Member with 3,006 posts.
 
Join Date: Oct 2007
Location: On the computer
Experience: learning more daily :)
10-Feb-2009, 12:54 AM #6
Well, the rules of this forum don't allow unqualified persons to help with malware (for good reason) so that's out. I see you have Malwarebytes and spybot which is good, I would try downloading Avast and scanning with it. Avast home edition free dowload here

If that doesn't fix it, and if I where you, I would either reinstall it or restore to a previous date.

Beyond that I don't think I can help any more, sorry.
__________________
For the wages of SIN is death; but the gift of God is eternal life through Jesus Christ our Lord. Romans 6:23
"You can tell whether a man is clever by his answers. You can tell whether a man is wise by his questions." - Naguib Mahfouz
Reply

Tags
firefox

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:43 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.