Jump to content

Build Theme!
  •  
  • Infected?

big grin WE'RE SURE THAT YOU'LL LOVE US!

We invite you to ask questions, share experiences, and learn. It's 100% free. Did we mention that it's free. It is. It's free. Join 91603 other members! Anybody can ask, anybody can answer. Consistently helpful members with best answers are invited to staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

HP redirect.com virus? [Solved]


  • This topic is locked This topic is locked
51 replies to this topic

#16 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 09 March 2014 - 10:09 AM

Hi,
 
Glad to hear that your system is running well again.   :)
 
As for a donation, that is really up to you.  Your thanks is nice enough.
 
Ok....let's check for anything else hiding before you go....
 
GUZVCQN.jpg Please download Malwarebytes Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.
     
          A3npGzM.jpg
       
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

The log can also be found here:
 
Windows 2000 & Windows XP:
C:\Documents and Settings\<USERNAME>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs
 
Windows Vista & Win7:
C:\Users\<USERNAME>\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
----------
 

ESET Online Scanner
 
Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.

----------


Posted Image
 
 

    Advertisements

Register to Remove


#17 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 10 March 2014 - 07:31 AM

Whew! The Eset scan took all day to scan But Ive lost it? I saved it to my desktop and it wasnt there when I looked? I cant seem to find it either .It just said txt. So I named it Eset txt before I saved it to desktop? Hang on I think Ive found it?Attached File  log.txt   10.75KB   43 downloads Attached File  mbam-log-2014-03-10 (01-11-08).txt   1.86KB   42 downloadsAttached File  mbam-log-2014-03-10 (01-06-29).txt   1.84KB   32 downloads



#18 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 11 March 2014 - 05:54 AM

Sorry for any delays......

 

From what I see in the ESET scans there are several issues popping up from your backup files that we will need to remove.  Are you good with making new backups once we have removed these?  


Posted Image
 
 

#19 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 11 March 2014 - 06:19 AM

Hi Jeff,Yes I can do a new backup no problem,do I delete the backups now?



#20 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 11 March 2014 - 06:21 AM

Not yet...I just wanted to confirm.  Give me a couple of minutes and I will have a new fix for you that should clear the rest of these bad entries out.  :)


Posted Image
 
 

#21 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 11 March 2014 - 06:27 AM

ComboFix

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    ClearJavaCache::
     
    File::
    C:\Users\bluey\Downloads\3.8.0.120_20140213023320.exe
    C:\Users\bluey\Downloads\ccsetup410.exe
    C:\Users\bluey\Downloads\ccsetup411.exe
    C:\Users\bluey\Downloads\cpu-z_1.64-setup-en.exe
    C:\Users\bluey\Downloads\dfsetup214(2).exe
    C:\Users\bluey\Downloads\rcsetup145.exe
    C:\Users\bluey\Downloads\spsetup121.exe
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 13.zip
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 17.zip
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 19.zip
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 20.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 9.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 16.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 20.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 22.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 23.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 27.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 28.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 29.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 30.zip
    K:\BLUEY-HP\Backup Set 2013-08-01 123357\Backup Files 2013-08-01 123357\Backup files 7.zip
    K:\BLUEY-HP\Backup Set 2013-08-01 123357\Backup Files 2013-08-01 123357\Backup files 9.zip
    K:\BLUEY-HP\Backup Set 2013-08-01 123357\Backup Files 2013-08-04 085454\Backup files 2.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 4.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 5.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 6.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 7.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-18 190001\Backup files 2.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-09-08 190000\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-10-07 025800\Backup files 5.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-11-03 190004\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-12-02 084710\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-12-22 190000\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2014-01-31 092012\Backup files 4.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2014-02-20 174341\Backup files 2.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2014-02-20 174341\Backup files 4.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 23.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 31.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 33.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 36.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 37.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 18.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 22.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 24.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 25.zip

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
     
    CFScriptB-4.gif
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------

 

Post the new log created and let me know what remaining malware problems you are having.  :)


Posted Image
 
 

#22 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 11 March 2014 - 06:38 AM

Do I run Combofix first and then open notepad start run etc.?



#23 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 11 March 2014 - 06:42 AM

Do I run Combofix first and then open notepad start run etc.?

 

No...create the file CFScript.txt first using notepad....then once created and saved to your Desktop, drag and drop it onto the ComboFix icon.  ComboFix will start on its own.  :)


Posted Image
 
 

#24 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 11 March 2014 - 07:09 AM

I hope this has worked?Attached File  ComboFix.txt   14.05KB   43 downloads



#25 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 11 March 2014 - 12:26 PM

Please move ComboFix to your Desktop and then run the ComboFix instructions again.  Post the new log.  :)


Posted Image
 
 

    Advertisements

Register to Remove


#26 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 11 March 2014 - 07:11 PM

Hi Jeff,I cant move Combofix to my desktop only the shortcut but I had already done that?



#27 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 11 March 2014 - 07:21 PM

OK I'm completely lost now,from when I open notepad? I couldn't find any start>run>type or code of any sort,its just a blank page? Combfix on top in blue didn't do anything when I moused over it either?


Edited by redrooster, 11 March 2014 - 07:51 PM.


#28 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 11 March 2014 - 08:33 PM

Here is a new log! I hope it worked this time? LOL     Attached File  ComboFix.txt   14.08KB   40 downloads



#29 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 13 March 2014 - 05:45 AM

Hi,
 
Sorry for any delay.  I didn't get any notification of your response.   :scratch:   
 
Anyway....

start>run>type or code of any sort

That is just a shortcut in how to get to Notepad in case someone can't find it.  No need to worry about that since you know where Notepad is already.   :)
 
It seems that we need to move things around a bit so we can get this to work right.
 
Please delete the current version of Combofix.exe from your desktop and download a new version from here be sure to place it on your Desktop.
 
Disable your AntiVirus and AntiSpyware applications.

  • Please open Notepad and then copy and paste the text present inside the code box below:

    ClearJavaCache::
     
    File::
    C:\Users\bluey\Downloads\3.8.0.120_20140213023320.exe
    C:\Users\bluey\Downloads\ccsetup410.exe
    C:\Users\bluey\Downloads\ccsetup411.exe
    C:\Users\bluey\Downloads\cpu-z_1.64-setup-en.exe
    C:\Users\bluey\Downloads\dfsetup214(2).exe
    C:\Users\bluey\Downloads\rcsetup145.exe
    C:\Users\bluey\Downloads\spsetup121.exe
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 13.zip
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 17.zip
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 19.zip
    K:\BLUEY-HP\Backup Set 2013-07-16 230823\Backup Files 2013-07-16 230823\Backup files 20.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 9.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 16.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 20.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 22.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 23.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 27.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 28.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 29.zip
    K:\BLUEY-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-28 190000\Backup files 30.zip
    K:\BLUEY-HP\Backup Set 2013-08-01 123357\Backup Files 2013-08-01 123357\Backup files 7.zip
    K:\BLUEY-HP\Backup Set 2013-08-01 123357\Backup Files 2013-08-01 123357\Backup files 9.zip
    K:\BLUEY-HP\Backup Set 2013-08-01 123357\Backup Files 2013-08-04 085454\Backup files 2.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 4.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 5.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 6.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-13 161858\Backup files 7.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-08-18 190001\Backup files 2.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-09-08 190000\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-10-07 025800\Backup files 5.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-11-03 190004\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-12-02 084710\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2013-12-22 190000\Backup files 3.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2014-01-31 092012\Backup files 4.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2014-02-20 174341\Backup files 2.zip
    K:\BLUEY-HP\Backup Set 2013-08-13 161858\Backup Files 2014-02-20 174341\Backup files 4.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 23.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 31.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 33.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 36.zip
    K:\BLUEY-HP\Backup Set 2014-02-24 003742\Backup Files 2014-02-24 003742\Backup files 37.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 18.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 22.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 24.zip
    K:\FREDDOFROG-HP\Backup Set 2013-07-22 142603\Backup Files 2013-07-22 142603\Backup files 25.zip

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
     
    CFScriptB-4.gif
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
    [/list]
    CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    ----------

Posted Image
 
 

#30 redrooster

redrooster

    Authentic Member

  • Authentic Member
  • PipPip
  • 29 posts

Posted 13 March 2014 - 12:03 PM

Hi Jeff, I got to the part where it says;Open notepad,then copy and paste the text present inside the code box below, (Clear javacache) when I right click on the text it doesn't show copy? So I cant copy and paste it to notepad and I don't know how to proceed from there?


Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users