This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirect Problems

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I have recently been having some problems with my computer. It started two months ago with some suspicious email coming through my Postini filter and into my Inbox. This email was irritating and seemed deliberate. In hindsight, I think it was/is. The problem affected my computer functioning when I tried to login to an online class. The login link opens a new browser window and redirects to a secure socket for the class session. My browser just bounced back and forth from the original address to the new one, never allowing me to load either one and hence not login to the class. No one in the class is having the problem…its on my end. Recently changed residences and had to change ISPs. The suspicious emails started back up in a few days on the new email address. I have updated to IE7, installed all new Microsoft Security Updates for XP, updated McAfee VirusScan, and installed their SpyWare Removal Tools and removed some SpyWare. I am still having the problem and posted a message on McAfee's message board. Someone there informed to download HijackThis and post my log. So here it is…. Can someone help me? Thank you so much. Logfile of HijackThis v1.99.1 Scan saved at 12:30:20 PM, on 11/4/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe c:\progra~1\mcafee\mcafee antispyware\massrv.exe C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mclogsrv.exe C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe c:\program files\common files\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\PROGRA~1\McAfee\MSC\mctskshd.exe C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\McAfee\MPS\mps.exe C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe C:\WINDOWS\system32\userinit.exe C:\WINDOWS\Explorer.EXE c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\McAfee\MPS\mpsevh.exe C:\WINDOWS\system32\ctfmon.exe C:\DOCUME~1\Scott\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
salud :D

Welcome to Tom Coyote sorry for the delay in responding but we get a little overwhelmed with logs most days.

I am not looking at anything bad on your log, the entry for winlogon 020….Win Logon..is legit so leave it alone.

This is what I suggest you do…

DO THIS FIRST
Your HIJACKTHIS program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.

Easy to fix.
  • just go to My Computer > YOUR C:\ DRIVE > Program Files and create a new folder and name it Hijackthis .
  • Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
  • Now open the new folder you just created and right click within that folder and select PASTE .
  • Now HJT should reside in C:\Program Files\Hijackthis\Hijackthis.exe
Please do not proceed until you have moved HJT




Run this system cleaner

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up




Run this free online virus scanner from Panda, it may pick up some bad entires that are not showing up on your HJT log. It's important that I see the log so copy and paste it into your next reply.
Panda ActiveScan <—-Accept default settings



Now this is important…. There are infections going around that are designed to hide from HJT, so go to where you have HJT installed, open the folder and right click on the HJT Icon, ( looks like a stick of dynamite with a plunger ) and rename it to Analyze.exe.


First run the cleaner, then run Panda, then run HJT and post a new log along with the Panda report.

Ken :D
Hey Ken…thanks so much for starting the process and
posting the reply.

Here are the ActiveScan results:


Incident Status Location

Potentially unwanted tool:application/bestoffer Not disinfected c:\windows\smdat32a.sys
Potentially unwanted tool:application/myway Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\uninstall\My Way Speedbar Uninstall
Adware:adware/statblaster Not disinfected Windows Registry
Potentially unwanted tool:application/altnet Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM
Adware:adware/sbsoft Not disinfected Windows Registry
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Patience\Application Data\Mozilla\Firefox\Profiles\sijq833k.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Patience\Application Data\Mozilla\Firefox\Profiles\sijq833k.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Patience\Application Data\Mozilla\Firefox\Profiles\sijq833k.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Patience\Application Data\Mozilla\Firefox\Profiles\sijq833k.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[stats.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[stats.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[www.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[stats.drivecleaner.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\3cbpxoqe.default\cookies.txt[.doubleclick.net/]

Now as HJT goes…I already had it in a folder of its own.
I did a new scan anyway and here are those results:

Logfile of HijackThis v1.99.1
Scan saved at 10:32:20 PM, on 11/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\mcafee\msc\mcupdui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hjt\analyze.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe


Maybe you are online now…I will be online for about an hour or so.
If not I will read your post tommorrow.
I also checked out your website…so glad they are people who enjoy
helping others. Thanks.
salud :D

This is where you had HJT installed on your original post and when we clean out your temp files, any backups that HJT makes could be lost.
C:\DOCUME~1\Scott\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe



We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.


Panda picked up a bad file, if its present you may have to boot to Safemode to delete it.
c:\windows\smdat32a.sys

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode


Still in Safemode, do this.

  • Go to My Computer/ C: Drive/ Documents and Settings/ Every User on this Computer /Local Settings and delete all the contents of the Temp Folder and the Temporary Internet Files Folder <–Just the contents, not the folder itself.
  • Go to My Computer/ C:/ Windows/ Temp and delete all the contents of the Temp Folder <– But not the temp folder itself.
  • Go to My Computer/ C:/ Windows/ Prefetch and remove all the contents of the Prefetch Folder. <–But not the Prefetch folder itself.

Reboot normally


Close any instance of Internet Explorer and Windows Explorer.
  • Go to Start> Control Panel> Internet Options . You shoud be on the General Tab
  • Delete Cookies
  • Delete Files > and offline content as well
  • Then go to the Programs Tab and Reset Web Settings



The rest of your log looks fine :thumbup: I don't see anything that is causing you your problems, lets see if removing that bad file and cleaning up your system makes a difference.
OK Ken this is going to sound whack, I know. When I restart in Safe Mode…there are extra accounts there like, "Administrator," that are not listed when I check the "User Accounts" on a normal login via the Control Panel. So when I login as Admin to XP in Safe Mode it does not let me type…like the keyboard does not work or something. I guess I am going to print your exact Safe Mode instructions. Restart in Safe Mode and try to follow the directions. Maybe right-click delete. Another thing I am noticing on my computer this evening Windows Update keeps appearing in the SysTray and if I right-click it it says Downloading 0% and ends up disappearing. What's up with that? Let me go check this real quick.
It will kind of take a hike, but if you leave your computer on it may finish, also the site may be real busy and it will pick up where it left off next time you turn your computer on.

Another thing I am noticing on my computer this evening Windows Update keeps appearing
in the SysTray and if I right-click it it says Downloading 0% and ends up disappearing.
What's up with that?



You can log on to any user, if your using a wireless mouse and keyboard it may not work, you need to use a USB mouse, the one in the old com port may not work either.

So when I login as Admin to XP in Safe Mode it does not let me type…like
the keyboard does not work or something.

Hey Ken do you check the email listed on your webpage? I sent you an email with some more info that did not belong on the post. If you have anymore tech advice we can switch back over to the thread. Thanks! Scott.
Scott,

I did read it. Your log looks free of malware. We can't do anything about someone sending you malicious email except for you to block them, you may even forward one to your ISP with a complaint.

You can run both these quick programs that will scan your computer for a Rootkit infection. Post the results of both scans and a new HJT log .

Rootkit Revealer < Just follow the instructions
http://www.sysinternals.com/Utilities/RootkitRevealer.html


Download and Save Blacklight to your desktop:
  • Double-click blbeta.exe
  • Then accept the agreement
  • leave [X]scan through Windows Explorer checked.
  • Click > scan then > next
  • You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
  • Copy and paste this log in your next reply.
  • Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"
Alright Ken. I am not at that computer now. I will do that when I am on it late tonight or sometime tommorrow and post new results. Can you suggest a good email filter/control program? I just assume get no emails from anyone except who I directly approve. What do you make of the browser redirect problem? Or maybe we'll get to that… :)
Scott,

I use Firefox, it's free and more secure than Outlook Express.
Firefox 2.0


In either IE or Firefox, you have an option to close out that account and create a new one. Talk to your ISP about it. You can also just stop using that account and setup web based mail at Yahoo, Hotmail or Gmail.


As far as the redirects, there is nothing on your log I see that would be causing it, but lets see what RK Revealer and Blacklight come up with.
Hey Ken…took me awhile to get the software and do these scans.

1. Here is the Rootkit Reveal log….

HKU\.DEFAULT\RemoteAccess\InternetProfile 9/4/2004 9:59 PM 7 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-1227912602-687269903-1541898498-1008\RemoteAccess\InternetProfile 11/28/2003 10:51 AM 7 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-18\RemoteAccess\InternetProfile 9/4/2004 9:59 PM 7 bytes Data mismatch between Windows API and raw hive data.
HKLM\SECURITY\Policy\Secrets\SAC* 9/3/2002 9:18 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 9/3/2002 9:18 AM 0 bytes Key name contains embedded nulls (*)
C:\Documents and Settings\Scott\Local Settings\Temp\TFR6D.tmp 11/11/2006 7:57 PM 8.00 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\css_14[2].css 11/11/2006 12:23 AM 26.71 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\dnserrordiagoff[1] 11/11/2006 7:57 PM 7.93 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\down[2] 11/11/2006 7:54 PM 3.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\favcenter[1] 11/11/2006 7:54 PM 3.29 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\favcenter[2] 11/11/2006 7:57 PM 3.29 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\google[1].htm 11/11/2006 7:57 PM 4.72 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\tools[1] 11/11/2006 7:57 PM 3.48 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\bullet[1] 11/11/2006 7:54 PM 3.09 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\css_14[1].css 11/11/2006 7:57 PM 26.71 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\down[1] 11/11/2006 7:57 PM 3.33 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\index[4].htm 11/11/2006 12:24 AM 103.21 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\bullet[1] 11/11/2006 7:57 PM 3.09 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\dnserrordiagoff[2] 11/11/2006 7:54 PM 7.93 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\errorPageStrings[1] 11/11/2006 7:57 PM 850 bytes Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\ErrorPageTemplate[1] 11/11/2006 7:54 PM 2.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\ErrorPageTemplate[2] 11/11/2006 7:57 PM 2.12 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\info_48[1] 11/11/2006 7:54 PM 6.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\ads[1].htm 11/11/2006 7:57 PM 9.81 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\background_gradient[1] 11/11/2006 7:54 PM 453 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\background_gradient[2] 11/11/2006 7:57 PM 453 bytes Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\errorPageStrings[1] 11/11/2006 7:54 PM 850 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\google[1].htm 11/11/2006 7:09 PM 4.72 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\httpErrorPagesScripts[1] 11/11/2006 7:57 PM 6.81 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\httpErrorPagesScripts[2] 11/11/2006 7:54 PM 6.81 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\index[3].htm 11/11/2006 7:57 PM 103.24 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\info_48[1] 11/11/2006 7:57 PM 6.83 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\tools[1] 11/11/2006 7:54 PM 3.48 KB Visible in Windows API, but not in MFT or directory index.

2. Now the Blacklight log…

11/11/06 20:02:18 [Info]: BlackLight Engine 1.0.47 initialized
11/11/06 20:02:18 [Info]: OS: 5.1 build 2600 (Service Pack 2)
11/11/06 20:02:19 [Note]: 7019 4
11/11/06 20:02:19 [Note]: 7005 0
11/11/06 20:02:25 [Note]: 7006 0
11/11/06 20:02:25 [Note]: 7011 3472
11/11/06 20:02:25 [Note]: 7026 0
11/11/06 20:02:25 [Note]: 7026 0
11/11/06 20:02:30 [Note]: FSRAW library version 1.7.1020
11/11/06 20:14:25 [Note]: 7007 0

3. And finally a new HJT log…

Logfile of HijackThis v1.99.1
Scan saved at 8:16:07 PM, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\Explorer.EXE
c:\program files\mcafee\msc\mcupdui.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\hjt\analyze.exe

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe

Hopefully this will explain things some more.
I will be on the lookout for your reply.

Scott
Blacklight found nothing :thumbup:


Rootkit Revealer found just some entries that may or maynot be bad in your Temporary Internet Files, did you flush them out like I previously posted?

Do them again, this should be run from Safemode.

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.


Outside of this, I see nothing on your log or any scans that are causing you your problem. Let me know if cleaning out the TIFs helped at all.
Ken, Good Evening, I thought I had done that already. I did it again for safe measure. :) In safemode, the interface was not exactly as you described, think the gist was there though. I still have that browser redirect issue, annoying, but if there is not anyone using my computer to mass email, I am happy. Maybe I can uninstall/reinstall browsers. Overall if you think the logs look good then sweet. This post could go inactive soon. Scott
Scott,

I am looking into the redirect, where exactly is it redirecting you? Another words, when you open IE and pick a bookmark like google for instance , does it take you to google or someplace else?

Try this, this program will clean out all the old host file entries and create new .

Download the Hoster Here

Unzip Hoster to your desktop

Open up the Hoster program.
  • Make sure that the "make hosts writable?" button in the upper right corner is enabled.
  • Click back up Host files
  • then click Restore orginal host files
  • close program
Let me know if it helped
It came to my attention in a very specific application. Other than this initial problem with the browser redirecting (along with the suspicious emails), I would have never suspected I had anything wrong. I.E. My browser and web surfing is fine other than this. I noticed it once I began taking an online class. There is a login link on the online professional development page. You click the link and it opens a new instance of your browser (whatever one you use…I have tried this in IE and Firefox). Once that new instance is open, the script initiates a browser redirect to get a secure socket for a protected session while you are online taking the class…its in a common web app called Blackboard. That is my rudimentary understanding of it. What is supposed to happen is that your browser is redirected to the secure socket and then you login and then you take the class. What happens in my browser is the web page is never allowed to load…it just bounces back and forth. Like in the address line it flicks back and forth between the two pages and nothing ever happens. The same thing happens in Firefox as IE. I have allowed cookies from these websites and opened their status as trusted websites. I also updated all of my browsers. I am definitely going to try the hoster this evening and see what happens. I will post more later and maybe you can brainstorm some more. In the meantime, I am very happy that there appears to be no more weird emails and my logs look good. Thanks for all of the advice so far. I have actually been saving these tools in hopes that I can keep a hold of them and use them in the future.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI