Web Browser Opens Up Random Sites?

The results were clean- no malware was detected
 

My Computer

Computer Manufacturer/Model Number
Sony VAIO VGN-NR11S
OS
Linux Mint with Windows 7 in Virtualbox
CPU
Intel® Core™ 1.5 GHz 2 Duo Processor T5250
Memory
2048 MB (2GB) RAM
Graphics Card(s)
Mobile Intel® Graphics Media Accelerator X3100
Sound Card
Realtek HD Audio
Screen Resolution
1280x800
Internet Speed
10 Mbps
Doesn't anyone have any ideas? :(
 

My Computer

Computer Manufacturer/Model Number
Sony VAIO VGN-NR11S
OS
Linux Mint with Windows 7 in Virtualbox
CPU
Intel® Core™ 1.5 GHz 2 Duo Processor T5250
Memory
2048 MB (2GB) RAM
Graphics Card(s)
Mobile Intel® Graphics Media Accelerator X3100
Sound Card
Realtek HD Audio
Screen Resolution
1280x800
Internet Speed
10 Mbps
I can't watch the video on that site :(

So I am not sure what I am facing..
 

My Computer

OS
Windows 7 Ultimate x86 SP1
Please download GooredFix from one of the locations below and save it to your Desktop
http://jpshortstuff.247fixes.com/GooredFix.exe
http://downloads.securitycadets.com/GooredFix.exe"
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista and Windows7).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
This is the best <snippet> I could get from your video
 

Attachments

  • Trojan Horse Found.jpg
    Trojan Horse Found.jpg
    19.5 KB · Views: 50

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
What ever the site was that you clicked on, must have been infected with malware .... this is not a pop-up from SpywareBlaster.

Did you click out of that pop-up?
Was this from your Antivirus or a 'fake'/rogue antivirus message? It's really too blurry for me to tell.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
What ever the site was that you clicked on, must have been infected with malware .... this is not a pop-up from SpywareBlaster.

Did you click out of that pop-up?
Was this from your Antivirus or a 'fake'/rogue antivirus message? It's really too blurry for me to tell.

ok, I managed to watch video :party:

I think It was warning from user's legit Avast AV.
It blocked trojan horse from the malicious site.
 

My Computer

OS
Windows 7 Ultimate x86 SP1
Back in your first combo fix log, the url's pointed to hxxp - I'd reinstall 7, clean format.
 

My Computer

Computer Manufacturer/Model Number
Sony Vaio Z46GDU
OS
Windows 7 Ultimate x86-64
CPU
[email protected] 1066MHz FSB
Motherboard
Sony branded
Memory
6GB DDR3 1066MHz
Graphics Card(s)
9300M GS 256MB Dedicated (Speed) + Intel4500MHD (Stamina)
Sound Card
Realtek HD Audio
Monitor(s) Displays
13.1' WXGA
Screen Resolution
1600x900
Hard Drives
320GB 7200RPM w/ 16MB cache
Internet Speed
1MB/s
LimeWire, P2P sharing would be the most likely suspect for the problem you are encountering.
I have to agree with Frostmourne
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
The message was from a legit Avast! copy. You see, I visited that website and I visited the AVG website, I was redirected from both websites to different websites. However, when I closed Firefox and reopened it, the redirects from the two websites were gone and opened the actual websites so I don't think the websites were malicious (especially the AVG homepage) but the redirects were.

BTW, I don't use Limewire, torrents or fo P2P sharing as I hate doing it.
 

My Computer

Computer Manufacturer/Model Number
Sony VAIO VGN-NR11S
OS
Linux Mint with Windows 7 in Virtualbox
CPU
Intel® Core™ 1.5 GHz 2 Duo Processor T5250
Memory
2048 MB (2GB) RAM
Graphics Card(s)
Mobile Intel® Graphics Media Accelerator X3100
Sound Card
Realtek HD Audio
Screen Resolution
1280x800
Internet Speed
10 Mbps
Back in your first combo fix log, the url's pointed to hxxp - I'd reinstall 7, clean format.
Missed that completely as I was only checking th HJT file....:o
hxxp according to Wiki
uStart Page = hxxp://www.google.co.uk/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
TCP: {BB929842-C69D-49F1-BCF1-183BECE4CD17} = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\Brijesh Patel\AppData\Roaming\Mozilla\Firefox\Profiles\5xaz82fm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://www.google.co.uk/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
 

My Computer

OS
XP Pro/Vista Ultimate (64)/Windows 7 Ultimate Signature Edition(64)
CPU
Core 2 Duo E8500 @ stock
Motherboard
Gigabyte EP45-UD3R
Memory
8Gb (4 X 2Gb) Corsair Dominator 1066Mhz DDR2
Graphics Card(s)
XFX ATI Radeon 4870 1Gb
Sound Card
Onboard 7.1
Monitor(s) Displays
BenQ E2200Hd, Asus VW161D, HP L1506
Screen Resolution
1920 X 1080
Hard Drives
Seagate 7200.12 500Gb
2 X Hitachi 1Tb
PSU
CoolerMaster 650 EPD
Case
Thermaltake
Cooling
2 X Noctua 120mm's, Stock Intel
Keyboard
Logitech
Mouse
Logitech
The hxxp:// is a 'munged' URL, in case it's malicious. That way, people looking at a CF log won't accidently click on a working link to malware.
In this case, it's by design and it's a safe URL
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Here's GooredFix Log I did in Safe Mode as it kept on freezing on 'General Malware' in Normal Mode

Code:
 GooredFix by jpshortstuff (08.01.10.1)
Log created at 15:54 on 20/01/2010 (Brijesh Patel)
Firefox version 3.5.6 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [17:10 24/10/2009]
{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [17:45 24/10/2009]
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [10:51 18/01/2010]

C:\Users\Brijesh Patel\Application Data\Mozilla\Firefox\Profiles\5xaz82fm.default\extensions\
[EMAIL="[email protected]"][email protected][/EMAIL] [13:20 05/12/2009]
SkipScreen@SkipScreen [18:52 15/12/2009]
yetanothersmoothscrolling@kataho [11:39 19/01/2010]
{73a6fe31-595d-460b-a920-fcc0f8843232} [08:46 18/01/2010]
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [08:08 19/12/2009]
{c36177c0-224a-11da-8cd6-0800200c9a91} [14:23 06/12/2009]
{cf47767d-5f3a-4e32-9fce-5d79565c9702} [19:17 15/01/2010]
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [16:18 08/01/2010]
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} [07:05 25/10/2009]
{DDC359D1-844A-42a7-9AA1-88A850A938A8} [16:14 12/01/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
(none)

-=E.O.F=-
 

My Computer

Computer Manufacturer/Model Number
Sony VAIO VGN-NR11S
OS
Linux Mint with Windows 7 in Virtualbox
CPU
Intel® Core™ 1.5 GHz 2 Duo Processor T5250
Memory
2048 MB (2GB) RAM
Graphics Card(s)
Mobile Intel® Graphics Media Accelerator X3100
Sound Card
Realtek HD Audio
Screen Resolution
1280x800
Internet Speed
10 Mbps
Back in your first combo fix log, the url's pointed to hxxp - I'd reinstall 7, clean format.

wait, what do you mean?
all hxxp I can find point to the legit and safe site (google)
except one which points to google search results :sarc:

EDIT: ohh, haven't seen Orpheous and Jacee's replies :p
 

My Computer

OS
Windows 7 Ultimate x86 SP1
Doesn't anyone know how to fix this? :confused:
 

My Computer

Computer Manufacturer/Model Number
Sony VAIO VGN-NR11S
OS
Linux Mint with Windows 7 in Virtualbox
CPU
Intel® Core™ 1.5 GHz 2 Duo Processor T5250
Memory
2048 MB (2GB) RAM
Graphics Card(s)
Mobile Intel® Graphics Media Accelerator X3100
Sound Card
Realtek HD Audio
Screen Resolution
1280x800
Internet Speed
10 Mbps
ok, try these.
1. Download Ccleaner CCleaner - Home
and clean up your temp files and browser cache.

2. Press Start.
Write cmd
right click, run as admin
write Ipconfig /flushdns

3. Download http://www.funkytoad.com/download/HostsXpert.zip
Unzip it
Click Restore Microsoft's Host files

4. Press Start
write clean
Enter Disk Cleanup
Tick Temporary files, Temporary Internet Files, Offline webpages
And delete them

5. Try disabling all extensions on your browser.

6. Try reverting back to your own ISP dns server
 

My Computer

OS
Windows 7 Ultimate x86 SP1
There is nothing suspicious in the log.

Clear Firefox's cache:
Tools, options, Advanced, Network, Offline Storage <--cache, click 'clear now'.

In case one of your add-on's isn't working properly, you can check it in 'safe mode':
Safe Mode
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top