Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

View previous topic View next topic Go down  Message [Page 1 of 1]

1 Help with redirect to different web page? on Mon Dec 14, 2009 7:56 pm

kheops_raven


New Member
Everytime I try to hit Ebay, I get redirected to a different site. On the second try, I get there, no problem... I read a forum thread that told me that you guys were awesome at helping with this stuff. I did what they told me, which was to download 'Hijack this', grab the file and post it here.

Help and thanks, respectively,
Dan

PS - If there are other junk redirects or bad stuff you see, please let me know. Thanks again for any help and/or support you can provide.

------------------------
Log file (below)
------------------------

Logfile of HijackThis v1.98.2
Scan saved at 7:53:59 PM, on 12/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
F:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\WINDOWS\runservice.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\SelectRebates\SelectRebates.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Upromise\dca-ua.exe
C:\Program Files\Upromise\UpromiseTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
F:\Dan Folder\Virus Protection Programs\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll
O2 - BHO: DCA - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll
O2 - BHO: ShopAtHomeIEHelper - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: ShopAtHome Toolbar - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [*syscom] C:\WINDOWS\Tasks\syscom.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [basicsmssmenu] "F:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Picasa Media Detector] F:\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Upromise Update] C:\Program Files\Upromise\dca-ua.exe
O4 - HKCU\..\Run: [Upromise Tray] C:\Program Files\Upromise\UpromiseTray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra 'Tools' menuitem: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/27.38/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1230297902203
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1230295805125
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://samsclubus.pnimedia.com/upload/activex/v2_0_0_11/PCAXSetupv2.0.0.11.cab?
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

2 Re: Help with redirect to different web page? on Mon Dec 14, 2009 8:49 pm

DragonMaster Jay


Site Owner
Site Owner
Please download Malwarebytes Anti-Malware from here.

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

3 Re: Help with redirect to different web page? on Sun Dec 27, 2009 6:48 pm

kheops_raven


New Member
Thanks for all the help!! Much appreciated for you taking time out to lend a hand to fight jerks who want to infect machines-

Below is the log file that you created-

PS - Great picture for your avatar. Is that Elmore or Rowena's art?

------------------------------------------
------------------------------------------

Malwarebytes' Anti-Malware 1.42
Database version: 3441
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

12/27/2009 6:10:40 PM
mbam-log-2009-12-27 (18-10-40).txt

Scan type: Full Scan (C:\|F:\|)
Objects scanned: 265116
Time elapsed: 1 hour(s), 36 minute(s), 35 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 2
Registry Keys Infected: 18
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 14
Files Infected: 108

Memory Processes Infected:
C:\Program Files\SelectRebates\SelectRebates.exe (Adware.SelectRebates) -> Unloaded process successfully.

Memory Modules Infected:
C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (Adware.SelectRebates) -> Delete on reboot.
C:\Program Files\SelectRebates\SRebates.dll (Adware.SelectRebates) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shopathome.ietoolbar (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{462e4aec-db3b-4e69-af61-4f300d76255c} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e8daaa30-6caa-4b58-9603-8e54238219e2} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e8daaa30-6caa-4b58-9603-8e54238219e2} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e8daaa30-6caa-4b58-9603-8e54238219e2} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shopathome.ietoolbar.1 (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\selectrebatesuninstall (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\selectrebates (Adware.SelectRebates) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Common Files\WinTools (Trojan.WinTools) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\content (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\locale (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\defaults (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\defaults\preferences (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SahImages (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Cache (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\ImageCache (Adware.SelectRebates) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebatesDownload.exe (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\WinTools\iwuivj.wzg (Trojan.WinTools) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\WinTools\WToolsT.dll (Trojan.WinTools) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectAlerts.dat (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebates.exe (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebates.ini (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebatesA.dat (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebatesApi.exe (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebatesB.dat (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebatesBT.dat (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebatesUninstall.exe (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SRebates.dll (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SRFF3.dll (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome.manifest (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\install.rdf (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\content\options.js (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\content\options.xul (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\content\sahtoolbar.js (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\content\sahtoolbar.xul (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US\contents.rdf (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.dtd (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.dtd.skin (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.properties (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\3rdParty.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\add-folderplus.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\add-plussign.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\alert-blue.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\alert-red.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\bluebar.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\dollarsign.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\FindWords.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\gripper.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\icon-magnifying.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\invite.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\invite2.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-blue.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-gray.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-green.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-red.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Options.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\S.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\SAH-LogoHotSpots.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\SAH-logotext.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\SAH-mainlogo-v1.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\SAH-mainlogo-v2.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\sahtoolbar.css (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Scissors.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Search.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\shoppingcart.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\singleperson.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\star.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\thumb2.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Thumbs.db (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\toolbar-images-ALL.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Toolbar_HelpAndFeedback.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Wrench.png (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SahImages\bg-gradient.gif (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SahImages\button-close.gif (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SahImages\sah-logopop.gif (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Add.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\AdvancedOptions.html (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\basis.xml (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Basis.xml.dym (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Blank.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\button-CloseWindow.gif (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\icons.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Invite.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\i_clipboard.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\i_help.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\i_magnifying.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\logo.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\logo_24.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\logo_HotSpots.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\MyNew.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\MyNone.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\MyPage.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Rate.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\RightControls.dym (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\sah_logo_bars.gif (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Scissors.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Tools.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\Tools2.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\Toolbar\ImageCache\alert-red.bmp (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\basmc.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\cranti.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\dnsinet.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\dnsras.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\faxfont.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\faxip.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\faxplay.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\inetac.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\inetav.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\inettapi.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\inetw.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\libmfc.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\libnet.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\pc.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\pcav.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\pcurl.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\sysdrv.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\sysimg.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\vbcab.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\wdrv.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\wfax.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\wwms.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

4 Re: Help with redirect to different web page? on Sun Dec 27, 2009 7:44 pm

DragonMaster Jay


Site Owner
Site Owner
Neither one. Check out my profile. You will see the Deviant Art link.

Download SuperAntiSpyware

  • Load SuperAntiSpyware and click the Check for updates button.
  • Once the update is finished click the Scan your computer button.
  • Check Perform Complete Scan and then next.
  • SuperAntiSpyware will now scan your computer and when its finished it will list all the infections it has found.
  • Make sure that they all have a check next to them and press next.
  • Click finish and you will be taken back to the main interface.
  • Click Preferences and then click the statistics/logs tab. Click the dated log and press view log and a text file will appear.
  • Copy and paste the log onto the forum.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 1]

Permissions in this forum:
You cannot reply to topics in this forum