HELP! IE and FF redirecting to dust-cat site then stop working.

the avast ‘malicious site’ block is still popping up. it happens in internet explorer and firefox and happens everything i search for something in yahoo, google, bing, msn…basically any search engine then try to click on one of the links. it happens when i’m going to perfectly safe sites. I tried searching ‘avast’ in yahoo then when i went to click on the result that would take me to www.avast.com i was redirected to a site called ‘dailymallwinners’ or something like that…it wanted me to click on something because it said i won an ipad 3.
i hate to say it but i’m getting really frustrated that none of these things are working, and we’ve been working on this all week. i’m still having the same issues as when i put up my first post.

what should i do?

OK lets check a different area

[*]Run OTL
[*]Select All Users
[*]Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%*.exe
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
C:\Windows\assembly\tmp\U*.* /s
CREATERESTOREPOINT

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[]When the scan completes, it will open one notepad windows.
[
]Attach this log

here you go.
let me know what to do next.
thanks!

The problem that I see is that there is a proxy being set in IE continually

Do you recognise these two programmes

C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\Common Files\JDA

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810 [2012/01/22 23:13:20 | 000,000,635 | ---- | C] () -- C:\Users\Christopher\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

hi essexboy,

i confirmed this…

C:\Program Files\IDT\WDM\sttray.exe

This is for IDT audio and is innocent…i am also running IDT audio.

thanks true indian, i’ll wait to run this fix.

essexboy i’ll wait for instructions from you before i continue

Yes continue - they are not included in the fix ;D

Any information on JDA ?

thanks. here is the log from the quick scan.

how we looking? tonight is the first night in weeks that i haven’t been redirected to other sites, however the malicious url blocker from avast did still pop up, but i was still allowed to view my desired site.

Those proxy settings are returning - lets try a manual reset

  1. Under “Tools” in the browser tool bar select “Internet Options”.
  2. In the “Internet Options” window that pops up, click the “Connections” tab at the top.
  3. Click “LAN Settings” near the bottom of the “Connections” section.
  4. If the “Proxy server” checkbox is marked with a check, click it to deselect/uncheck it.
  5. Click “Ok” to close the “Local Area Network (LAN) Settings” window.
  6. Click “Ok” to close the “Internet Options” window.

ok!! now that made a difference!
i did another OTL quick scan after that as well. let me know if i should check anywhere else or run anything else you can check to make sure i’m looking good.

i’ll give it a couple of days and let you know if anything ‘virus-ey’ happens.

thanks!!!

http://www.google.co.in/search?sourceid=chrome&ie=UTF-8&q=JDA

Just run a quick scan as I am only interested in the proxy setting

attached here is a quick scan from OTL, the problem is still happening. what do you see?

They are back… You never did answer about JDA so unless you say stop it is going… Especially as it activates on start

This is one of those miscreants that hides in unusual places and we need to hunt it down

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810 IE - HKU\S-1-5-21-2773036655-1795469504-3343648015-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = [2012/01/18 20:39:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDA [2012/01/18 20:39:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\JDA

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

JDA is a spaceplanning program for my job. Sorry I didn’t see that you asked me that before.

Attached is the most current scan.

I see you also have AVG installed could you remove one of the antivirus programmes please

At the moment I cannot see where the redirect is coming from

So I will look deeper

Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named )

First we will run a virus scan

Click the cog in the upper right

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/AVPfront.gif

Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/avpsettings.gif

Allow AVP to delete all infections found
Once it has finished select report tab (last tab)
Select Detected threats report from the left and press Save button
Save it to your desktop and attach to your next post

Now the Analysis

Rerun AVP and select the Manual Disinfection tab and press Start Gathering System Information

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/AVPAnalysis.gif

On completion click the link to locate the zip file to upload and attach to your next post

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/AVPZiplocation.gif

Megaupload

here’s the post from the virus scan. it found an infection. i can’t figure out how to post the xip file that the second scan produced. let me know if you know how to do this.

Could you upload it to mediafire and post the sharing link please

http://www.mediafire.com/