Hello,

I have a laptop with windows xp sp3 on it. I removed a pretty big malware program with malwarebytes. It got rid of the program for the most part but there is one underlaying factor.

Firefox and Internet explorer 7 both redirect to and other random sites anytime you go anywhere on both browsers.

I have tired everything known to the net, not one of which were able to detect or remove anything.

I believe it is a hidden driver but Im not sure. I looked at them all and they all seem to be good.

I have tried:
Combofix
smitfraud
malwarebytes
SAS
Panda RootKit
Trendmicro rootkit
sdfix
webroot
and more

you name it, ive tried it. All come back with nothing.

Hitman pro 3.5 did state that it detected a hidden driver in the hard drive layer with the allias of "allureon tld3"... I believe. But again can't find a hidden driver that is bad.

Someone help!

Dani AI

Generated

Both browsers redirecting to the same external site usually means the problem is below the browser: altered name resolution (HOSTS/DNS), a system proxy or LSP/Winsock/driver that intercepts HTTP, or a router/ISP-level DNS change. indicates many scanners found nothing while HitmanPro reported a suspicious hidden driver; is correct to ask for logs and to caution about running powerful tools unsupervised.

Quick, safe triage to narrow scope (do these first):

  • Check whether other devices on the same network are affected (if yes, suspect the router/ISP).
  • Boot Windows into Safe Mode with Networking and retest the redirect.
  • Inspect the HOSTS file and browser/IE proxy settings.
  • Temporarily point DNS to a known resolver (for testing only).

Useful commands to run from an elevated command prompt:

ipconfig /all
nslookup stopmalwaresite.com
netstat -ano | findstr :80
netsh winsock reset
ipconfig /flushdns

Deeper checks if the redirect remains:

  • Use Sysinternals Autoruns (Drivers/Services tabs) and export the list to look for unusual drivers or autostarts.
  • Use Process Explorer/netstat to identify which process is handling outbound connections to the redirect target.
  • Inspect the Winsock/LSP catalog: netsh winsock show catalog.
  • Log into the router admin panel and verify DNS servers; restore factory defaults and update firmware if DNS has been altered.

Cautions and recovery path:

  • Avoid running aggressive removal tools without producing logs first (as noted). Back up personal files. If a driver/rootkit persists after offline rescue scans, a clean reinstall is the most reliable cure. For focused analysis, the most useful artifacts are: Malwarebytes and HitmanPro logs, Autoruns export, output of ipconfig /all, netsh winsock show catalog, netstat -ano, and driverquery /v.

You are contradicting yourself here...I removed a pretty big malware program with malwarebytes.and then you say...I have tired everything known to the net, not one of which were able to detect or remove anything.
Several of the programs you ran are for one specific infection and if you don't HAVE that infection then there is nothing for it to remove...i.e....smitfraud and sdfix
You ran Combofix without being asked to run it which is against ALL instructions for it.http://www.bleepingcomputer.com/forums/index.php?showtopic=273628&hl=combofix

ComboFix is an Anti-Malware tool used by advanced malware technicians
specifically trained in its use.

Please DO NOT USE COMBOFIX on your own without supervision!!!

We can't offer any assistance until we see some logs. You obviously must have some and we need to see them ALL beginning with the MBA-M log.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.