1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Same Site Opens In A Browser Regardless What Was Typed In The Address Bar

Discussion in 'General Malware And Security' started by AliBali, Jul 30, 2011.

  1. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    Looks like I have a complex problem:
    Whatever I type in the address bar,whatever link I click, the same site opens in Fox ( and IE). The site is "Time Warner Cable - Automated Provisioning"
    I downloaded Malwarebytes Anti-Malware from a flash drive, but when I tried to launch Malwarebytes Anti-Malware I got a message: "Windows cannot access the specified device,path or file. You may not have appropriate permissions to access the item."
    I have: Windows XP Media Center, SP-3, VAIO laptop.
    I got a feeling its a walware or virus. Can someone help me?
     
  2. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    First, welcome to Computer Help Forums! :)

    Sorry for the late reply but we were doing a major upgrade on Saturday.

    I agree that you appear to be infected by something. Please have a look at this post so that you can prepare to have this looked at by our Malware Removal Experts http://computerhelpforums.net/topic/13814-preparation-for-malware-removal-help/
     
  3. woodyblade

    woodyblade Inactive Staff Member

    Joined:
    Dec 20, 2009
    Messages:
    720
    Operating System:
    Windows 8
    I had a search and it seems to be a problem Time Warner have had with their cable service for a few years heres a few links with multiple people having the same problem, thats assuming you have Time Warners cable service?

    http://www.dslreport...ed-Provisioning

    http://www.dslreport...ed-provisioning

    http://www.dslreport...ed-provisioning

    If so you should try resetting/rebooting your modem & router (if applicable) and see if you can connect to any site, otherwise phone up Time Warner Tech Support, they should be able to confirm it's a problem on their end and be fixing it.
     
  4. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Nice catch Woodyblade! Hopefully that will resolve the issue and is not malware related.
     
  5. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    Thank you for response.I was thinking of that possibility, but I have another computer on the same modem and it works fine.
     
  6. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    To Woodyblade

    I am not TW costomer, I have ATT service., another computer connected to the same modem works fine; also, I reconnected my laptop (troubled one) to neighbor's
    wireless network and stil have the same problem.
     
  7. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    I also tried to reset the modem
     
  8. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    Looks like I have a complex problem:
    Whatever I type in the address bar,whatever link I click, the same site opens in Fox ( and IE). The site is "Time Warner Cable - Automated Provisioning"

    I had a search and it seems to be a problem Time Warner have had with their cable service for a few years heres a few links with multiple people having the same problem, but I am not TW costomer, I have ATT service., another computer connected to the same modem works fine; also, I reconnected my laptop (troubled one) to neighbor's wireless network and stil have the same problem.


    I downloaded Malwarebytes Anti-Malware from a flash drive, but when I tried to launch Malwarebytes Anti-Malware in 5 seconds it disapeared, then I got a message: "Windows cannot access the specified device,path or file. You may not have appropriate permissions to access the item."The same happened with OTL. It started working, in 1-2 sec. it disapeared and now every time I try to launchn it , I got this message.
    I was able to run aswMBR and have a log (attached).

    I have: Windows XP Media Center, SP-3, VAIO laptop.
    I got a feeling its a malware or virus. Can someone help me?
     

    Attached Files:

  9. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Please only start one thread or topic on the same problem. I have merged them into one.
     
  10. woodyblade

    woodyblade Inactive Staff Member

    Joined:
    Dec 20, 2009
    Messages:
    720
    Operating System:
    Windows 8
    Ok just going by the information we have, if you had mentioned another computer connected fine then I wouldn't have needed to suggest what I did, anyway one last thing to suggest before it moves on to Starbuck who will help you remove the possible virus/malware, if you could run a Traceroute on both computers we should have an idea what's going on in regards to the webpage redirections.

    Go to Start > Run and then type in cmd

    You should get a window like this

    cmd.png

    Then type in the following command, you can replace the website with any website you like I just put that there as an example, use the same website on both computers.

    Code:
    tracert bbc.co.uk
    
    You should get this data once the traceroute is complete.

    View attachment traceroute.gif

    Then press Alt+PrtSc and paste the screenshot of that window in Paint, remember to blank out your ISP and IP address like I have and your username if you wish, just use Paint and put a black square over them.
     
  11. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    woodyblade, sorry for stupid question, but hoe can i place Paint image in forum window?

    I've done as you asked, basically its all timed out.
     
  12. woodyblade

    woodyblade Inactive Staff Member

    Joined:
    Dec 20, 2009
    Messages:
    720
    Operating System:
    Windows 8
    If you select "More Reply Options" directly to the bottom right of this post (below the quick reply box), you will get what is called a Full Reply window on that you will see an Attach Files section just below where you write your post, attach the image/s and once they have finished uploading to the board you will see next to the right of them an "add to post" and "delete" options just select add to post and a little bit of code will be added to your post which will show us the image.

    Anyway there isn't such a thing as a stupid question, I had to ask these type of questions at one point in time.
     
  13. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
  14. woodyblade

    woodyblade Inactive Staff Member

    Joined:
    Dec 20, 2009
    Messages:
    720
    Operating System:
    Windows 8
    Very odd that every connection attempt times out, basically to me it seems like your not even connected to the internet, you might be connected to the modem/router but the modem isn't having any of it.
    The website auto-prov.rr.com is mentioned first, your local IP addresses would usually be mentioned if you were connected to the internet properly.

    There was an IP address in there next to the BBC website, it wasn't the BBC website IP address which is 212.58.241.131, in your CMD window it was showing 24.28.193.6, which I checked and it resolved to a Roadrunner LLC owned site, does that happen to be your internet provider? It seems Roadrunner were formerly part of AT&T broadband which seems to have been split off between Comcast and Time Warner, Time Warner look to own Roadrunner
    Does this happen to be the only screen you see when you try to go to websites? - http://apweb.central.rr.com/ap_index

    If so then you need to phone Roadrunner, AT&T or whoever is the cable provider on your bills and provide your MAC address to them so that computer is allowed on the Internet, this seems most likely having seen those traceroute commands going nowhere at all.

    EDIT: I might be grabbing the wrong end of the stick altogether with this internet provider problem, but logically to me it seems the most plausible based on the information we have got, that traceroute puts me further off a malware problem, why would someone code malware to block you entirely from the internet (though I wouldn't put it past anyone in todays world), malware and spam in the vast majority of cases is written for profit, only a small percentage is written for mischievous acts.
     
  15. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    To woodyblade.
    on your link is exactly rhe screen I see on my laptop. I have same assumptions about reason. Another thing confuses me is that I can not open any anti-malware program and that message "Windows cannot access the specified device,path or file. You may not have appropriate permissions to access the item."
     
  16. AliBali

    AliBali

    Joined:
    Jul 30, 2011
    Messages:
    9
    Location:
    Los Angeles
    Operating System:
    Windows XP Professional
    Woodyblade, I am so sorry. my modem was reset and the laptop didn't have a internet connection. That's why Tracerout showed timed out for all pings. Now I have a new screen for you to help me with :rolleyes: . I got a feeling we can make it this time.
    Thank's
     

    Attached Files:

  17. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Alibali,

    It certainly wouldn't hurt to run some scans and see if we can throw up any reason for this.

    If you can't access the internet from your PC, you can download these programs using another system and then transfer them by way of a USB stick.


    Step 1
    Download RogueKiller and save it to your desktop.
    • Close all the running processes
    • Double click RogueKiller icon to run the program
      Vista/Win7 users should right click the icon and select Run as Administrator.
    • When prompted, type 1 (SCAN) and then press Enter
    • A report will open, please copy and paste this report in your next reply.
    A copy of the RKreport.txt can be found on your desktop.

    Note:
    If RogueKiller is blocked, do not hesitate to try running it again.
    If it still fails to run, right click on the downloaded icon and select 'Rename'.....rename it to winlogon and try again.


    Step 2
    • Download OTL to your desktop.
      right click on the link and select 'Save Link/Target As'.

      if you have problems, try this download link:
      OTL
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check
    .

    .
    .

    • Now copy the lines in bold below.

      netsvcs
      msconfig
      %SYSTEMDRIVE%\*.*
      %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\System32\config\*.sav
      %PROGRAMFILES%\*
      %USERPROFILE%\..|smtmp;true;true;true /FP
      HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
      hklm\software\clients\startmenuinternet|command /rs
      hklm\software\clients\startmenuinternet|command /64 /rs
      CREATERESTOREPOINT


    • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.

      .
      .
    • Click the Run Scan button.

      [​IMG]
    • Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.



    In your next reply, please submit:
    RKreport.txt
    both reports from OTL

    Thanks.
     
    Last edited by a moderator: Feb 4, 2014
  18. woodyblade

    woodyblade Inactive Staff Member

    Joined:
    Dec 20, 2009
    Messages:
    720
    Operating System:
    Windows 8
    Well that ping got through successfully and there doesn't seem to be anything wrong with the route it has taken from what I can gather, so from my point view it seems a look for malware is the best way to go for now, Starbuck will continue from here once you've run those scans and replied back.
     

Share This Page