also @ TechSpot: Next iPad rumored to be 33% lighter and thinner thanks to new touchscreen tech

8 Step search result hijack help

Discussion in 'Virus and Malware Removal' started by EMS0525, Dec 10, 2009.

  1. kimsland Ex-TechSpotter Posts: 18,353

  2. EMS0525 Newcomer, in training Posts: 39

    Why can there be one program that scans and finds everything... why is there a dozen things you have to scan with?

    So far the eset found 3: win32/bagle.gen.zip.worm
  3. kimsland Ex-TechSpotter Posts: 18,353

    lol :)

    Good point

    If I made a Malware scanner, I'd be making one that does everything
    It might take 4 hours to scan, but who cares !!!
  4. EMS0525 Newcomer, in training Posts: 39

    Well it went all night and cleaned 4 items.
  5. EMS0525 Newcomer, in training Posts: 39

    ok, next step? Still not fixed. This is ridiculous...
  6. kimsland Ex-TechSpotter Posts: 18,353

    I have done a bit of research, this will do it ;)
    • Download The Avenger by Swandog46 from HERE.
    • Unzip/extract it to a folder on your desktop.
    • Double click on avenger.exe to run The Avenger.
    • Click OK.
    • Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
    • Copy all of the text in the below code box to the clipboard by highlighting it and then pressing Ctrl+C.
    • In the avenger window, click the Paste Script from Clipboard, [IMG] button.
    • You will be asked Are you sure you want to execute the current script?.
    • Click Yes.
    • You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
    • Click Yes.
    • Your PC will now be rebooted.
    • Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
    • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
    • Please attach[IMG] this log, along with a new HijackThis log in your next reply.

    EDIT: This is for Vista only
     
  7. EMS0525 Newcomer, in training Posts: 39

    after i get the are you sure you want to execute the current script and click yes, i get a box that says "Error: Invalid script. A valid script must begin with a command directive. Aborting execution!"
  8. kimsland Ex-TechSpotter Posts: 18,353

    You need to copy both lines
    Including the "Files to move: "
  9. EMS0525 Newcomer, in training Posts: 39

    oooooooooooooooooops
  10. EMS0525 Newcomer, in training Posts: 39

    sorry, one moment
  11. EMS0525 Newcomer, in training Posts: 39

    As you can see, I am not Eric. This is his wife Krissy. He is at work having do all of this stuff! Sorry, im messing it all up!
  12. kimsland Ex-TechSpotter Posts: 18,353

    What the hell

    I gave you Vista command, god knows why, must have gone dumb for a sec
    C:\WINDOWS\ServicePackFiles\i386 That's where atapi.sys lives

    But we need to check something first:

    Start > Run > cmd /c start /min cmd /c "PEV -l %systemdrive%\atapi.sys >Log.txt&Log.txt&del Log.txt"
    Wait about 30 secs for this log to show. Please post this log file to a new reply
  13. EMS0525 Newcomer, in training Posts: 39

    here it is
  14. kimsland Ex-TechSpotter Posts: 18,353

    Look no matter how that turns out, just do the following: (I'm really confident now ;))

    Lets try another option to remove this infection

    Download MBR.exe and save it to your c:\ root directory, so its at c:\mbr.exe

    Click on Start > Run and type in cmd and click OK.

    Type in: c:\mbr.exe -f and then press the Enter key

    Restart
  15. EMS0525 Newcomer, in training Posts: 39

    whats next?
  16. EMS0525 Newcomer, in training Posts: 39

    My wifes at home doing this stuff, and im here at work, i can thank you enough for helping us through this. It doesnt seem that bad like id have to reformat the comp just bad enough to be annoying, and no programs were removing it. Thank you.
  17. kritius TechSpot Guru Posts: 2,087

    I wouldn't try using the -f command without seeing the output of -t first.
  18. kimsland Ex-TechSpotter Posts: 18,353

    I've safely done the f command before

    Is it still redirecting?
  19. EMS0525 Newcomer, in training Posts: 39

    yes it is.:(
  20. kimsland Ex-TechSpotter Posts: 18,353

    kritius its beyond me :(

    HELP

    Unless its Erunt doing it?