Redirecting problem 8-steps completed

Solved
By scheng07
Jun 13, 2010
Topic Status:
Not open for further replies.
  1. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    the scan came up clean., so i couldn't get a report

    Thank you
  2. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    Please, download fresh copy of Combofix and post new log.
  3. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    Are you still out there?
  4. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    Sorry! I been busy with work. Here is the combofix log.

    Thank you

    Attached Files:

  5. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    Download Bootkit Remover to your Desktop.

    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
    • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.
  6. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    here is what was on the bootkit remover screen

    Attached Files:

  7. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    Open Notepad
    Copy and paste following text into Notepad:
    Code:
    @ECHO OFF
    START remover.exe fix \\.\PhysicalDrive0
    EXIT
    Go FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES
    Then in the FILE NAME box type fix.bat.
    Save fix.bat to your Desktop.

    Run fix.bat by double clicking.
    You may see a black box appear; this is normal.

    When done, run remover.exe again and post its output.

    Restart computer and check for redirection.
  8. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    I would get an error message after running the fix.bat. Attach

    Attached Files:

  9. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    That's odd.
    I assume, you copied/pasted my script, instead of typing it manually. I always worry about some "typo".

    If you did it correctly, restart computer and try again.
    If it still doesn't work, we'll use another way.
    I'm glad, we, finally, found very possible culprit.
  10. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    it doesn't work.

    Thank you
  11. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    If you have Vista DVD...

    start with step 2

    If you don't have Vista DVD...

    1. Create Vista Recovery Disc.

    Option 1:
    http://www.c4consulting.com.au/soluctions/vista/VISTA SOLUCTIONS.htm

    Option 2:
    Download Vista Recovery Disc iso image: http://neosmart.net/blog/2008/windows-vista-recovery-disc-download/
    Burn it to CD, or DVD: http://neosmart.net/wiki/display/G/Burning ISO Images to a CD or DVD

    2. Boot from created disk.
    At first screen click on Repair your computer:
    [​IMG]
    This will bring you to a new screen where the repair process will look for all Windows Vista installations on your computer. When done you will be presented with the System Recovery Options dialog box:
    [​IMG]
    After this, it will present you with a list of options including startup repair, system restore and command prompt:
    [​IMG]
    Select Command Prompt

    Type in:
    bootrec /FixMbr
    and then press Enter

    Once completed then type Exit, press Enter and restart computer.

    Re-run remover.exe and post fresh log.
     
  12. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    I can't seem to get the CD to boot. I keep getting files. I tried option 2.

    Thank you
  13. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    I'm not sure, if I understand the above.
  14. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    oh, sorry. I meant that when I try to boot the CD, a folder opens with the files in it.
  15. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    How exactly do you boot from that CD?
    Tell me, step by step.
  16. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    well, I place the CD into the computer and from there the computer opens up a folder with files in it.

    Attached Files:

  17. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    OK.
    You have to put the CD in and restart computer.
    If the boot order is correct, your computer should automatically boot to the CD, or you'll see a message:
    "Press any key to boot from CD"
  18. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    here is the new bootkit log

    Thank you

    Attached Files:

  19. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    Excellent :)
    Let me go through our topic to see where we stand right now...
  20. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    OK. How is redirection issue?
  21. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    so far google chrome haven't been redirecting, but firefox still have some redirecting.

    Thank you.
  22. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    Restart computer and check again.
  23. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

  24. Broni

    Broni Malware Annihilator Posts: 46,179   +251

    Close Firefox. Go Start>All Programs>Mozilla Firefox, click on Mozilla Firefox (safe mode). Same thing?
  25. scheng07

    scheng07 Newcomer, in training Topic Starter Posts: 44

    yep same thing
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.