also @ TechSpot: Google quietly adds conversational search to Chrome 27

Redirecting problem 8-steps completed

Discussion in 'Virus and Malware Removal' started by scheng07, Jun 13, 2010.

  1. scheng07 Newcomer, in training Posts: 44

    that page is like the intermediate page. that page redirects me to random pages that has nothing to do with what I'm looking for.
  2. Broni Malware Annihilator Posts: 39,324   +175

    Open Windows Explorer.
    Navigate to:
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC
    You'll see hosts file there.
    Open it with Notepad.
    Add following line:

    Code:
    127.0.0.1 http://results.google-analytics.com
    Go File>Save

    Restart computer.

    Check for redirections.
  3. scheng07 Newcomer, in training Posts: 44

    So do I save it as a notepad file or the original file?
  4. Broni Malware Annihilator Posts: 39,324   +175

    When you click File>Save, it'll save as original file.
  5. scheng07 Newcomer, in training Posts: 44

    It doesn't do that for me. I get a message that says Cannot create the C:\WINDOWS\System32\drivers\etc\Hosts file.
  6. scheng07 Newcomer, in training Posts: 44

    I can't save the file.
     
  7. Broni Malware Annihilator Posts: 39,324   +175

  8. scheng07 Newcomer, in training Posts: 44

    it seems to be working for firefox, but for google chrome it still redirects.
    google chrome redirects to http://results5.google.com/.

    I'll update you if there is any changes with firefox.
    Thank you
  9. scheng07 Newcomer, in training Posts: 44

    Never mind it still redirects.
  10. Broni Malware Annihilator Posts: 39,324   +175

    Download Dr.Web CureIt to the desktop:
    ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
    Alternative download: http://majorgeeks.com/Dr.Web_CureIT_d4783.html

    • Doubleclick the drweb-cureit.exe file and click Scan to run express scan. Click OK in pop-up window to allow scan.
    • This will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it. This is only a short scan.
    • Once the short scan has finished, select Complete scan.
    • Click the green arrow [IMG] at the right, and the scan will start.
    • Click Yes to all if it asks if you want to cure/move the file.
    • When the scan has finished, in the menu, click File and choose Save report list
    • Save the report to your desktop. The report will be called DrWeb.csv
    • Close Dr.Web Cureit.
    • [color=5]Important![/color] Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    • Copy and paste that log in the next reply. You can use Notepad to open the DrWeb.cvs report.

    NOTE. During the scan, pop-up window will open asking for full version purchase. Simply close the window by clicking on X in upper right corner.
  11. scheng07 Newcomer, in training Posts: 44

    the scan came up clean., so i couldn't get a report

    Thank you
  12. Broni Malware Annihilator Posts: 39,324   +175

    Please, download fresh copy of Combofix and post new log.
  13. Broni Malware Annihilator Posts: 39,324   +175

    Are you still out there?
  14. scheng07 Newcomer, in training Posts: 44

    Sorry! I been busy with work. Here is the combofix log.

    Thank you

    Attached Files:

  15. Broni Malware Annihilator Posts: 39,324   +175

    Download Bootkit Remover to your Desktop.

    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
    • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.
  16. scheng07 Newcomer, in training Posts: 44

    here is what was on the bootkit remover screen

    Attached Files:

  17. Broni Malware Annihilator Posts: 39,324   +175

    Open Notepad
    Copy and paste following text into Notepad:
    Code:
    @ECHO OFF
    START remover.exe fix \\.\PhysicalDrive0
    EXIT
    Go FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES
    Then in the FILE NAME box type fix.bat.
    Save fix.bat to your Desktop.

    Run fix.bat by double clicking.
    You may see a black box appear; this is normal.

    When done, run remover.exe again and post its output.

    Restart computer and check for redirection.
  18. scheng07 Newcomer, in training Posts: 44

    I would get an error message after running the fix.bat. Attach

    Attached Files:

  19. Broni Malware Annihilator Posts: 39,324   +175

    That's odd.
    I assume, you copied/pasted my script, instead of typing it manually. I always worry about some "typo".

    If you did it correctly, restart computer and try again.
    If it still doesn't work, we'll use another way.
    I'm glad, we, finally, found very possible culprit.
  20. scheng07 Newcomer, in training Posts: 44

    it doesn't work.

    Thank you