Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Download Now:
[Inactive] Redirect virus won't die
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
[Inactive] Redirect virus won't die
Hi,
I'm running WIN XP, SP 2. Recently got this re-direct virus affecting both Firefox and IE. I've run complete scan/repair processes with: AVG Super AV Malware Bytes Sometimes it finds infected items and fixes them but this thing keeps coming back. I really don't want to do a new OS install as my drivers are very tricky to load on this machine. I've also tried numerous other fixes including this one (http://www.techspot.com/vb/topic127425.html) but I'm not sure I'm doing right as I don't know if all these log files they refer to are general or relative to the computers of the person in the thread.. I did run some of these and got the following logs in the attached files. I'm going nuts with this! Is there any real solution to this or should I just bite the bullet and re-install Windows? |
|
#2
|
||||
|
||||
|
Download the MBR Rootkit Detector: http://www2.gmer.net/mbr/mbr.exe to your desktop.
* Doubleclick mbr.exe and follow prompts (Vista users: right click on mbr.exe and click "Run As Administrator"). * A black DOS window will quickly appear then disappear. * When mbr.exe is finished it will create a log on your desktop. * Copy and paste contents of that log (mbr.log) file to your next reply. |
|
#3
|
|||
|
|||
|
Log File
To protect your privacy, remote images are blocked in this message. Display images
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK I don't know what this is but thanks! |
|
#4
|
||||
|
||||
|
How is redirection issue?
|
|
#5
|
|||
|
|||
|
Issue
Basically, either in firefox or IE. I google anything. When I click on the link it takes me to an alternate page. Also seems to happen with any other search engine such as Yahoo etc.
BTW - I am using XP Thanks |
|
|
|
#6
|
||||
|
||||
|
Uninstall Combofix:
Go Start > Run [Vista users, go Start>"Start search"] Type in: Combofix /Uninstall Note the space between the "Combofix" and the "/Uninstall" Click OK (Vista users - press Enter). Restart computer. ======================================================================= Download Kenco.exe to your desktop
|
|
#7
|
|||
|
|||
|
no reboot
Kenco by jpshortstuff (31.12.09.1)
Log created at 21:12 on 09/02/2010 (JF) ========== Task Unlocker ========== ========== KencoScan ========== ========== C:\WINDOWS\Tasks ========== RegCure Program Check.job -> [18:07 08/02/2010] 384 bytes RegCure Startup.job -> [18:07 08/02/2010] 372 bytes RegCure.job -> [18:07 08/02/2010] 366 bytes -=E.O.F=- |
|
#8
|
|||
|
|||
|
additional
just confirmed....redirect is still occuring
|
|
#9
|
||||
|
||||
|
Download RootRepeal.zip (Mirror1, Mirror2) and unzip it to your Desktop.
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead. |
|
#10
|
|||
|
|||
|
Very Strange
I downloaded and ran Rootrepeal. At the end of the process my system automatically restarted. I saw no report and the only thing I was left with was a .dat file on my desktop....Attached.
Thoughts? |
|
#11
|
||||
|
||||
|
Please, re-run it.
|
|
#12
|
|||
|
|||
|
Re-Run
i did actually run it three times with the same result. I'll try again. I'll sit and watch it this time.
Thanks |
|
#13
|
||||
|
||||
|
OK, leave it for now...
Download OTL to your Desktop. * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. * Under the Custom Scan box paste this in: netsvcs %SYSTEMDRIVE%\*.exe /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys /md5stop %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
|
|
#14
|
|||
|
|||
|
OTL & Extras Logs
Sorry...OTL and Extras Logs were too long to paste and thus not permitted here....I attached them....
|
|
#15
|
||||
|
||||
|
Please, uninstall RegCure. No registry tools are ever recommended.
========================================================================= I recommend, you remove NVIDIA ActiveArmor hardware firewall built into nVidia nForce motherboard chipsets. It's known for causing a lot of problems. Open Notepad. Copy, and paste text below: Quote:
Run it, by doubleclicking on nvidia.bat Restart computer. ========================================================================== Run OTL
|
|
#16
|
|||
|
|||
|
Latest Info
I performed the procedure you noted above and received the following log. Not sure what this means however?
---- All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4}\ not found. C:\WINDOWS\system32\drivers\kgpcpy.cfg moved successfully. C:\SZKGFS.dat moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: JF ->Temp folder emptied: 1910838 bytes ->Temporary Internet Files folder emptied: 9724995 bytes ->Java cache emptied: 70324051 bytes ->FireFox cache emptied: 64320491 bytes ->Apple Safari cache emptied: 5635135 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2142714 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 65536 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 67 bytes RecycleBin emptied: 119582098 bytes Total Files Cleaned = 261.00 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.1.28.0 log created on 02112010_105328 Files\Folders moved on Reboot... C:\Documents and Settings\JF\Local Settings\Application Data\Mozilla\Firefox\Profiles\qcos0x7y.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\JF\Local Settings\Application Data\Mozilla\Firefox\Profiles\qcos0x7y.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\JF\Local Settings\Application Data\Mozilla\Firefox\Profiles\qcos0x7y.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\JF\Local Settings\Application Data\Mozilla\Firefox\Profiles\qcos0x7y.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\JF\Local Settings\Application Data\Mozilla\Firefox\Profiles\qcos0x7y.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\JF\Local Settings\Application Data\Mozilla\Firefox\Profiles\qcos0x7y.default\XUL.mfl moved successfully. File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot. Registry entries deleted on Reboot... |
|
#17
|
|||
|
|||
|
Additionally
I was prompted on re-boot to run OTL so I did the quick scan again. Posted here. Probably not necessary?
It's attached here. |
|
#18
|
||||
|
||||
|
How is redirection issue?
|
|
#19
|
|||
|
|||
|
Very Strange....
Well, the re-direction is still happening. Man, this is a bad infection. I'm beginning to wonder if it's worth persuing or given the time I'm spending it's worth biting the bullet and doing a re-install of windows....Would have already if the drivers on this Avid system were not so fussy.
What do you think? I continue to (most of the time but not always) get redirected from the link I have searched to something completely irrelevant. Also odd is that when I click "back" on the browser it usually, but not always, takes me to the originally intended page. Your thoughts? |
|
#20
|
|||
|
|||
|
Oops...Also
did you see the logs that I uploaded? Do they mean anything to you?
|
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
[Inactive] Google Search Redirect - Followed 8 Steps (Logs Attached)
|
2 | Virus and Malware Removal | ||
[Inactive] Links from google searches redirect me
|
1 | Virus and Malware Removal | ||
[Inactive] Virus Removal
|
6 | Virus and Malware Removal | ||
[Inactive] Help with Virus Removal Please
|
2 | Virus and Malware Removal | ||
[Inactive] IE Problem or Virus?
|
2 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 06:21 PM.



[Inactive] Google Search Redirect - Followed 8 Steps (Logs Attached)