Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
|
|||||||
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
Google redirect
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Google redirect
When I do a google search, I get redirected to search sites such as info.com,informationgetter.com,on one
web.com,address.com etc. I did the 8Steps to no avail. I'm fresh to forums so I hope I've done this right. Just like the Colts, I took a wrong turn and missed step #3. However, I corrected my direction and posting the current set of logs. Very sorry. Last edited by prybar3; 02-08-2010 at 11:07 AM.. Reason: Posting new logs |
|
#2
|
||||
|
||||
|
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
NOTE 2. If Combofix asks you to update the program, always do so.
Make sure, you re-enable your security programs, when you're done with Combofix. DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!! |
|
#3
|
|||
|
|||
|
Per your instructions please find attached the ComboFix log and a new Hijack This log. Thanks in advance.
|
|
#4
|
||||
|
||||
|
1. Please open Notepad
2. Now copy/paste the entire content of the codebox below into the Notepad window: Code:
KillAll:: MBR:: 3. Save the above as CFScript.txt 4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. ![]() 5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
|
|
#5
|
|||
|
|||
|
Broni-please dumb this down for me. Where do I the "killAll" and the"MBR" codes from?
|
|
|
|
#6
|
|||
|
|||
|
Please find the attached logs as requested. Thanks
|
|
#7
|
||||
|
||||
|
Quote:
|
|
#8
|
|||
|
|||
|
Please see post #6. Sorry for the confusion.
|
|
#9
|
||||
|
||||
|
How is redirection issue and what browser is getting redirected?
Download the MBR Rootkit Detector: http://www2.gmer.net/mbr/mbr.exe to your desktop. * Doubleclick mbr.exe and follow prompts (Vista users: right click on mbr.exe and click "Run As Administrator"). * A black DOS window will quickly appear then disappear. * When mbr.exe is finished it will create a log on your desktop. * Copy and paste contents of that log (mbr.log) file to your next reply. |
|
#10
|
|||
|
|||
|
Redirection issue same as before. I just did a search for "2010 Saturn"-google presented me with search results-I clicked on "2010 Saturn", www.kbb.com. That took me to http://hotjobs.yahoo.com(Crazy isn't it?) I am using IE 8 version 8.0.6001.18702. Please find the mbr log you requested.
|
|
#11
|
||||
|
||||
|
Which browser is getting redirected?
Quote:
![]() Uninstall Combofix: Go Start > Run [Vista users, go Start>"Start search"] Type in: Combofix /Uninstall Note the space between the "Combofix" and the "/Uninstall" Click OK (Vista users - press Enter). Restart computer. ===================================================================== Download Kenco.exe to your desktop
|
|
#12
|
|||
|
|||
|
Please find Kenco log attached.
|
|
#13
|
||||
|
||||
|
Download RootRepeal.zip (Mirror1, Mirror2) and unzip it to your Desktop.
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead. |
|
#14
|
|||
|
|||
|
Please find attached RootRepeal report.
|
|
#15
|
||||
|
||||
|
Looks good too...
Download OTL to your Desktop. * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. * Under the Custom Scan box paste this in: netsvcs %SYSTEMDRIVE%\*.exe /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys /md5stop %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
|
|
#16
|
|||
|
|||
|
The OTL.txt is 42714 characters-too long to post here. adding as an attachment ok?
|
|
#17
|
|||
|
|||
|
The OTL "Extras.txt" is 19686 characters long-adding as an attachment ok?
|
|
#18
|
||||
|
||||
|
1. Please download The Avenger to your Desktop.
Code:
Begin copying here: Files to move: C:\WINDOWS\ServicePackFiles\i386\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys 3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
|
|
#19
|
|||
|
|||
|
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File move operation "C:\WINDOWS\ServicePackFiles\i386\atapi.sys|C:\WINDOWS\system32\drivers\ata pi.sys" completed successfully. Completed script processing. ******************* Finished! Terminate. |
|
#20
|
||||
|
||||
|
Check for redirection, please.
|
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Google redirect
|
13 | Virus and Malware Removal | ||
Yet another google redirect
|
1 | Virus and Malware Removal | ||
Google redirect
|
7 | Virus and Malware Removal | ||
Google Redirect
|
4 | Virus and Malware Removal | ||
Google redirect
|
0 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 06:24 PM.





Google redirect