Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Download Now:
Another Google redirect virus, MBAM crashes during all scans
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Another Google redirect virus, MBAM crashes during all scans
Hi!
Unfortunately I am also facing a redirect virus/malware issue that seems to be plaguing these boards. Google links will redirect to ads/other sites, but typing sites into the address bar or bookmarked sites load fine. I have AVG antivirus, Spybot S&D, and Malwarebytes, but none of these programs find any infections. Malwarebytes will crash during any scan, whether it be a quick scan or a full scan. Any help or advice would be appreciated, thanks in advance! |
|
#3
|
|||
|
|||
|
Hi Crunchie,
Thank you for helping. I will follow the steps and post the logs by tomorrow. Note: Malwarebytes still crashes during scans, but I will attempt to try it again while moving through the steps. |
|
#4
|
||||
|
||||
|
If it will not run, just get what logs you can and post them
.
|
|
#5
|
|||
|
|||
|
Here are the logs.
Unfortunately malwarebytes still crashes so i couldn't get a log for that. Thanks again! |
|
|
|
#6
|
||||
|
||||
|
Please download JavaRa
If you get this message: Problems with the download? Please use this direct link or try another mirror. Select the Direct link download unzip it to your Desktop. Double click JavaRa.exe then click Remove Older Versions. Follow any prompts; a log will popup (JavaRa.log)-- please post the contents of this log. Next, open JavaRa.exe again, and select Search For Updates. Select Update Using Sun Java's Website --> Search, and continue the instructions for downloading and installing the latest Java version. Look for JDK 6 Update 21 (JDK or JRE). On the right select this one Download JRE.. In Vista and Windows 7 run the tool as Administrator. ============= Please download ComboFix by sUBs from HERE or HERE
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine. Run Combofix ONCE only!! |
|
#7
|
|||
|
|||
|
I followed the Java steps with no issue, but after running combofix my computer seems to be in a worse situation.
The scan went smoothly until it found and infection and automatically rebooted. I did not do anything as instructed, but upon reboot, I receive a blue screen of death message, "STOP: c000021a Fatal System Error The windows logon Process system terminated unexpectedly with a status of 0xc0000005 (0x0000000 0x00000000). The system has been shut down." After manual reboots, the computer will load the desktop, then reboot itself and give the same blue screen. Please advise! |
|
#8
|
|||
|
|||
|
Also, forgot to mention that combofix asked me to download/install recovery console. I followed the prompt and it downloaded and installed.
I have the computer off as it will boot up normally then crash after loading. Currently posting from another computer. |
|
#9
|
||||
|
||||
|
When you attempt to boot, go to selective startup and see if it will boot ok from 'Use the last known good configuration.'
If it will not do so, try booting to safe mode and do a system restore. Report back how you went please. |
|
#10
|
|||
|
|||
|
I loaded last known good configuration.
Windows loaded fine, but it gave me a winlogon.exe stop working (probably because it was deleted?). But, no reboots or blue screens. Also, redirect seems to be gone. Unfortunately there was no log produced from combofix as it was giving me blue screens. I have attached the JavaRa log as well. Thanks again crunchie |
|
#11
|
|||
|
|||
|
Ok so, now the comp wont start up again, having same issues. After i loaded last known good config it was working fine, after i turned off comp and turned it on again, it started giving me the same error and would give me a blue screen after loading.
thanks |
|
#12
|
||||
|
||||
|
Can you try rolling back by using system restore please and we will see where we go after that
.
|
|
#13
|
|||
|
|||
|
Sorry, I've never performed a system restore, could you guide me as to how to go about doing this?
thanks! |
|
#14
|
|||
|
|||
|
Sorry crunchie, disregard that last post.
I figured it out but, this looks like it wont work either, before loading the system restore box, the comp crashes with the same blue screen error |
|
#15
|
||||
|
||||
|
Go to Start | Run and type in msconfig and hit OK. Select the Launch System Restore button.
The radio button for Restore my computer to an earlier time should be selected then go next. Select a date that you wish to restore to and select next. |
|
#16
|
|||
|
|||
|
Crunchie,
the system restore fixed the crashing, but the virus is back ;( |
|
#17
|
||||
|
||||
|
Download Bootkit Remover to your Desktop.
|
|
#18
|
|||
|
|||
|
Here are the bootkit results
Bootkit Remover (c) 2009 eSage Lab www.esagelab.com Program version: 1.1.0.0 OS Version: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) System volume is \\.\C: \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`3ec10000 Boot sector MD5 is: 6def5ffcbcdbdb4082f1015625e597bd Size Device Name MBR Status -------------------------------------------- 298 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found) Done; Press any key to quit... |
|
#19
|
||||
|
||||
|
That looks ok.
Please Run the ESET Online Scanner and post the ScanLog with your post for assistance. NOTE: If you are unable to complete the ESET scan, please try another from the list below: • Kaspersky Online Scanner • Panda Active Scan • Trend Micro HouseCall • F-Secure Online Virus Scanner |
|
#20
|
|||
|
|||
|
ESET would not run, and Kaspersky required a java framework download, so I am currently running a panda active scan.
Will post results when finished |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Google keeps redirecting, virus scans are clean
|
6 | Virus and Malware Removal | ||
I have the Google Redirect Virus
|
2 | Virus and Malware Removal | ||
Google Redirect Virus
|
15 | Virus and Malware Removal | ||
Google Redirect Virus, 8 Steps Complete, Still Have Virus..
|
10 | Virus and Malware Removal | ||
Another Google redirect, but cant load MBAM or SAS
|
3 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 03:17 PM.


.
Google keeps redirecting, virus scans are clean