![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
|
#1
|
|||
|
|||
|
Hey all,
I've been having some redirection problems to various websites, sometimes from Google and sometimes if I type a URL in myself. I've followed the steps from the sticky on this subject up to step 4, my TDSSkiller log is attached. Should I continue on to run the MBRCheck? Thanks! ![]()
__________________
Windows 7 64 bit |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks! Yes! And then continue on with the READ & RUN ME which is mentioned right after MBRcheck.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
MBRCheck log is attached
__________________
Windows 7 64 bit |
|
#4
|
|||
|
|||
|
Attached are logs from SAS, MBAM and MGtools.
Combofix would not run past the extraction stage; it displayed no blue screen as shown in the instructions. RootRepeal is not included since I am using Windows 7 x64. Also, MGtools displayed an error message stating that HiJackThis couldn't access the Hosts file for some reason. I'm still having redirection problems after performing all the cleanup procedures and scans! I think it started a day or two ago. I'm afraid I'm not sure what I was doing at the time, sorry :s
__________________
Windows 7 64 bit |
|
#5
|
||||
|
||||
|
Go back and re-run TDSSkiller and if the below still appear like last time, cure/delete them ( which ever option is presented ) this time
Code:
15:44:25.0608 5620 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user 15:44:25.0608 5620 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O4 - .DEFAULT User Startup: toap.exe (User 'Default user') After clicking Fix, exit HJT. Now download The Avenger by Swandog46, and save it to your Desktop. See the download links under this icon ![]()
Quote:
After reboot, copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day). C:\WINDOWS\TEMP C:\Documents and Settings\Sean Walsh\Local Settings\Temp Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program. NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
HostsXpert says "Your HOSTS file is marked as a "system file" and can NOT be manipulated. Press OK to remove the system file attribute, CANCEL to Quit."
I click OK and the same window pops up, press it again and it goes away but the 'Make Writable?' button does nothing. The 'Restore MS Hosts file' button also comes up with an error.
__________________
Windows 7 64 bit |
|
#7
|
||||
|
||||
|
Try running HostsXpert.exe by right clicking on it and selecting Run As Administrator.
If that does not work, just continue on with the rest of the instructions anyway.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#8
|
|||
|
|||
|
HostsXpert.exe still wouldn't work even running as administrator.
Avenger rebooted my PC but didn't create avenger.txt anywhere nor show me a file on reboot... the closest thing I could find is the attached ozvxqu.txt I didn't download ATF Cleaner because it says it's for Windows XP or 2000 and I'm running Windows 7. Everything else seemed to go fine, I got the success message from fixme.reg and MGlogs.zip is attached. Still getting redirected I'm afraid and browsing still doesn't seem as fast as it should be.
__________________
Windows 7 64 bit |
![]() |
| Tags |
| redirect google website |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| website redirection problems still after running guide | rossia77 | Malware Removal | 10 | 08-09-11 05:21 |
| General redirection problems + malware cleared desktop and mydocuments | quatfro | Malware Removal | 12 | 07-07-11 14:34 |
| Fixing Google Redirection/hijacking and other redirection problems | chaslang | Malware Removal | 0 | 01-02-11 14:33 |
| Comp running slower | gobble | Malware Removal | 1 | 04-12-08 18:55 |
| Spybot running slower?? | gimpster123 | Malware Removal | 5 | 06-26-07 22:06 |