![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Recently I noticed that Internet Explorer is redirecting me to bogus websites that look like the site I am attempting to login to. Example would be Ebay, Paypal, or any other website that requires logging in that is an "https:". I have tried Malwarebytes, CCleaner, McAfee and nothing works to remove it. I ran a RootRepeal report this morning and is says MBR Rootkit Detected! I am most eager to get this resolved as I work from home on this computer and it's starting to hinder my work. I will patiently await someone's response on this. I am also attaching the rootrepeal log.
Thank you, Dan |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Quote:
Welcome to Major Geeks! Please read ALL of this message including the notes before doing anything. Pleases follow the instructions in the below link: READ & RUN ME FIRST. Malware Removal Guide and attach the requested logs when you finish these instructions.
Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST. You need to attach logs from running tools regardless of whether or not they found anything. For example the program might be outdated, and didn't find anything because of that fact, so do post logs from MBAM as well as the other requested logs which you haven't posted, from running the R&R. Before I see them, I cannot build you a fix. Quote:
![]() |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
SkyChimp (02-13-10) | ||
|
#3
|
|||
|
|||
|
Okay... I followed all steps and I noticed that some items where picked up. Here are the logs on all four programs that you wanted.
|
|
#4
|
|||
|
|||
|
And finally the MGlogs
|
|
#5
|
||||
|
||||
|
1. Now we need to use ComboFix
Code:
KILLALL:: Fcopy:: C:\WINDOWS\ServicePackFiles\i386\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys File:: c:\windows\system32\f9t.dat Folder:: c:\documents and settings\All Users\Application Data\Viewpoint C:\$AVG
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. 2. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now! Are you still being directed? Last edited by Kestrel13!; 01-29-10 at 08:28.. |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
SkyChimp (02-13-10) | ||
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Things are running much better now and I'm not being redirected. Thank you
![]() |
|
#7
|
||||
|
||||
|
That's great to hear
If you wish to attach logs just so I can really confirm you're clean then you can of course do so. Let me know. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| MBR rootkit detected | Jozza | Malware Removal | 1 | 11-23-09 19:36 |
| Rootkit --> redirecting search engine links | Ryan13x | Malware Removal | 2 | 10-21-09 13:13 |
| Rootkit activity detected, now what? | lpontius1 | Malware Removal | 4 | 01-30-09 16:28 |
| GMER detected rootkit; now what? | eliewriter | Malware Removal | 11 | 12-24-08 12:44 |
| Rootkit.bagle and Rootkit.Agent - No Internet, No Safe Mode, No Antivirus | raremedium | Malware Removal | 14 | 04-19-08 22:48 |