![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi I am having a continual problem with a google redirect virus. I use Malwarebytes and continually update and scan my computer. An AdRotator virus keeps coming up and I constantly remove it but it keeps appearing and the redirects continue to occur.
I've went through the steps posted on this forum for removing the redirect virus but It did not solve the situation. I currently use Firefox, on a 64bit Windows 7 system. Any help would be appreciated. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
Then work your way through the below: Please read ALL of this message including the notes before doing anything. Pleases follow the instructions in the below link: READ & RUN ME FIRST. Malware Removal Guide and attach the requested logs when you finish these instructions.
Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Ran through the steps that you've outlined. Experienced no problems with the installation or running of these programs.
Attaching the logs Sorry for the delayed response, hurricane knocked out my internet. |
|
#4
|
||||
|
||||
|
Please attach logs from Combofix and MGTools.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
Logs
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Is AVG currently installed or not?
Ask Toolbar <--- uninstall this garbage. Now we need to use ComboFix sUBs
Code:
KILLALL::
File::
C:\Users\ADMIN\AppData\Local\job2x0sqvd7o45x6j2pw86tbh7
C:\Users\ADMIN\AppData\Local\y46sfanjfs78b7643d
C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Templates\job2x0sqvd7o45x6j2pw86tbh7
C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Templates\y46sfanjfs78b7643d
C:\ProgramData\626016e7801474pf
C:\ProgramData\job2x0sqvd7o45x6j2pw86tbh7
C:\ProgramData\y46sfanjfs78b7643d
C:\Windows\system32\tmp.txt
Registry::
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
AVG is not installed
Could not uninstall Ask Toolbar. After repeated attempts at uninstalling it via the Add/Remove Programs Panel it does not allow me to continue the un-installation stating that I must first close all Internet Explorer browsers even though IE is not running and I have even checked the Program Manager. Attached is the logs. I am still experiencing redirects via google. |
|
#8
|
||||
|
||||
|
Quote:
Quote:
Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program. Download and run OTM. Download OTM by Old Timer and save it to your Desktop.
Code:
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}]
:files
c:\users\ADMIN\AppData\Roaming\AVG10
c:\programdata\AVG10
c:\windows\system32\drivers\AVG
c:\program files (x86)\AVG
c:\programdata\MFAData
C:\ProgramData\626016e7801474pf
C:\ProgramData\job2x0sqvd7o45x6j2pw86tbh7
C:\ProgramData\y46sfanjfs78b7643d
C:\Users\ADMIN\AppData\Local\job2x0sqvd7o45x6j2pw86tbh7
C:\Users\ADMIN\AppData\Local\y46sfanjfs78b7643d
C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Templates\job2x0sqvd7o45x6j2pw86tbh7
C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Templates\y46sfanjfs78b7643d
C:\Windows\system32\tmp.txt
:Commands
[emptytemp]
[Reboot]
NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now! Quote:
You can test this theory by connecting directly to your modem and if the redirects stop, then you know it is the router that is infected.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#9
|
|||
|
|||
|
Hardlined into the modem and am still experiencing redirect issues.
I do not have my boot CD on hand. Attached are the logs. |
|
#10
|
||||
|
||||
|
You have an MBR infection, so you may want to try creating and using Hiren's CD to fix the MBR. See what was posted in message # 12 of the below thread and see if you can get this CD to run. If you still need special drivers to access your drive, you will need to post in the Software Forum on how to do this.
whistler/black internet@mbr again!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Google Chrome Redirect virus infection - have logs and programs ready to go | jis3 | Malware Removal | 6 | 08-18-11 22:03 |
| Google Chrome/Firefox google search redirect virus help. | time_warrior66 | Malware Removal | 3 | 07-12-11 11:54 |
| virus or spyware blocking anti-virus programs and pages | Zeruth | Malware Removal | 1 | 02-17-06 23:01 |
| Unable to run or download any anti virus or anti spyware programs | schemero | Malware Removal | 0 | 11-21-04 21:37 |