Redirects no virus dected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pelriver, Nov 20, 2011.

  1. pelriver

    pelriver Private E-2

    I have seen several people with the same issue. All my logs have come up clean, but I have a faked MBR. I have attached the logs that are suggested. I think that I may have the small partition issue that several have posted about
     

    Attached Files:

  2. pelriver

    pelriver Private E-2

    for some reason Mglogs and combofix won't upload. I will try again in morning.
     
  3. pelriver

    pelriver Private E-2

    Okay, they attached this morning. Any help would be greatly appreciated!!

    Thanks,
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now:

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. pelriver

    pelriver Private E-2

    I have attached the logs that you have requested
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you don't have your Win7 disc, you can create one here:
    Win7 64bit Recovery Environment

    Win7 32bit Recovery Environment

    You can use ImageBurn to create the disc.

    Once you have created the disc, boot to your bios and change the boot order to CD/DVD as first boot device. Insert the disc and reboot. Once in the Recovery Environment, choose the Command prompt and type in this:
    Bootrec.exe /fixmbr

    Once done, exit and reboot to normal mode. Re-run MBRCheck and attach the new log.

    Now I also want you to :

     
  7. pelriver

    pelriver Private E-2

    I booted from new recovery disk. Ran the fixmbr command. It completed succesfully. Reran MBRCheck. The same code came up as before telling me that I had a fake mbr. For some reason, I am having the same issue as last night with uploading files. It gets stuck at 84% I can tell you that the log is the same as before.

    When running ShowNew in MGtools. I had several unsupported 16 bit application running in a 64 bit system errors. Too many to count.
     
  8. pelriver

    pelriver Private E-2

    Here are the logs that you requested.

    Thanks for your further help
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :otl
    :services
    rextqe
    clnaiuzp
    :files
    C:\Windows\SysWow64\drivers\rextqe.sys
    C:\Windows\SysWow64\drivers\clnaiuzp.sys
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.



    If you go into Hard drive management, are you only seeing the two partitions?
     
  10. pelriver

    pelriver Private E-2

    Ran Fix in OTL. When it came up a process called help pane was running and it pulled up a help pan in every browser that I tried to open. I had to open task manager and shut that process down to get it to stop.

    I have attached the OTL log.

    I also ran the dos commands for MGTools and attached the .zip file.

    I have 3 partitions. I have attached a snip of the disk management screen.

    Thanks,
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like you have a faked partition. Would you take another screen shot and scroll to the left so I can see the size of the partition?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds