Atapi.sys ~ redirection of all browser searches.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tracyw, Jun 5, 2011.

  1. tracyw

    tracyw Private E-2

    Greetings.:)

    I have been infected with some type of redirect virus/malware/trojan or something along those lines.

    Was seeking help at a different malware forum but after several months of trying various things and working with them exclusivly(none of their ideas working). Thought I would go at it myself.

    After numerous reformats I believe I have figured out the problem but alas I have zero idea on how to fix it.

    If I do a full system restore(wiping everything out), the redirect still occurs upon first boot up.
    I have found if I run combofix on the very first boot up after a system restore, that it will say there is something wrong with my atapi.sys file.

    Combofix will attempt to fix the problem but then upon rebooting I get an endless blue screen of death loop, due to the atapi.sys being moddifed or deleted.

    I have tried pretty much every program on the market(tdskiller,avast,avira,eset,.....)
    combofix seems to be the only program that will detect a problem with the atapi.sys file. But when it fixes the problem Im gifted the ol BSOD.

    I read some articles online talking about downloading a atapi.sys file from a good computer making it a read only file and then transfering onto this computer, but without better instructions(also do not have acess to another computer). I am unable to fix the problem and since my browser redirects me constantly it makes it almost impossible to find the file online to download.

    Any help would be greatly appreciated. thanks a million.:)
     
  2. tracyw

    tracyw Private E-2

    I did not realize there was a time limit on editing posts or else I would have included all info in that post, sorry about that.

    1st. Deleted all but one antivirus and firewall software.

    2nd. Made sure all old java was removed and downloaded newest versions.

    3rd. I have the windows xp32bit operating system 2002

    4th. select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files option.

    5th. Set msconfig to "Normal startup mode"

    6th. I don't believe I have any disk emulation software, Ran Defogger just incase.

    7th. Toggled the system restore option.

    Going to post some logs next, I believe that if I run the combofix it will detect the atapi.sys file and delete/modify it which will present with with the blue screen of death. I am almost positive that that atapi.sys file is the problem but wanted to go through the steps listed here just incase.
     
  3. tracyw

    tracyw Private E-2

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the following:
    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. tracyw

    tracyw Private E-2

    Thank you so much for the help.:)

    I am using windows xp home edition.

    1st. Rebooted into safemode then click administrator option.

    2nd ran the defogger ~just incase.

    3rd Downloaded Avenger/unziped to desktop
    Ran analysis.exe-- checked the O2 - BHO: (no name), and hit fix
    (after closing broswer window).

    4th, Copy pasted text, hit execute, computer reboots back into normal mode, avenger log is saved at startup.

    5th. Ran GetLogs.bat,

    6th uploaded files here,
    View attachment avenger.txt

    View attachment MGlogs.zip

    7th checked browser search function, the redirect is stilll here and now there seems to be a pop up window appearing that hasn't shown up before.

    Example:
    I type forums majorgeeks into google, when I hover my mouse over the link some crazy thing shows up, enclosed a screen capture.
    redirect.jpg
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. tracyw

    tracyw Private E-2

    **question** do i need to reboot into safe mode and then do the steps laid out?
    I did them this time from the regular start up.
    (on my xp computer I can only log in as administrator from safemode)


    1.disable all anti-virus and anti-spyware programs,

    2.saved text in notepad as instructed.

    3.Window pops up asking if I want to add to the registry, I hit yes, then another window pops up saying information has sucessfully been entered into the registry.

    4.ran the GetLogs.bat file

    here is the updated log.
    View attachment MGlogs.zip

    The problem still persists exactly as before,
     
    Last edited by a moderator: Jun 5, 2011
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Reboot and tell me if you still are redirected.
     
  9. tracyw

    tracyw Private E-2

    Rebooted, still infected with the redirect on all browsers and search enginees, pop up widow advertising still happening as well.

    :***
    I hate this damn redirect thing, I would love to find the person who made this awful invention.






    ti.jpg
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have been trying to avoid this, but it's time for you to get me a ComboFix log, as we have removed what should have been the cause of the redirects.

    Just noticed that your TDSSKiller logs are from months ago, please do this:
    TDSSkiller - How to run
     
  11. tracyw

    tracyw Private E-2

    Ok.
    Downloaded a fresh copy of the tdskiller from your link and ran, it didn't detect anything.

    Do I run the combo fix from safe mode while logged in as administrator?

    Now if I get the blue screen of death after running the combo fix, is there any info you would like to write down, is there a way to pause that blue screen of death so I can read what it says? And is there anything i can do to fix it short of doing the system recovery with destrutive option?

    I don't have access to another computer so If I get the bsod I will have to do a system restore from the D: drive(factory installed backup recovery drive). I do have everything important backed up so.. if it happens it happens.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click My Computer / properties / advanced / and go into startup and recovery and uncheck the box to restart on errors. That should give you the BSOD info.

    You should be able to do a system restore if you run into problems.

    TDSSKiller found nothing? Crap.
     
  13. tracyw

    tracyw Private E-2

    LOL:-D
    Man If I had a dollar everytime I said "crap" cause of this damn thing... at least I can laugh about it now.

    turned off the auto restart on system failures.
    Im going to run combofix right now,

    ill be back shortly(hopefully).

    Now if memory serves me I believe combo fix only detected a problem with the atapi.sys file if I ran on the very first boot up after a fresh install.

    guess we shall see.


    thanks for the help, I really appreciate it:)
     
  14. tracyw

    tracyw Private E-2

    No bsod:cool

    here is the combofix log,

    the redirect is still the same as in the screenshots I posted before though.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    
    :reg
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Redirects gone?
     
  16. tracyw

    tracyw Private E-2

    Kestrel13 & Tim thanks again for the help,

    sadly the redirect is still here after otm.:cry

    here is the getlogs.bat file
    & otm log
    View attachment MGlogs.zip

    View attachment otmlog.txt

    Sreenshot after running otm, still have the weird address appear on mouse overs and when I click any link after doing a search I get taken to some random place.:***
    sreenshotMonAM.jpg
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25
    [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  18. tracyw

    tracyw Private E-2

    the fixME.reg was sucessfully added to the registry.

    oddly I can't upload the file MGlogs.zip:
    I get the following error

    "You have already attached this file in thread : Atapi.sys ~ redirection of all browser searches."
     

    Attached Files:

  19. tracyw

    tracyw Private E-2

    Browser redirect and random pop up windows still persist.
    cant upload the mglogs.zip file still, should I rename it?
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"="213.109.69.44 213.109.76.46 205.171.3.25 205.171.2.25"
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"="213.109.69.44 213.109.76.46 205.171.3.25 205.171.2.25"
    [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
    "DhcpNameServer"="213.109.69.44 213.109.76.46 205.171.3.25 205.171.2.25"
    Registry:: 
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"=""
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"=""
    [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
    "DhcpNameServer"=""
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  21. tracyw

    tracyw Private E-2

    Things just got real interesting.:confused

    I had downloaded iobit security as my primary antivirus last night, and deleted my previous antivirus.

    I followed your instructions to a tee, disabled iobit before dragging/dropping the txt file onto the combofix. I was away from the computer for a second but when I returned combofix had rebooted the computer.

    The iobit restarted after the reboot and combo fix was still running but had frozen up, possibly because of iobit had restarted.:confused

    And this little pop up from iobit was on the screen, I thought maybe hitting cancel would allow the combofix to finish.
    http://forums.majorgeeks.com/attachment.php?attachmentid=160484&d=1307379881

    As soon as i hit cancel another pop up came up, I hit cancel again, another pop up from iobit.. I did that about 7 times.


    At this point combofix is still open and says its preparing the log, but its obviously frozen as it had been preparing the log for about 45 mins at that point.

    So I click on internet explorer and go to google, type in a search
    NO MORE REDIRECT.

    At this point combo fix is still open(frozen) and iobit keeps popping up these little messages saying something is trying to alter my browser.

    I right click on the iobit icon in the tray and hit exit.
    wait awhile, combofix still wasnt responding so I hit the "x" to close it out.

    I close out the internet browser, reopen it, get back online and the redirect is back. damn:(

    The combofix log did not save because it froze.. Im guessing I should delete iobit? and rerun your last set of instructions?

    WTF.JPG
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You probably should have hit "Allow this scan", but for the time being, uninstall it. Then run CCleaner to remove any leftovers and then try the Combofix script again. Combo is not reporting any problem with atapi. Your redirects are due to the DHCP settings which we are trying to fix. ( also kill any other AS software like Dr. Web.)
     
  23. tracyw

    tracyw Private E-2

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, it is very stubborn but we are renowned for our persistence. :).

    Do you use a router? If so reset it to defaults, not just a soft reset. Just doing that alone is not going to help but I want you to do it anyway, also the below:

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25"
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25"
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  25. tracyw

    tracyw Private E-2

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, you need to reboot and surf around again. The runkeys.log is now not showing the signs of infection and the log from Combofix shows the correct settings and none of the bad:

     
  27. tracyw

    tracyw Private E-2

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Combofix by double clicking it's icon or right clicking and running as admin if on Win7 or Vista.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  29. tracyw

    tracyw Private E-2

    I have windows xp, I can only sign into adminstrator in safe mode.
    Shall I do that?
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please.
     
  31. tracyw

    tracyw Private E-2

    After running combofix in safe mode(adminstrator) and the getlogs file, I was then unable to connect to the internet, I reboot the computer into safe mode again in hopes that the internet would work. Upon opening the browser this screen popped up.

    And the problem still persists as well.

    View attachment log.txt

    View attachment MGlogs.zip

    untitlede.JPG
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, let's keep at it.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
    Registry::
    [HKEY_LOCAL_MACHINE\system\controlset002\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25"
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  33. tracyw

    tracyw Private E-2

  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you been running my fixes in normal mode or safe mode?
     
  35. tracyw

    tracyw Private E-2

    I have been running everything in safe mode under "Administrator"(safe mode being the only way I know how to get into the administator account.

    but for instance, if I am in safe mode running combofix, when reboots and the end of combo fix it boots into a regular startup under the general user name which is named "Admin".

    or another way to say that, there is two users on this computer, "admin(regular start up)" and "administator(safe mode)"
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, I need to make this clear, on the ADMIN account (Not Administrator) you need to run this fix in NORMAL mode not safe mode! :)

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25"
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"="205.171.3.25 205.171.2.25"
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  37. tracyw

    tracyw Private E-2

    Here is what I did in detail this morning.

    1.
    Turned on computer, opened a browser, logged onto majorgeeks and read your latest post.

    2.
    Open notepad, save the text in the quote box as CFscript.txt on the desktop, combofix is also located on the desktop.

    3.
    I shut down the computer and then start it up again, normal start up, not safe mode.

    4.
    at this point the computer has started in normal mode, I have not opened ANY programs/browsers/etc since restarting the computer.


    5.
    I double click on defogger.exe and hit disable(am I supposed to do that:confused?)
    http://forums.majorgeeks.com/attachment.php?attachmentid=160542&d=1307454800
    I open paint and do a screen shot of the defogger program, save the screenshot, then exit paint.

    6. I drag the CFscript.txt previously saved on the desktop on top of combofix.exe, this starts combofix up.

    7. Combofix asks if I would like to update to the newest version of combofix, I hit yes.
    combofix restarts and prompts me to agree to the service agreement once more, i hit yes.

    combo fix continues running, after stage 50 is complete, it reboots the computer, when the computer restarts combofix also opens again. It says not to run any programs until combofix is finished, then it says its creating a log and the combofix program closes by itself. the CFscript.txt that was saved on the desktop is now gone as well.

    8.
    I go to c:, find mgtools and click on the getlogs.bat file, it runs normally and at the end says, press any key to close the window.

    9.
    I now open internet explorer and get an error message, I am unable to connect to the internet, I try a couple browsers neither work.



    10.
    Since I am unable to connect to the internet I decided to restart the computer.
    I click on the start menu, go down to "turn off computer" then select restart.

    http://forums.majorgeeks.com/attachment.php?attachmentid=160541&d=1307454800

    Now this seems rather important.:confused

    When the computer restarts, i click on internet explorer again, NOW the browser is working once again. I type google.com into the address bar it loads fine.
    I then do a websearch and still get the same redirection and pop up windows as before, nothing has changed.:cry

    My uneducated assumption is there is still something on the computer that changes the settings you are working to fix when the computer is restarted.
     

    Attached Files:

  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Attach the log.
     
  39. tracyw

    tracyw Private E-2

  40. tracyw

    tracyw Private E-2

    Would it help you to solve the problem, If I do a Destructive System Recovery?

    I have done the Destructive system recovery before hoping it would fix the problem but the problem does not go away.

    I guessed that my d: drive (the partition that contains the recovery software) had been compromised.

    This computer is a hp pavilion btw.

    http://h10025.www1.hp.com/ewfrf/wc/document?cc=us&lc=en&docname=bph07145
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you going through a router? Are any other computers using the router, if you are. Do they get redirected?
     
  42. tracyw

    tracyw Private E-2

    I am using a router, I also did a hard reset, as advised by kestrel.
    My boyfriend was using the same router as me for the last 4 months, he never had a single redirect/popup problem the whole time my computer was having the problem

    Our new puppy pulled his computer off the table last week and it now needs some work though.
     
    Last edited: Jun 7, 2011
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go into msconfig and under start ups do you see anything like:
    ose? If so, disable it. Boot back into normal mode and let's run Avenger again:

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now re-run C:\MGTools\GetRunKeys.bat and get me both the Avenger and the RunKeys log.
     
  44. tracyw

    tracyw Private E-2

    I don't see anything like ose listed, I looked at this screen under both "startup item" & command. msconfig.jpg

    Here are the logs you asked for.
    View attachment avenger.txt
    View attachment runkeys.txt


    Also I don't know if it matters at all, but when I just checked to see if the redirect was still hapenning I noticed that when I mouse over a link it is now different than it was previously..
    here is a screen capture, it now says "35e4.r.google" before it was something different.
    newaddyforredir.jpg
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is what has me concerned:
    Code:
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    "ose"=dword:00000003
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Again, need the Avenger log and a new Runkeys log.
     
  46. tracyw

    tracyw Private E-2

    I inputed this into avenger just as advised.
    Code:
    Registry values to replace with dummy:
    HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters | DhcpNameServer 
    
    HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters | DhcpNameServer 
    here are the two logs you requested:)
    View attachment avenger.txt

    View attachment runkeys.txt
     
  47. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about that last message, I am drawing at straws at this point. I've asked Chaslang to take a look and see if he sees something we are missing. Hang in there. :(
     
  48. tracyw

    tracyw Private E-2

    thank you for all the help from everyone.

    Now I am not very computer savy and don't know jack about computers, but I figure ill explain why I thought it was the atapi.sys file

    I have had this redirect for quite awhile maybe 5 months.

    A few months back I did a Destructive System Recovery trying to rid myself of this dreadful thing.
    the destructive systyem recovery is preloaded under D:\ so the computer doesn't actually come with cds to reinstall windows, so maybe there is something in my d:\ that causes these problems?


    To my dismay when the computer started up for the first time I still had the redirect, very odd I thought.

    I try running antivirus software, I remember using avg,avira,microsoft security essentials, esent, drweb, avast, combofix, and Im sure many others.

    I ended up doing another Destructive System Recovery/
    This time I ran combofix(may have been possibly iobit) the very first time windows loads. And it picked up the atapi.sys file.

    Which is odd because I found if i rebooted the computer once after the very first time windows had been installed(the second time windows starts), it will no longer pick up the atapi.sys file.

    probably nothing, but for whatever its worth.

    :)
     
    Last edited: Jun 7, 2011
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please uninstall Surf Anonymous Free. Then reboot your PC.

    Do you still have the exact same problem?
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also, please tell me how you have your Obtain DNS server address automatically options set for your network interface. If you don't know how to do this, you can see how to obtain this info in the below:

    http://support.microsoft.com/kb/305553
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds